How to Install Sentinalone With Token Mac OS
For how to install sentinalone with token mac os, download the macOS SentinelOne .pkg scoped to the destination Site, save that Site Token or Group Token as plain text in a file named com.sentinelone.registration-token, and place both files in /tmp. Change the token file owner to root, then run the package as an administrator with sudo installer -pkg “./[SentinelOne Package File Name].pkg” -target /.
Beyond that, for MDM deployment, install the required profiles before the package. Endpoint Central calls for PPPC, Web Content Filter, and System Extensions configurations, while Jamf Now uses a token plist at /Library/Managed Preferences/com.sentinelone.registration-token.plist, mode 644, plus a PPPC custom profile.
How to Install Sentinalone with Token on Mac OS
Install the SentinelOne Agent on a Mac by downloading a macOS package scoped to the destination Site, placing the matching Site Token or Group Token in a registration-token file, and running the package as an administrator. First, select Packages in the Sentinels toolbar and download the latest macOS installer package for the Site where the Mac should be assigned. Save the applicable token because the installer uses it to register the endpoint with the SentinelOne tenant. Run the installation only after confirming that the package scope includes the intended Site.
Use the Registration-Token File
Keep the installer package and a plain-text token file together in /tmp for the local command-line method. Guardz specifies that the file must be named exactly com.sentinelone.registration-token and that its ownership should be changed to root with sudo chown root. Because the installer searches its own directory for that filename, it can use the stored token during registration. From the directory containing the package, install the Agent with sudo installer -pkg “./[SentinelOne Package File Name].pkg” -target /.
Alternatively, use the Installation Wizard when the person installing the software is given the token string directly. Provide the Site Token or Group Token in a message or email, run the SentinelOne package, and enter the token when the wizard requests it. Each Mac requires that one-time token-entry step. Once the prerequisite approval has been completed, it does not need to be repeated for later SentinelOne application updates.
After installation, look for the SentinelOne status-bar icon and open it to check for an online status in the top right. Opening the status display should show that the token was applied and that the Mac is reporting to the SentinelOne dashboard. When a script-based deployment reports successful execution, confirm that its deployment status also shows a successful installation. Administrators troubleshooting a Mac with no installed Agent can collect the installer log with cp /var/log/install.log ~/Desktop.
Administrators should obtain a current macOS .pkg installer scoped to the destination Site, along with that Site Token or a Group Token, before beginning deployment. Select the latest macOS package from Packages in the Sentinels toolbar for the documented one-endpoint console workflow, after confirming that the package scope includes the Site to which the Agent will be assigned.
Package scope matters because the installer and registration token associate the Mac with the intended SentinelOne tenant or organization. A Site Token is a unique string that identifies that tenant or organization, while a Group Token is also accepted in the documented local installation workflow. Retain the applicable token before proceeding, since the Scalefusion deployment script requires a token for activation.
Avoid selecting a package by matching a filename printed in an example. The example names Sentinel-Release-23-4-1-7125.pkg and Sentinel-Release-25-1-2-8039_macos_v25_1_2_8039.pkg are examples as of September 2026, not replacements for the current installer package supplied for the account. Use the account-supplied package rather than substituting one of those labels.
For MDM deployment, collect the installer and registration material in the format required by the management platform before assigning software to devices. Endpoint Central uses a file named com.sentinelone.registration-token, uploaded under Installation before the SentinelOne Mac package. Jamf Now instead requires a macOS package containing a registration-token plist at /Library/Managed Preferences/com.sentinelone.registration-token.plist, with the supplied Site Token string placed in that plist. Scalefusion deployment similarly needs the token and the agent package, while its script writes the token file and installs the package from /tmp.
When using the Installation Wizard route, prepare the token string for delivery to the user, such as through a message or email. Each Mac requires the token to be entered when the wizard requests it. That route makes the token string, rather than a token file or packaged plist, the registration material to have ready before the SentinelOne Agent installation begins.
Follow the Local Mac Installation Steps
For one Mac, install the SentinelOne Agent by placing a plain-text registration-token file beside the package in /tmp and running the package with administrator privileges. Alternatively, use the Installation Wizard, enter the supplied token when prompted, and complete that token-entry step once on each endpoint.
Use the local endpoint for this workflow. Guardz directs administrators to change the token file’s ownership to root with sudo chown root. That file name must remain exactly com.sentinelone.registration-token. The installer searches the same directory as the .pkg for this file and uses its contents to register the Mac with the SentinelOne tenant.
Install from Terminal
Beyond that, use this Terminal sequence on the Mac after moving into /tmp:
- Place the .pkg installer in /tmp, where the registration file will be available to it.
- Save the token as plain text.
- Change its ownership by running sudo chown root com.sentinelone.registration-token.
- Replace the bracketed placeholder with the current package filename supplied for the account.
- Run the installer from that directory.
- Complete the required prerequisite approval so the Mac is fully protected.
