CrowdStrike is a cloud-based next-generation antivirus, EDR (endpoint detection and response) solution. You can deploy CrowdStrike in your infrastructure via a single lightweight agent. In this post, we will discuss how we can install CrowdStrike falcon agent / Sensor using Intune on Azure Ad joined devices.
data:image/s3,"s3://crabby-images/27a08/27a08c5ef4237d25ead490a27f5fa8fc649f55d7" alt="CrowdStrike Intune"
- Use the following code in Install.cmd. You should use your own CID (Customer ID)
@ECHO OFF
SET ThisScriptsDirectory=%~dp0
WindowsSensor.LionLanner.exe /install /quiet /norestart CID=02A1C79U38044E2XXXXXXX-FA
CrowdStrike Falcon Agent Install Switches
CID= | Customer ID Checksum, which is required when installing. |
MAINTENANCE_TOKEN= | Bulk Maintenance Token is retrieved from the CrowdStrike site when performing upgrades. |
/install | Install the sensor (default). |
/passive | The installer shows a minimal UI with no prompts. |
/quiet | The installer shows no UI and no prompts. |
/norestart | Prevents the host from restarting at the end of the sensor installation. |
- Now create an Intune package using Intune Packaging App. (Change source path and destination folder path)
PS C:\IntuneAppsWinAppsUtil> .\IntuneWinAppUtil.exe
Please specify the source folder: C:\CrowdStrike
Please specify the setup file: Install.cmd
Please specify the output folder: C:\CrowdStrike
Do you want to specify catalog folder (Y/N)?N
data:image/s3,"s3://crabby-images/501d0/501d0ca8da4a178ae2cc171e0e0c6b6036a86785" alt="Install CrowdStrike Intune"
- Select App Package file which we created earlier.
data:image/s3,"s3://crabby-images/7d584/7d584eba43d35fa0838e3cb96bfd1034c7628f1c" alt="CrowdStrike Sensor Intune"
- Add app information such as Name & Publisher
data:image/s3,"s3://crabby-images/d3d09/d3d09f1681bfd4be8f5e975fdc4add3100d70454" alt="Crowdstrike Deployment Intune"
- Specify the commands to install and uninstall this app
data:image/s3,"s3://crabby-images/dcf49/dcf495f1c31cf284c260e33c6464457bae432e78" alt="Intune CrowdStrike Installation"
- Select both OS system architecture and minimum OS to Windows 10 1607
data:image/s3,"s3://crabby-images/a665b/a665b754ef14180c3ee30f5044fc77ff4a20609d" alt="Falcon Agent Intune"
- On detection rule, select “Manually configure detection rules and Rule type Register”
data:image/s3,"s3://crabby-images/c9101/c9101dfb23a0812db099ffed0d24e4c243b43c4d" alt="Intune Detection Rule"
Path : C:\Program Files\CrowdStrike
File or folder : CSFalconController.exe
- Assign to the group you want to deploy printer using Intune.