> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy CrowdStrike as a Custom App

> Deploy the CrowdStrike Falcon sensor to Mac computers as a custom app in Iru Endpoint. Package the installer, add the customer ID, and approve extensions.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Mac computers</Callout>

### Prerequisites

<Warning>
  Intel-based Mac computers require the KEXT version of the Crowdstrike settings profile when using Crowdstrike's Firmware Analysis feature. If you are not using Firmware Analysis, we recommend using the non-KEXT versions of the custom settings below.
</Warning>

* CrowdStrike installer from the vendor (Hosts > Sensor Downloads)
* Crowdstrike Custom Settings
  * **All Mac Architectures**
    * macOS 15 (Sequoia) ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_settings_macOS15.mobileconfig))
  * **Apple Silicon**
    * All macOS Versions ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_settings.mobileconfig))
  * **Intel with KEXT**
    * All macOS Versions ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_settings_with_kext.mobileconfig))
* CrowdStrike Service Management Profile
  * macOS 13 (Ventura) - macOS 15 (Sequoia) ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_service_management.mobileconfig))
* CrowdStrike Audit Script ([GitHub Link](https://github.com/kandji-inc/support/tree/main/custom-apps/crowdstrike/crowdstrike_falcon_ae_script.zsh))
* CrowdStrike Postinstall script ([GitHub Link](https://github.com/kandji-inc/support/tree/main/custom-apps/crowdstrike/crowdstrike_falcon_postinstall_script.zsh))

### Considerations

* The **CrowdStrike Settings Profiles** are designed to facilitate the approval of CrowdStrike across all network content filters, kernel extensions, system extensions, PPPC, and web-filtering requirements. This profile is compatible with both the older Falcon agent using kernel extensions and the latest version using system extensions
  * You will need to deploy both the **crowdstrike\_settings\_macOS15** and **crowdstrike\_settings** profiles following the steps in the [Deploying with Assignment Maps](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#deploying-with-assignment-maps) section to assign them correctly
* The **CrowdStrike Service Management Profile** handles essential login and background processes
* If you require it, the **Legacy System Extension (KEXT) Settings Profile** can be accessed via this [GitHub link](https://github.com/kandji-inc/support/tree/main/custom-apps/crowdstrike/crowdstrike_settings_with_kext.mobileconfig)
  * This profile supports both the Falcon agent with kernel extensions and the newer version with system extensions
  * The KEXT payload is necessary only when using the CrowdStrike Firmware Analysis feature on Intel-based Mac computers
* Please note that depending on the specific CrowdStrike product and version you have installed, there may be variations in app paths, privacy access settings, and kernel or system extension requirements. As with any Custom App, we strongly recommend thorough testing before deploying it to a production Mac

### Add and Configure the Custom Profiles

<Note>
  The service management profile for Crowdstrike Falcon is compatible with macOS 13 Ventura and later. For macOS Monterey 12 and earlier, an Assignment Map must be used for advanced scoping to prevent the service management profile from being assigned to those devices. To learn more about deploying Crowdstrike in Assignment Maps, follow the [Deploying with Assignment Maps](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#deploying-with-assignment-maps) section.
</Note>

To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article.

<Steps>
  <Step title="Name the Profile">
    Give your Custom Profile a **Name**.
  </Step>

  <Step title="Select Platform">
    For **Install on**, select Mac.
  </Step>

  <Step title="Assign to Blueprint">
    Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints).

    <Frame>
      <img src="https://mintcdn.com/iru/ra-017G2NJ9qGfJp/assets/media/images/Kandji-Support-KB-0907AM@2x.png?fit=max&auto=format&n=ra-017G2NJ9qGfJp&q=85&s=4798bd05184c8d619aa213b222da505f" alt="Custom Profile configuration showing Blueprint assignment options" width="2968" height="1720" data-path="assets/media/images/Kandji-Support-KB-0907AM@2x.png" />
    </Frame>
  </Step>

  <Step title="Upload Settings Profile">
    Upload the CrowdStrike Settings Profile (or Legacy System Extension (KEXT) settings profile).

    <Frame>
      <img src="https://mintcdn.com/iru/Pp4ndpzRp4nipP1L/assets/media/images/2h7wntz3918tglf1aqik1_zegbwd4fnsya.png?fit=max&auto=format&n=Pp4ndpzRp4nipP1L&q=85&s=42d80957d9e87c33b12893c9f3a7d586" alt="Custom Profile upload showing CrowdStrike settings profile selection" width="2688" height="1730" data-path="assets/media/images/2h7wntz3918tglf1aqik1_zegbwd4fnsya.png" />
    </Frame>
  </Step>

  <Step title="Save Profile">
    Click **Save**.
  </Step>

  <Step title="Create Additional Profiles">
    Repeat the previous steps in this section for the **crowdstrike\_settings\_macOS15** and **crowdstrike\_service\_management** profiles.
  </Step>
</Steps>

### Add and Configure the Custom App

To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article.

