Identity risk can shift in seconds — a lateral movement attempt, a credential misuse pattern, an abnormal login. Static endpoint policies can’t keep up on their own, and security teams are left doing the same thing over and over: watching risk climb in real time, then manually reassigning a host’s policy mid-incident to respond to it.
Silverfort closes that gap by feeding live identity and device risk directly into SentinelOne’s policy engine. The moment a host’s risk crosses a configured threshold, Silverfort automatically escalates it into a stricter, pre-configured SentinelOne policy group — applying every control configured for that group at once, not a single fixed action. When the risk resolves, the host reverts to its original policy group automatically, with no manual cleanup required.
Because escalation can be driven by identity risk, device risk, or both, protection scales precisely with the threat: a host stays escalated until every contributing risk factor has cleared, then steps back down on its own. SOC teams stop reconfiguring policy by hand and stay focused on investigation instead.
In this solution brief, you’ll learn how to:
- Trigger automatic policy escalation — move endpoints into a stricter SentinelOne policy group the instant Silverfort detects identity or device risk crossing a configured threshold.
- Apply full policy enforcement, not a single action — enforce every control configured for the escalated group at once, for broader containment than a fixed response.
- Keep policy continuously aligned with risk — let endpoints move between policy states automatically as risk changes, without manual reconfiguration.
