Understanding Accounts, Sites and Licensing

Understanding Accounts, Sites and Licensing

Scope Hierarchy

SentinelOne uses a hierarchical structure to organize and manage your deployment.
Global → Account → Site → Group → Endpoint

Global

The Global scope represents the entire SentinelOne deployment.
Users with Global access can manage all Accounts, Sites, Groups, policies, and settings across the environment.

Account

An Account is a logical segment within a deployment.
Accounts are commonly used to separate business units, customers, departments, or managed environments.

Each Account:
  1. Can contain multiple Sites.
  2. Inherits settings from the Global level.
  3. Can have its own policies and configurations.
Notes
Multiple Accounts require the appropriate SentinelOne licensing.

Site

A Site is a physical or logical segment within an Account.

Examples include:
  1. Offices
  2. Departments
  3. Geographic regions
  4. Business units
Each Site:
  1. Belongs to a single Account.
  2. Has its own settings and policies.
  3. Contains one or more Groups.
  4. Receives licenses from its parent Account.
All SentinelOne Agents are assigned to a specific Site.

Group

Groups are logical collections of endpoints inside a Site.
Groups help organize devices and apply specific policies, exclusions, and configurations.
Groups do not control licensing or user permissions.

Types of Groups

Manual Groups

Endpoints are manually assigned to the Group.
Devices remain in the Group unless they are moved manually or match a Dynamic Group rule.

Dynamic Groups
Endpoints are automatically assigned based on filters and conditions.

For example:
  1. Operating System
  2. Device Name
  3. Domain
  4. Tags
  5. Agent Version
If an endpoint matches a Dynamic Group rule, it is automatically moved into that Group.

Pinned Groups
Pinned Groups override Dynamic Group assignments.
Endpoints assigned to a Pinned Group remain in that Group even if they match Dynamic Group criteria.

Accounts

Accounts are useful when different teams or administrators manage separate environments.

Each Account:
  1. Has its own license allocation.
  2. Has its own expiration date.
  3. Can contain multiple Sites.
  4. Can inherit settings from Global scope.
Account names must be unique within the deployment.

Sites

Sites represent individual environments within an Account.

Each Site:
  1. Belongs to only one Account.
  2. Has its own settings and policies.
  3. Receives licenses from the parent Account.
  4. Contains one or more Groups.
Site names must be unique within the same Account.
The same Site name can exist in different Accounts.

For example:
  1. Account A → IT
  2. Account B → IT

Licenses

Licenses are assigned at the Account level and distributed to Sites.
Each active Agent consumes a license.
An Agent is considered active if it has not been uninstalled or decommissioned.
Available license types depend on your SentinelOne subscription.

Examples include:
  1. Core
  2. Control
  3. Complete
  4. Mobile
  5. Add-on modules
If a Site is deleted, its licenses are automatically returned to the parent Account.
Alert
License deployment must match the purchased SKU. For example, workstation licenses should not be deployed to server environments.

Viewing Account and Site Information

View Sites in an Account

  1. Select an Account.
  2. Open Settings.
  3. Select Sites.
You can view:
  1. Site names
  2. License usage
  3. Total licenses
  4. Creation date
  5. Expiration date

View Site Details

  1. Select a Site.
  2. Open Sentinels.
  3. Select Site Info.
You can view:
  1. Site Token
  2. Site ID
  3. License allocation
  4. Creation date
  5. Expiration date

View Accounts

  1. 1. Select Global scope or a multi-account view.
  2. 2. Open Settings.
  3. 3. Select Accounts.
You can view:
  1. Account names
  2. License usage
  3. Creation date
  4. Expiration date

Site Expiration

When a Site expires:
  1. Endpoints remain assigned to the Site.
  2. Alerts are no longer shown in the console.
  3. Protection policies are reduced to detection mode.
  4. Agents continue communicating with the Management Console at reduced intervals.
If the Site is reactivated, it can take up to 60 minutes for Agents to resume normal communication.
To avoid unexpected license usage, regularly review inactive devices and configure automatic decommissioning where appropriate.

    • Related Articles

    • Managing Licenses within TSFA

      ThinkShield Firmware Assurance (TSFA) operates on a device-based SaaS model. Licenses for TSFA can be purchased through standard Lenovo channels and applied to UDS / TSFA. Within the TSFA portal, administrators can view the organization's purchased ...
    • Creating and Managing User Groups

      Grouping users is helpful for managing a large number of users - typically by geography, department, or role. Creating User Groups Navigate to User Management > User Groups. Click the ✚ Create Group button. In the Add group screen, fill in the group ...
    • Verifying the User is in the Administrators Group

      Purpose You must use an account that is a member of the Administrators group. This document is meant to show how to verify the Configuration Manager user is added to the Administrators group on the server/computer. Configuration The Administrators ...
    • Verifying Your User is in the WSUS Administrators Group

      Purpose You must use an account that is a member of the WSUS Administrators group. This document is meant to show how to verify the Configuration Manager user is added to the WSUS Administrators group on the WSUS server. Configuration The WSUS ...
    • An Error (1332) Occurred While Enumerating the Group Membership. The Member SID Could Not Be Resolved

      Symptom When running the Lenovo Patch Configuration Checker, a check or multiple checks for group membership returns a Fail in the result column and the details column displays An error (1332) occurred while enumerating the group membership. The ...