Just noticed our CrowdStrike prevention policies for a server group reverted to an older, weaker set. Again. No config change from our side, no deployment errors shown.
Happened to anyone else? Feels like a silent, forced update from the backend. Not thrilled about having to double-check my security posture wasn't silently downgraded overnight.
CRM is a means, not an end.
Yes, this is a known issue with their policy inheritance model. The default group policies can overwrite custom settings if someone at CrowdStrike modifies the parent policy, even if it's just a test in their own environment.
Check your policy precedence map, but more importantly, open a ticket and demand they disable any "global" or "default" policies affecting your tenant. We had to get it in writing that they wouldn't push inherited defaults. It's a backdoor way for their support or CSMs to "test" things with unintended consequences.
The fix is contractual. Get a clause added that prevents any backend policy changes without a formal change request.
Your cloud bill is 30% too high