Skip to content

Need urgent help? Call us at 440-991-9980

Computers & Devices

Security software blocked a file or program

What to do when SentinelOne quarantines something — including the one thing you should never do — and how to get a legitimate business tool approved.

4 min read Updated
  • sentinelone
  • edr
  • quarantine
  • security
  • antivirus
On this page

Every workstation runs SentinelOne, which watches for malicious behaviour rather than just known bad files. When it acts, it blocks or quarantines something and usually shows a notification.

That alert is the system working. The important thing is what you do next.

Do not restore it yourself

Even if you are certain the file is safe. Even if you have used it for years. Even if a colleague sent it.

Restoring quarantined items yourself defeats the protection, and if the detection was correct it can release something actively harmful onto the network. Send it to us instead. We can inspect it safely, tell you what it is, and release it properly if it is legitimate — usually within the hour.

There is no scenario where restoring it yourself is the right move, and we will never ask you to.

What to do when you see an alert

  1. Read it and note what was detected. The file name and path, and the detection name if shown.
  2. Photograph or screenshot it. Alerts often clear before you can write everything down.
  3. Note what you were doing — downloading something, opening an attachment, installing software, or nothing at all.
  4. Stop using that file.
  5. Tell us, even if the alert says it was resolved automatically. We see the alert on our side, but your context — where the file came from — is the part we cannot see.

If you were opening an email attachment

Treat that as urgent and call 440-991-9980.

An email attachment triggering a detection means someone is targeting your company, and there is a good chance colleagues received the same message. Telling us quickly lets us block it for everyone before someone else opens it.

Also read You received a suspicious email — how to check it and report it.

If the computer is unresponsive or behaving strangely

If SentinelOne has isolated the machine from the network, or you see multiple alerts, or files are being renamed or encrypted:

  1. Leave the computer powered on. Do not restart it and do not shut it down. Restarting destroys evidence we need and can, in some cases, make things worse.
  2. Disconnect it from the network — unplug the ethernet cable, or turn off Wi-Fi.
  3. Call us immediately. Do not email from that machine.
  4. Do not try to clean it up.

Network isolation is a deliberate protective action. It looks alarming — the machine appears to have lost internet — but it means the system caught something and contained it. Call us and we will investigate and release it when it is safe.

Legitimate software being blocked

It happens, particularly with:

  • Niche or industry-specific applications
  • Older software with unsigned installers
  • Developer and system administration tools
  • Anything downloaded from a file-sharing site rather than the vendor
  • Small vendors’ updaters

Send us the software name, the vendor’s website, what it is for, and where you downloaded it. We will verify it and add an exclusion if it checks out.

Always download from the vendor’s own website. A large share of the “false positives” we investigate turn out to be genuinely bundled with something unwanted, picked up from a download portal rather than the real source.

Please do not install software yourself

Not a rule for its own sake. Software installed without going through us tends to arrive without updates, without licensing, and occasionally with extras nobody wanted.

If you need a tool for your work, ask. We will look at it, check the licensing, get a price if needed, and deploy it properly. That is usually quicker than you would expect, and it means the thing is supported when it breaks.

Why the machine may be isolated

If SentinelOne has cut a computer off from the network, you will see:

  • No internet, no email, no access to shared drives
  • The machine otherwise running normally

That is containment, not a fault. Call us; we will look at what triggered it and either clean the machine or confirm it was a false alarm and reconnect it. Please do not try to reconnect it by other means — a phone hotspot, for instance — because that puts the containment in exactly the wrong place.

What we need

  • The alert text or a screenshot.
  • The file or program name.
  • Where it came from — email, download, USB stick, network share.
  • What you were doing.
  • The computer name or Service Tag.
  • Whether anyone else received the same file.

Seen an alert? Call 440-991-9980 or email support@iconiumnetworks.com. For anything involving an email attachment or a machine that has been isolated, please phone rather than email — those are the ones where minutes count.

Did this fix the problem?

If you followed these steps and it's still not working, get in touch and mention this article — Security software blocked a file or program — so we can skip the basics.

Still stuck? Email support at support@iconiumnetworks.com or call 440-991-9980 to open a ticket.