Skip to content

TPower2112/Writing-Sample-2

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

43 Commits
 
 
 
 
 
 

Repository files navigation

CrowdStrike: Falcon Sensor Upgrade for Big Sur

User Experience for the CrowdStrike Mac Sensor Upgrade Process

Table Of Contents

  1. Objective

  2. The User Experience for endpoints not enrolled in JAMF

    A. Approving Network Content Filtering

    B. Approving System Extension

    C. Approving Full Disk Access

  3. The Apple "Falcon Notifications" Prompt

  4. What happens if an end user chooses an incorrect prompt?

Objective

This document illustrates the correct security options the user must choose to provide protection on an endpoint that is not enrolled in JAMF.

If a workstation is managed by JAMF, the three options for enabling Network Filtering, the CrowdStrike Security Extension, and Full Disk Access, are set automatically in the MDM profile.

The User Experience for endpoints not enrolled in JAMF

The upgrade to the latest sensor occurs silently in the background with no restart or reboot required. The end user must enable the following three prompts.

A. Approving Network Content Filtering

The end user must allow the Falcon sensor to filter network content. Please select Allow from the prompt below:

Network Content Filter

B. Approving System Extension

Apple implemented system extensions instead of kernel extensions in Big Sur. The end user will see the following prompt and must open Security Preferences.

Security Preferences

Under the General tab in Security & Privacy settings, select Allow for Falcon application.

Allow System Extension

C. Approving Full Disk Access

Full disk access is required for Catalina and later operating systems. The end user must grant full disk access on the host. Administrator account permission is required. Please follow the instructions below to enable full disk access:

  1. Select the Apple icon and Open System Perferences, then click Security & Privacy.
  2. On the Privacy tab, if privacy settings are locked, select the lock icon and specify the password.
  3. In the left pane, select Full Disk Access.
  4. In the right pane, select the plus icon and the check box next to Agent. Allow Full Disk

The Apple "Falcon Notifications" Prompt

The Falcon Notifications notifications prompt is displayed at the end of the installation. Security Operations recommends the end user to select Allow.

Allow Falcon Notifications

What happens if an end user chooses an incorrect prompt

If an end user chooses an incorrect prompt, CrowdStrike will not operate properly. The end user can reload the system extensions by running the following command in the Terminal application:

sudo /Applications/Falcon.app/Contents/Resources/falconctl load

Releases

No releases published

Packages

No packages published