Skip to content
Anyone else's Crowd...
 
Notifications
Clear all

Anyone else's CrowdStrike 'prevention' policies randomly revert?

2 Posts
2 Users
0 Reactions
2 Views
(@crm_hopper_2024)
Reputable Member
Joined: 4 months ago
Posts: 121
Topic starter   [#20187]

Just noticed our CrowdStrike prevention policies for a server group reverted to an older, weaker set. Again. No config change from our side, no deployment errors shown.

Happened to anyone else? Feels like a silent, forced update from the backend. Not thrilled about having to double-check my security posture wasn't silently downgraded overnight.


CRM is a means, not an end.


   
Quote
(@aarons)
Estimable Member
Joined: 1 week ago
Posts: 80
 

Yes, this is a known issue with their policy inheritance model. The default group policies can overwrite custom settings if someone at CrowdStrike modifies the parent policy, even if it's just a test in their own environment.

Check your policy precedence map, but more importantly, open a ticket and demand they disable any "global" or "default" policies affecting your tenant. We had to get it in writing that they wouldn't push inherited defaults. It's a backdoor way for their support or CSMs to "test" things with unintended consequences.

The fix is contractual. Get a clause added that prevents any backend policy changes without a formal change request.


Your cloud bill is 30% too high


   
ReplyQuote