Open add/remove programs and select the Falcon Agent, and click uninstall: When Uninstall Protection is enabled and an uninstall is initiated, users are presented with the setup dialog and are required to input the token obtained from the Falcon UI. Navigate to Host App > Host Management, then select the host of interest and click “Reveal maintenance token” and you are presented with the one-time maintenance token, which can be given to the end-user/technician updating or uninstalling the Falcon Agent.Įven if the device is offline, the token will allow the uninstall/update to proceed. To simplify the management of protected Falcon Agent installations, maintenance tokens can be accessed from the Hosts app. With this policy applied to our devices, an uninstall will now require a token to complete.įalcon Uninstall Workflow with Protection Enabled Within the Falcon Update Policy, Sensor Uninstall Protection is configurable (Configuration > Sensor Update Policies > Sensor Protection). This role must be enabled against the Falcon user’s account in order to obtain maintenance tokens or manage policy related to Uninstall Protection. The “Maintenance Manager” role is available which grants permission to access the maintenance tokens. Uninstall Protection also adds a layer of protection that prevents unauthorized users from removing the sensor. ![]() Once enabled in the policy, helpdesk teams can provide one-time device-specific maintenance tokens as needed. Uninstall Protection can be controlled by policy, making it easier to lock down sensitive devices. Crowdstrike offers an easy to use Uninstall Protection process for the Falcon Agent.
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |