Integrating with CrowdStrike

Ishita Snehil
Ishita Snehil
  • Updated

Connect CrowdStrike Falcon to Lifecycle Manager to sync client and device information for use in Deliverables.

Who can use this feature?

  • ScalePad Hub Administrators
  • Users with Manage Sync Settings permissions in their ScalePad Hub account.

What you'll need:

  • A CrowdStrike Falcon administrator account

Generate API credentials directly from CrowdStrike

Please refer to CrowdStrike’s API credentials quick start and the CrowdStrike OAuth2 documentation if you have any questions.

  1. Sign in to the CrowdStrike Falcon console.
  2. Open Support > API Clients and Keys.
  3. Select Add new API client.
  4. Enter a name for the API client.
  5. Enable the Hosts: READ permission.
  6. Save the API client.
  7. Copy the client ID and client secret and store them in an approved password manager.

The client secret is used with the client ID to authenticate through OAuth 2.0. 

Connect CrowdStrike to Lifecycle Manager

  1.  Log into the ScalePad Hub and click Integrations
  2. Click + Add Integration
  3. Search and Select CrowdStrike.
  4. Enter your CrowdStrike Client ID.
  5. Enter your Client Secret.
  6. Select the CrowdStrike cloud Region for your account:
    • US-1
    • US-2
    • EU-1
    • US-GOV-1
    • US-GOV-2
  7. Select Connect.
  8. Confirm that the integration shows as connected.

Fields we are syncing data for

Client data

CrowdStrike field Lifecycle Manager field
Child CID Client identifier
Child client name Client name

Device data

CrowdStrike field Lifecycle Manager field
Device ID (AID) Device identifier
Hostname Host name
Platform name, OS version, and OS build Operating system
Local IP address IP address
External IP address Public IP address
MAC address MAC addresses
Serial number Serial number
System manufacturer Manufacturer
System product name Model
Last seen Last seen online
Last reboot Last reboot
Product type description Device type
Agent status and reduced functionality mode Antivirus status

How syncing works

For CrowdStrike Flight Control accounts, Lifecycle Manager retrieves the available child clients and syncs device data for each client environment.

Lifecycle Manager uses CrowdStrike’s Hosts API to retrieve device information. Device records are associated with the matching client in Lifecycle Manager and refreshed when the integration runs.

Troubleshooting

Symptom Likely cause Resolution
The connection fails The client ID, client secret, or region is incorrect. Verify the credentials and selected region in CrowdStrike, then reconnect.
The API client is rejected The API client does not have Hosts: READ permission. Update the API client permissions in CrowdStrike and reconnect.
Some clients or devices are missing The CrowdStrike account does not have access to the child client or device. Verify the client scope and device access in CrowdStrike.
Device information is outdated The latest synchronization has not completed. Run the integration again and verify the device in Lifecycle Manager.
Any questions? Reach out to our Lifecycle Manager support team by submitting a support ticket.
:sparkles: NEW :sparkles: Join our MSP Power-Ups - Free 15-minute micro-workshops + live Q&A with our Lifecycle Manager experts. Sign up here to reserve your spot.

Was this article helpful?

Yes! No