Well that was a new one. Instead of just blocking my malicious activity SentinalOne just.... isolated the entire domain controller from the network.

I guess that is one way to do it...