Because the token file is part of registration, leave its contents as the supplied token string in plain text. The installer uses that neighboring file during installation to register the Mac with the SentinelOne tenant. Avoid changing the required file name, which is the name the installer searches for in its directory.
Use the Installation Wizard
During the Installation Wizard route, send the user the token string in a message or email, then have that user run the installation package. At the wizard prompt, enter the token string to register the endpoint. Each Mac requires that wizard token entry one time. Following completion of the prerequisite approval, later SentinelOne application updates do not require the approval again.
After the package finishes, look for the SentinelOne status-bar icon. Opening it should show online at the top right in the documented deployment example. This confirms the expected connection. Confirm the deployment status for script-based processes.
Guardz directs administrators to copy that log to the Desktop when no Agent is installed after the attempt. That command copies /var/log/install.log to ~/Desktop for the endpoint.
Set macOS Permissions Before MDM Deployment
Before an MDM installs the SentinelOne agent, enroll the Mac in MDM and deploy the required macOS configuration profiles. Endpoint Central identifies three pre-install requirements: Privacy Preferences Policy Control (PPPC), Web Content Filter, and System Extensions configurations.
These profiles manage the settings and permissions SentinelOne needs on the Mac. Enrollment comes first because configuration profiles are MDM payloads, which means they can only be deployed to devices already enrolled in the MDM service. For Endpoint Central, administrators can deploy the PPPC, Web Content Filter, and System Extensions settings together in one Custom Configuration Profile.
Endpoint Central Profile Setup
Administrators using Endpoint Central can create the required profile through Configurations > Configuration > Mac > Custom Configurations Computer Configurations. That profile should be deployed before the SentinelOne package is sent to devices. In the same platform, the package workflow is available through Software Deployment > Package Creation > Packages > Add Package > Mac, where the registration-token file is uploaded under Installation along with the SentinelOne installer package.
Jamf Now uses its own deployment structure for SentinelOne macOS permissions. Its documented method includes creating and uploading a PPPC custom profile with iMazing, then assigning the required packages to the appropriate Blueprints.
Platform Details to Consider
After the required profiles are in place, the agent package can be deployed through the MDM’s package workflow. Each management platform has a distinct token-delivery method, so use the workflow intended for that MDM rather than substituting a token path from another deployment route. Where Bluetooth Device Control is needed, macOS Sonoma supports it from Agent version 23.3+, while macOS Ventura does not support Bluetooth Low Energy Device Control rules. Successful package deployment can then be checked through the MDM’s device or application-status views.
Compare Token Methods Across Deployment Routes
Local command-line deployment uses its documented token method, while managed routes carry registration data through their own upload, script, or plist method. Rather than treating those paths as interchangeable, use the workflow designed for the deployment product because token placement and package handling differ.
| Deployment Route | Token Method | Installation Action | Check |
|---|---|---|---|
| Local command line | com.sentinelone.registration-token in /tmp with the installer | Run the macOS .pkg installer | Collect /var/log/install.log if no Agent installs |
| Installation Wizard | Give the user the token string | Enter the token when prompted | Token entry occurs once per endpoint |
| Endpoint Central | Upload the token file under Installation | Add the SentinelOne Mac package | Follow package deployment status |
| Intune script | Create the token file in /tmp, then remove it after installation | Install the Agent through the script | Status-bar icon shows online |
| Jamf Now | Package a token plist in /Library/Managed Preferences | Upload token and vendor packages to Blueprints | Check the Mac’s Mac Apps tab |
For one Mac, use the local command-line token method before installation. Endpoint Central uses its documented command-line pattern.
Unlike the hand-run approach, token handling becomes part of package deployment rather than a file prepared manually on every Mac. Its deployment record separates the registration-token upload from the SentinelOne installer-package upload. Administrators should also ensure the downloaded package scope includes the destination Site before deployment.
Intune-oriented scripts create /tmp/com.sentinelone.registration-token, install the SentinelOne Agent, and remove the token file afterward. Scalefusion similarly uses its deployment method. Because Scalefusion uses a shell-script deployment, its MDM Client Application must be installed on targeted devices, and the script is set not to run as the signed-in user.
Jamf Now uses a separate managed-preferences method instead of the /tmp token-file approach. After creating /Library/Managed Preferences/com.sentinelone.registration-token.plist with the supplied Site Token, set its permissions to mode 644, package it, and assign both packages to the needed Blueprints. Installation status for the SentinelOne package appears in the individual Mac’s Mac Apps tab.
The local command line method and Scalefusion use a plain token file in /tmp, while Jamf Now expects a plist in its managed-preferences location. Those are different delivery mechanisms, not competing instructions. For a single Mac, the local method is the more direct choice; for managed fleets, I would let the MDM workflow determine the token format and placement.
Verify the Agent and Resolve Installation Failures
Successful registration is confirmed when the SentinelOne status-bar icon is present and the application shows online at the top right. For an Intune deployment, that online state confirms registration. Administrators should also review the deployment result after successful script execution.
