Prerequisites
- CrowdStrike installer from the vendor (Hosts > Sensor Downloads)
- Crowdstrike Custom Settings
- All Mac Architectures
- macOS 15 (Sequoia) and later (GitHub Link)
- Apple Silicon
- All macOS Versions (GitHub Link)
- Intel with KEXT
- All macOS Versions (GitHub Link)
- All Mac Architectures
- CrowdStrike Service Management Profile
- macOS 13 (Ventura) and later (GitHub Link)
- CrowdStrike Audit Script (GitHub Link)
- CrowdStrike Postinstall script (GitHub Link)
Considerations
- The CrowdStrike Settings Profiles are designed to facilitate the approval of CrowdStrike across all network content filters, kernel extensions, system extensions, PPPC, and web-filtering requirements. This profile is compatible with both the older Falcon agent using kernel extensions and the latest version using system extensions
- You will need to deploy both the crowdstrike_settings_macOS15 and crowdstrike_settings profiles following the steps in the Deploying with Assignment Maps section to assign them correctly
- The CrowdStrike Service Management Profile handles essential login and background processes
- If you require it, the Legacy System Extension (KEXT) Settings Profile can be accessed via this GitHub link
- This profile supports both the Falcon agent with kernel extensions and the newer version with system extensions
- The KEXT payload is necessary only when using the CrowdStrike Firmware Analysis feature on Intel-based Mac computers
- Please note that depending on the specific CrowdStrike product and version you have installed, there may be variations in app paths, privacy access settings, and kernel or system extension requirements. As with any Custom App, we strongly recommend thorough testing before deploying it to a production Mac
Add and Configure the Custom Profiles
Name the Profile
Select Platform
Assign to Blueprint
Upload Settings Profile

Save Profile
Create Additional Profiles
Add and Configure the Custom App
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article.Name the Custom App
Assign to Blueprint
Set Installation Type
Configure Audit Script

Select Deployment Type
Upload Installer
Configure Postinstall Script
- In the Post-Install script, update the customerIDChecksum variable on line 55 with your Customer ID
- Optionally, paste your install token on line 59 inside the installToken variable; otherwise, leave it blank

Save Custom App
Deploying with Assignment Maps
There are four Crowdstrike Custom Profiles that need conditional logic to ensure they are deployed to the correct devices. An Assignment Map provides an easy solution for all of your devices in one convenient view. Please review our Creating a Blueprint and Using Conditional Logic in Blueprints articles.Create Base Conditional Block
Assign Custom App
Set macOS 15+ Condition
Assign macOS 15+ Settings Profile
Set Apple Silicon Condition
Assign Apple Silicon Settings Profile
Set Intel Condition
Assign Intel KEXT Settings Profile
Set macOS 13+ Condition
Assign Service Management Profile
