{"id":75155,"date":"2023-05-18T16:54:21","date_gmt":"2023-05-18T20:54:21","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=75155"},"modified":"2024-09-13T11:44:13","modified_gmt":"2024-09-13T15:44:13","slug":"install-the-crowdstrike-falcon-agent","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/install-the-crowdstrike-falcon-agent","title":{"rendered":"Install the CrowdStrike Falcon Agent"},"content":{"rendered":"\n
You can download and install the CrowdStrike Falcon Agent on Windows and macOS devices from the JumpCloud Admin Portal. CrowdStrike provides cloud security and threat detection software. <\/p>\n\n\n\n
For macOS devices, you\u2019ll also need to apply a policy in JumpCloud that creates a Mobile Device Management (MDM) profile and sets the necessary permissions required by the CrowdStrike Falcon Agent. If you’re running macOS on an Intel processor that uses a kernel extension with the CrowdStrike firmware analysis tool, you\u2019ll need to apply a second policy.<\/p>\n\n\n\n
<\/p><\/div>
For macOS devices, you should create and apply the CrowdStrike policy before<\/em> you deploy the CrowdStrike app.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Every Apple silicon and macOS device requires the CrowdStrike Falcon MDM Settings (No kernel extension) Policy described below. If you have a macOS device on Intel that includes a kernel extension policy to run CrowdStrike\u2019s firmware analysis tool, you\u2019ll also need to apply the CrowdStrike Falcon Firmware Analysis Settings Policy (Intel only).<\/p>\n\n\n\n Have your CrowdStrike Customer ID (CCID) checksum handy because both CrowdStrike policies will use it to create the MDM profile.<\/p>\n\n\n\n To create a macOS CrowdStrike Policy<\/strong>:<\/p>\n\n\n\n <\/p><\/div> If the command doesn\u2019t run, verify that you have root permissions.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To further verify the policy, run this command:<\/p>\n\n\n\n \/usr\/libexec\/PlistBuddy -c “print” \/Library\/Application Support\/com.apple.TCC\/MDMOverrides.plist<\/p>\n<\/div><\/div>\n\n\n\n The CrowdStrike policy does not appear in Apple\u2019s System Settings > Privacy & Security > Full Disk Access<\/strong> location. That location contains policies that the user approves or has approved, rather than Admin-approved policies like the Application Privacy Preferences Policy.<\/p>\n\n\n\n <\/p><\/div> MacOS 15 Sequoia will disable the option to toggle the Crowdstrike extension under System Settings > General > Login Items & Extensions > Endpoint Security Extensions<\/strong> for end users.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To install the CrowdStrike Falcon Agent on a macOS device<\/strong>:<\/p>\n\n\n\n <\/p><\/div> This script works for many situations; you might need to alter some variables for your organization. For more information, see the CrowdStrike documentation.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n <\/p><\/div> If your organization is treating Full Disk Access of tools other than Falcon as an Immediate remediation item for your security posture and ZTA score, CrowdStrike will alert when other software has Full Disk Access. JumpCloud requires Full Disk Access to control PAM module settings on a macOS device. <\/p><\/div> For installation troubleshooting information, see Troubleshooting<\/a> below.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To install the CrowdStrike Falcon Agent on a Windows device<\/strong>:<\/p>\n\n\n\n <\/p><\/div> This script works for many situations; you might need to alter some variables for your organization. For more information, see the CrowdStrike documentation.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\nCreating a MacOS CrowdStrike Policy<\/h2>\n\n\n\n
\n
\n
\n
<\/li>\n\n\n\n\n
<\/li>\n\n\n\n\n
<\/li>\n<\/ol>\n\n\n\nInstalling the CrowdStrike Falcon Agent<\/h2>\n\n\n\n
MacOS<\/h3>\n\n\n\n
\n
\n
<\/li>\n\n\n\n
<\/li>\n\n\n\n\n
<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n\n
\n\n
\n\n
This may cause an alert that you could interpret as the CrowdStrike Falcon agent not having access to the Full Disk Access settings. That is not the case. In the event that Full Disk Access is listed as a red item in the ZTA score breakdown, that is because an application that is not Falcon has Full Disk Access.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n\n
Windows<\/h3>\n\n\n\n
\n
\n
<\/li>\n\n\n\n
<\/li>\n\n\n\n\n
<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n\n
\n\n
\n\n