In Jamf Now, open the individual Mac and check the SentinelOne package’s installation status in the Mac Apps tab. That console check is specific to the Jamf Now workflow and provides a package-level view for the selected device. A successful package result complements the Agent’s online status, which confirms registration and dashboard communication in the stated Intune example.
If no Agent is installed, collect the available installer log. Copying the log to the Desktop follows the documented collection step for an endpoint without an installed Agent. Guardz directs administrators to use this log collection when no Agent is installed, providing the stated record for review.
Before treating an installation as complete, distinguish a package deployment from a registered, reporting Agent. Package-status checks show the installation result in Jamf Now, while the online indicator provides the Intune check. Neither verification view should replace the other where a deployment route offers its own stated check. Confirming the applicable Agent status separates installation from registration.
After a script reports success, use the reported deployment status alongside the Mac’s Agent indication where applicable. Different management routes expose different checks, so retain the installer log whenever no Agent appears. Those actions give administrators a focused way to confirm registration or gather the available evidence for follow-up. Likewise, package status in Jamf Now can be checked for each individual Mac.
Deploy with Jamf Now or Scalefusion
Jamf Now and Scalefusion use platform-specific deployment workflows instead of a manually placed token file. Rather than treating their token locations as interchangeable, follow the method designed for the MDM platform managing the Mac.
Jamf Now Setup
Administrators using Jamf Now should follow the platform’s established package workflow for registration. Jamf Now’s deployment process then calls for uploading that token-plist package, uploading the SentinelOne installer package, and assigning both packages to the required Blueprints. Separately, create and upload a PPPC custom profile with iMazing as part of the Jamf Now setup.
Scalefusion Setup
Scalefusion deployments follow the platform’s established script workflow for token based agent installation. For this deployment route, the Scalefusion MDM Client Application must be installed on targeted devices. Script settings should also run the deployment as the signed-in user set to No.
Deployment logic can check for /Applications/SentinelOne/ before proceeding. When that directory exists, the documented Scalefusion script outputs “Already Installed” rather than continuing with installation. Because the token is required for activation, include the account’s supplied token in the script configuration before deploying it.
Unlike Jamf Now’s managed-preferences plist, Scalefusion uses the temporary /tmp token-file approach during script execution. Each platform therefore needs its own package or script preparation steps before assigning SentinelOne to managed Macs.
Frequently Asked Questions
Where Is the SentinelOne Site Token Location?
Download an installer package whose scope includes the destination Site, then save that Site Token or Group Token for the installation workflow. For a local command-line installation, place the token in a plain-text file alongside the installer in /tmp. Jamf Now uses a different deployment method, with the token stored in a plist under /Library/Managed Preferences.
What File Name Does the SentinelOne Registration Token Require on macOS?
For local command-line, Intune script, and similar deployment workflows, the file name must be exactly com.sentinelone.registration-token. Place it in /tmp with the SentinelOne .pkg installer for the local installation method. Guardz also directs administrators to change the token file owner to root.
Which macOS Permissions Are Required for SentinelOne MDM Deployment?
Before deploying SentinelOne through Endpoint Central, deploy PPPC, Web Content Filter, and System Extensions configurations. Endpoint Central says these configurations can be delivered together in one Custom Configuration Profile. Jamf Now uses a PPPC custom profile created with iMazing before the packages are assigned to Blueprints.
How Do I Verify That the SentinelOne Agent Is Online on a Mac?
A successful Intune-style deployment produces a SentinelOne status-bar icon. Open the icon and check for online at the top right. That status means the Site Token was applied and the Mac is reporting to the SentinelOne dashboard.
What Should I Collect When SentinelOne Agent Installation Failed?
If no SentinelOne Agent is installed on the endpoint, collect the installer log. Guardz provides collection instructions. The copied log can then be reviewed as part of the installation troubleshooting process.
Successful SentinelOne installation on macOS depends on matching the token method to the deployment route. Use the exact registration-token filename for local and script-based deployments, while Jamf Now uses its token-plist package method. Confirm that the installer package is scoped to the intended Site, deploy required MDM permission profiles before the agent where applicable, and check the SentinelOne status-bar icon for an online connection after installation.
References
- SentinelOne FAQ | Platform, Support & More, sentinelone.com
- macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox | SentinelOne, sentinelone.com
- Reddit – The heart of the internet, Reddit, reddit.com
- SentinelOne Installation – macOS | Guardz Help Center, Guardz Help Center, support.guardz.com
- How to install SentinelOne antivirus agent?, ManageEngine Endpoint Central, manageengine.com
- Deploy SentinelOne for macOS with Intune, SMBtotheCloud, SMBtotheCloud, smbtothecloud.com
- Install SentinelOne on macOS devices, Scalefusion Help Docs, help.scalefusion.com
- How to Install SentinelOne with Jamf Now | Jamf Support Portal, Jamf Support Portal, support.jamf.com
Sources read in September 2026.
