Skip to content
CELS Virtual Helpdesk

CELS Virtual Helpdesk

  • Systems Group
  • Blog
  • Documentation

CELS Virtual Helpdesk

CELS Shared Services Systems Group

EDR Update: macOS rollout begins Monday

March 3, 2023 by Stacey, Craig

Hi, everyone!  Happy March!  We’re going to have a few short announcements regarding the EDR rollout over the course of the month as we get things put into place across the various operating systems we have.  For background, see my previous EDR announcement.

This first one is for macOS.  For all managed and co-managed machines, we’re going to push out the profile for CrowdStrike Falcon on Monday.  (For completely self-managed machines, please see these instructions.) This will send the software to your computer but it will not automatically install it.  The reason we’re taking this approach is that in the process of installing the software, the network component will cause a brief interruption in any active network connections, and we don’t want you to lose any work due to a network blip.

Instead, we’ve got it set to install on the next login.  So after Monday (let’s say end of day to be safe), when you’re at a good spot for that sort of thing, logout of your Mac.  You don’t need to restart for this, but if you’ve got pending updates this is a good opportunity to take care of them and restart all the same.

After the installation happens, depending on the version of macOS you’re running, you’ll see notifications of what’s been installed and what is happening.  Ventura users will see notifications related to the background tasks that launch on login to run the Falcon sensor.  You may also see the Falcon sensor asking permission to send you notifications.  I recommend allowing that, as it will tell you when it finds something, but if you disallow that the findings are still reported back to the server regardless.

If you run third party network filtering software (for example, Little Snitch) you will also be asked for network permission to contact the Crowdstrike server.  You really do need to allow that.  If you disallow it, the software isn’t doing its job, and we’ll eventually reach out to you to ask why the sensor isn’t able to report home or get updates.

After that, you’re done.  It’s installed.  It will self-update, it will handle malicious software, and notify us or Cyber where necessary.

For more information, see the Crowdstrike FAQ.

Thanks!

Post navigation

Previous Post:

February Newsletter: Legacy Retirement Imminent (due March 31)

Search Docs

Search for:
  • Service Catalog
  • Request…
    • a Confluence space migration
    • a Database
    • a domain name
    • a GCE Unix Group
    • an IP Address
    • a Laptop Build
    • a loaner laptop
    • a jira.cels.anl.gov account
    • a JIRA project
    • a Mailing List
    • an Overleaf account
    • a port activation
    • a poster print
    • a reactivation for a returning user
    • an upgrade to Slack Business Plus from Free.
    • a WordPress migration
    • a WordPress site
    • an xgitlab or gitlab migration
    • a Zoom license upgrade

Previous Dispatches

Site search

Search Documentation

Search for:

Privay & Security Notice

Privacy & Security Notice

Site tools

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2023 CELS Virtual Helpdesk | WordPress Theme by Superbthemes