ForumsEndpoint & XDR

Multi-tenant EDR for an MSSP: what we learned migrating 60 clients

Implementation notes about SentinelOne Singularity 25 Jun 2026 668 views
Daniel Okonkwo Sample Runs an MSSP serving 60 mid-market clients. · member since Feb 2026

Finished a migration of about 60 client tenants and wrote up what I wish I had known.

One, tenant separation on paper and tenant separation in the console are different things. Ask to see a real multi-tenant deployment, not a demo tenant.

Two, uninstall protection on the outgoing product will cost you more time than installing the new one. Budget a week per 500 endpoints for the stragglers.

Three, agree who owns policy. If every client can edit their own policy you will spend your life explaining why a detection was disabled.

3 replies

Gaurav Malhotra Sample MSP owner. Sells outcomes, not licences. · 2 months ago

The uninstall estimate matches ours almost exactly. The stragglers are always machines that have not been on the network for months, and they come back one at a time over the following quarter.

On policy ownership: we made it a contract clause rather than a technical control. Clients can request a change, we implement it, and the request is logged. That has been worth more than any RBAC setting.

Vikram Nair Sample Boutique MSP. Two engineers, 900 endpoints, no budget for shelfware. · 2 months ago

Would add a fourth: agree the exclusion process before migration, not during. We inherited 200 exclusions from the old product, most undocumented, and moving them wholesale would have carried the previous team's mistakes into the new tool. We rebuilt from zero and added back with justification. Painful, right decision.

Daniel Okonkwo Sample Runs an MSSP serving 60 mid-market clients. · 2 months ago

Rebuilding exclusions from zero is the advice I would give my past self. We carried ours across and are still finding ones nobody can explain.

Sign in or join to reply.