<Steps>
  <Step title="Name the Custom App">
    Give the Custom App a **Name**. Optionally, add a custom icon.
  </Step>

  <Step title="Assign to Blueprint">
    Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints).

    <Frame>
      <img src="https://mintcdn.com/iru/ra-017G2NJ9qGfJp/assets/media/images/Kandji-Support-KB-0924AM.png?fit=max&auto=format&n=ra-017G2NJ9qGfJp&q=85&s=8b1ce019d9284f94e5e0ff1d4c19dad2" alt="Custom App configuration showing Blueprint assignment options" width="2966" height="1420" data-path="assets/media/images/Kandji-Support-KB-0924AM.png" />
    </Frame>
  </Step>

  <Step title="Set Installation Type">
    Change the **Installation** to Audit and Enforce.
  </Step>

  <Step title="Configure Audit Script">
    Copy and paste the crowdstrike\_ae\_script.zsh script from the [prerequisites](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#prerequisites) into the **Audit & Enforce** text box. No modification is required.

    <Frame>
      <img src="https://mintcdn.com/iru/ra-017G2NJ9qGfJp/assets/media/images/Kandji-Support-KB-0926AM@2x.png?fit=max&auto=format&n=ra-017G2NJ9qGfJp&q=85&s=cae2a07f5c4a5bb7316589b336a960d0" alt="Custom App audit and enforce script configuration" width="2960" height="1468" data-path="assets/media/images/Kandji-Support-KB-0926AM@2x.png" />
    </Frame>
  </Step>

  <Step title="Select Deployment Type">
    Select Installer **Package (install .pkg or .mpkg)** as the deployment type.
  </Step>

  <Step title="Upload Installer">
    Upload the installer package.
  </Step>

  <Step title="Configure Postinstall Script">
    Paste the **Postinstall Script** referenced in the [Prerequisites](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#prerequisites).

    * In the Post-Install script, update the **customerIDChecksum** variable on line 55 with your Customer ID
    * Optionally, paste your install token on line 59 inside the **installToken** variable; otherwise, leave it blank

    <Frame>
      <img src="https://mintcdn.com/iru/ra-017G2NJ9qGfJp/assets/media/images/Kandji-Support-KB-0929AM@2x.png?fit=max&auto=format&n=ra-017G2NJ9qGfJp&q=85&s=2b228d1b68277acc394340ceb2fb014e" alt="Custom App postinstall script configuration showing customer ID and install token settings" width="2962" height="2346" data-path="assets/media/images/Kandji-Support-KB-0929AM@2x.png" />
    </Frame>
  </Step>

  <Step title="Save Custom App">
    Click **Save**.
  </Step>
</Steps>

### Deploying with Assignment Maps

There are four Crowdstrike Custom Profiles that need conditional logic to ensure they are deployed to the correct devices. An Assignment Map provides an easy solution for all of your devices in one convenient view.

Please review our [Creating a Blueprint](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) articles.

<Steps>
  <Step title="Create Base Conditional Block">
    Start with the **For All devices on this Blueprint** conditional block.
  </Step>

  <Step title="Assign Custom App">
    Assign the **Crowdstrike** Custom App to the block.

    If multiple Custom Apps are needed, create a conditional block with conditions for the different versions of the installer.
  </Step>

  <Step title="Set macOS 15+ Condition">
    Set the top of the conditional block to **If** **macOS is greater than or equal to 15.0**.
  </Step>

  <Step title="Assign macOS 15+ Settings Profile">
    Assign the **crowdstrike\_settings\_macOS15** Custom Profile to the conditional block.
  </Step>

  <Step title="Set Apple Silicon Condition">
    Set the top of the conditional block to **If** **Chip type is Apple Silicon**.
  </Step>

  <Step title="Assign Apple Silicon Settings Profile">
    Assign the **crowdstrike\_settings** Custom Profile to the conditional block.
  </Step>

  <Step title="Set Intel Condition">
    Set the bottom conditional block to **else if Chip type is Intel**.
  </Step>

  <Step title="Assign Intel KEXT Settings Profile">
    Assign the **crowdstrike\_settings\_with\_kext** Custom Profile to the conditional block.
  </Step>

  <Step title="Set macOS 13+ Condition">
    Set the top of the conditional block to **If macOS is greater than or equal to 13.0**.
  </Step>

  <Step title="Assign Service Management Profile">
    Assign the **crowdstrike\_service\_management** Custom Profile to the conditional block.

    <Frame>
      <img src="https://mintcdn.com/iru/6NXI9g0KcsHj7H5R/assets/media/images/Kandji-Support-KB-0743AM.png?fit=max&auto=format&n=6NXI9g0KcsHj7H5R&q=85&s=6e1ce15287e8725cd693c65e6f50a0c7" alt="Assignment Map configuration showing CrowdStrike deployment with conditional logic for different macOS versions and chip types" width="5652" height="1980" data-path="assets/media/images/Kandji-Support-KB-0743AM.png" />
    </Frame>
  </Step>
</Steps>
