Deploying Crowdstrike Falcon here via policy and manually approving them before deployment. So far they have been pretty stable as far as we can tell.
Just this week I got notice that "Falcon" was not approved in the Security System Prefs on a Mac that was not reporting in to Crowdstrike. The user unlocked the System Preference and approved it and it started reporting in again. Looking closer into the situation, we found a few dozen Macs that had Crowdstrike installed, but not reporting in to Crowdstrike. Checking into a few of these showed the same story - it was not approved and needed to be approved in the Security System Prefs. In once case I reinstalled from Self Service and it was happy again. We are not using a PPPC to set it up, but probably should - however there doesn't seem to be any great consensus on how to do it yet.
To find the Macs that were not reporting in to Crowdstrike, I had to take a report from CS of the ones that were reporting and then subtract that from our list of all Macs. I did that through some Excel magic, but would like to find a way to catch these in JAMF so I can make a smart group and target that group for a reinstall. But I don't know what to look for. The Falcon.app is already installed. I don't see anything under "Services" in JAMF that would seem to be a match. And I am stuck there - not knowing what else to look for to create a smart group that shows Macs with a broken Crowdstrike Falcon install.
Part II is trying to find out why some number of our Macs suddenly decided to 'unapprove' Falcon. I am sorting through the specs of the machines I found and no common thread yet - different OS levels, different hardware, different techs who initially set the machines up, different locations. Curious if anyone else has seen something similar.
"Save me, JAMF Nation - you're my only hope"
