Capture Client: Prevent macOS 26.6 False Positives with SentinelOne Policy Override

Description

What is causing the elevated Static AI false positive alerts on macOS, and what is Sentinel One doing to fix it?

SentinelOne is aware of increased Static AI false positive alerts triggering on legitimate macOS system processes following the July 27, 2026, macOS Tahoe 26.6 update. A multi-stage fix is in progress, including:

  •  Global exclusion (allowlisting) of the known hashes triggering the false positives.
  • A permanent fix via macOS Agent version 26.1 SP1, to be released once QA and validation are complete.

In the interim, if you have upgraded or plan to upgrade to macOS Tahoe 26.6 in the near term, it is recommended that you apply the Policy Override (PO) to avoid potential false positives and disruption to your environment.

Changing Agent Configuration with Policy Override

  • Supported from Management version: Iguazu SP3
  • Supported from Agent Version: Windows 2.6+ | macOS 2.6+ | Linux 3.x+

Policy Override in the Management Console overrides a default option in the Agent configuration. You can send a Policy Override to a Site, to an Account, or to Global. The Policy Override page is available for users with the edit Policy role permission. Advanced Mode is not required.

⚠ Important

  • Change configuration with caution and with guidance from Capture Client Support.
  • Each Agent can apply only ONE Policy Override.
  • Each Policy Override can have multiple configuration changes, and you can add more configuration changes to an override.
  • Agents apply the override with the narrowest scope and version that matches them.
    • If you have a Policy Override configuration for a specific Agent version, Agents with that version do NOT apply changes from a different override that is for All Versions. A policy override for a specific version has a higher priority than a policy override that is set to All Versions, regardless of scope.
    • If you have an override for the Global scope and an override for a Group scope, Agents in the Group apply the Group override and NOT the Global override.
  • All parts of the configuration that you do not enter in the window will be overwritten from the other configuration sources. Make sure to include all changes, old and new, in the text you will enter.

Account and Global users can do this task

From Platform version W SP1, Policy Override configurations now have an Expand option to see the configuration settings more clearly. This shows as a toggle at the top of the Policy Override window.

  • On — The configuration shows in the whole window.
  • Off — The configuration shows in half of the window.

To configure Policy Override for a group, Site, Account, or all Agents:

  • Plan the configuration changes.
  • Save the latest Agent configuration.
    • In the sidebar, click Sentinels. Endpoints opens
    • Select an Agent and click Actions | Configuration | Agent Configuration.
    • Copy the text to a file and save it.
  • In the Settings toolbar, click Policy Override. Each policy override shows in the Policy Override page. Click an override to edit it. Select the checkbox next to an override, then click Delete Selection to remove it.
  • Click New Configuration. The window opens for the new policy override configuration.
  • Enter values for the configuration properties.
    New Configuration Values

    Field

    Description

    Configuration Name

    Name of the policy override as an asset.

    Platform

    Select the OS of the Agent configuration to change.

    Version

    Enter the build number of the Agent, in the format XX.X.X.XXX, or select All.

    Policy overrides are defined for a specific build number OR for ALL Agents. When you upgrade or add Agents with a different build number, duplicate each policy override that is for a specific version, or change the override to apply to all Agents.

    Description

    Explain the change and the reason.

    Access Level

    • Global: This will set the configuration of all Agents.
    • Account: Enter the name of an Account. You can set only one Account.
    • Site: Select an Account, and enter the name of a Site in that Account. You can set only one Site.
    • Group: Select an Account and a Site, and enter the name of a Group. You can set only one Group.
  •  In Configuration data, enter the JSON to change the configuration. For example:

    If the parameters to change are in a hierarchy, make sure you include the parent key and enclose the child parameters and the parent properly:

  • Click Save.

To copy a policy override for Agents of a different version:

When Agents are upgraded, or new Agents of a different version are added to the environment, you must configure the policy override for the new Agent Version. When a package with a new Agent is added to your Management Console:

  • In the Settings toolbar, click Policy Override.
  • Open a configuration from the table.
  • Copy the Configuration data and click Cancel.
  • Create a New Configuration for the new Agent version, or for All versions.
  • Paste in the copied configuration data.
  • Click Save.
  • Repeat for each existing configuration.

Note:

There are different ways to change Agent configuration. See the Agent Configuration Hierarchy to learn more.

Some configuration changes are only available through Sentinelctl and NOT through Policy Override. In the SentinelCTL documentation, commands that show Agent Configuration JSON syntax are available in Policy Override.

See Advanced: Changing Agent Configuration Manually to change the configuration for one or more selected Agents and not a whole group.

 

    Related Articles

    • Capture Client migration across consoles
      Read More
    • Best Practices Guide for SonicWall Endpoint Security (SES)
      Read More
    • Capture Client – Pre-requisites for Windows
      Read More
    not finding your answers?