First Endpoint Setup & Registration
Edit ArticleHow device identity tokens, DPAPI encryption, and initial policy synchronization work.
When Sentinel starts on a computer for the first time, it performs an automated initial handshake with the server to establish a cryptographic device identity.
The 3-Step Device Registration Process
Hardware Fingerprint Generation
The agent inspects the local motherboard UUID, disk serial number, and MAC address to create a tamper-proof hardware fingerprint.
DPAPI Token Encryption
Upon server approval, the server returns an encrypted device session token stored securely at "C:\ProgramData\Sentinel\registration.dat" using Windows Data Protection API (DPAPI).
Policy Pull & Immediate Heartbeat
The agent pulls the latest assigned monitoring policy and immediately sends its first heartbeat containing OS build, logged-in user, and hardware specs.
Was this documentation page helpful?
Your technician feedback helps our team continuously improve Sentinel guides.

