Sentinelctl.exe Unload !!top!! Jun 2026
The command must be executed from an elevated Command Prompt or PowerShell (Run as Administrator).
Once this completes, the agent's "purple icon" in the system tray will typically disappear or turn gray, indicating it is no longer active. How to Restart the Agent (Load)
If you need to disable the agent for maintenance, follow these steps: 1. Obtain the Passphrase Sentinelctl.exe Unload
Look for the menu or the device details panel to locate the Show Passphrase option. Copy this string. Step 2: Open an Elevated Command Line On the target Windows machine, click the Start menu. Type cmd or PowerShell .
| Command | Effect | |---------|--------| | sentinelctl disable | Disables policy enforcement but the kernel modules remain loaded (passive monitoring). | | sentinelctl unload | Unloads kernel modules entirely. Agent shows as "Not Active" or "Offline." | | sentinelctl load | Reloads the unloaded kernel components without rebooting. | The command must be executed from an elevated
Even with the correct syntax, sentinelctl.exe unload can fail. Here are the most common errors and their solutions.
The passphrase typed does not match the policy console. Obtain the Passphrase Look for the menu or
Understanding its syntax, requirements, and failure modes separates a junior admin from a seasoned endpoint security expert. When you run this command, you are momentarily stripping a machine of its defenses. Do so with intent, with a token, and with a clear plan to reload.
In some rare cases of corrupted installations, the unload command might hang. In these instances, administrators often turn to the , a specialized tool provided by SentinelOne support to "force" an agent removal when the standard CLI tools fail. Re-enabling Protection
When you run sentinelctl unload , the following components are typically removed from active memory:
Determining if the agent is conflicting with a legacy application.