> For the complete documentation index, see [llms.txt](https://docs.balkan.id/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.balkan.id/getting-started/setting-up-your-tenant/application-integrations/direct-application-integrations/crowdstrike-integration-setup.md).

# CrowdStrike Integration Setup

### Getting Started

Use this guide to connect CrowdStrike to your BalkanID tenant. You will need API client credentials from the CrowdStrike Falcon console and access to the Integrations section in BalkanID.

{% hint style="info" %}
This integration reads the Falcon console's own user directory — who can sign in to CrowdStrike Falcon and which Falcon roles they hold. It is a different surface from [CrowdStrike Falcon](/getting-started/setting-up-your-tenant/application-integrations/direct-application-integrations/crowdstrike-falcon-integration-setup.md), which reads Falcon Identity Protection data about your Active Directory. The two can be connected independently, and they share no data.
{% endhint %}

#### Requirements:

Before you begin, collect the following values from CrowdStrike:

* **API Client ID**
* **API Client Secret**
* **Cloud Region (us-1, us-2, eu-1, us-gov-1, us-gov-2; leave blank to auto-discover)**
* **Customer ID (CID, optional)**

### Configure CrowdStrike within your BalkanID tenant

1. To create the **API Client ID** and **API Client Secret**, sign in to your CrowdStrike Falcon console with an account that can manage API clients.
2. Navigate to **Support & Resources > API Clients and Keys**, then click **Create API client**.
3. Enter a name for the client, and under **API scopes** enable **User management: Read** (see [Integration Scopes](#integration-scopes) below). Then click **Create**.
4. Copy the **Client ID** and **Client Secret**. CrowdStrike shows the secret only once — if you lose it you will need to create a new client.
5. Note your **Cloud Region**. It is the region your Falcon console runs in, shown as the base URL on the same page: `us-1`, `us-2`, `eu-1`, `us-gov-1` or `us-gov-2`. If you leave this blank, BalkanID works the region out from the credentials.
6. In BalkanID, go to **Integrations** and click **Add integration**.

<div data-with-frame="true"><figure><img src="https://2975852473-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbVGYwk8aSk5yI1GDPEW9%2Fuploads%2FXbob87wTWwhQL6t9MRT5%2Fadd-integration.png?alt=media" alt="The BalkanID Integrations page, with the Add integration button at the top right of the toolbar"><figcaption><p>Integrations page, with <strong>Add integration</strong></p></figcaption></figure></div>

7. Search for **CrowdStrike**, select it, then click **Next**.

<div data-with-frame="true"><figure><img src="https://2975852473-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbVGYwk8aSk5yI1GDPEW9%2Fuploads%2FDpVesf2UPLUu0T6c3lIR%2Fcrowdstrike-connect-application.png?alt=media" alt="Step one of the Connect a new application wizard with CrowdStrike searched for and selected"><figcaption><p>CrowdStrike selected in <strong>Connect a new application</strong></p></figcaption></figure></div>

8. Under **Data Sync Preferences**, choose the entity types you want BalkanID to sync. Everything supported is selected by default. Users are always synced and cannot be deselected, and the relationships between the types you select are synced for you.

<div data-with-frame="true"><figure><img src="https://2975852473-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbVGYwk8aSk5yI1GDPEW9%2Fuploads%2FX4brrvtFWY5dc6NAgn2P%2Fcrowdstrike-data-sync-preferences.png?alt=media" alt="The Data Sync Preferences panel showing the Users and Roles entity types and the required API scope"><figcaption><p><strong>Data Sync Preferences</strong> and the required API scope</p></figcaption></figure></div>

9. Under **Select Extraction Type**, choose **Direct Configuration**, then paste the values you collected into **API Client ID**, **API Client Secret** and **Cloud Region**. Leave **Customer ID (CID, optional)** empty unless you want BalkanID to read one specific child account under Falcon Flight Control — when it is empty, BalkanID reads the account the API client belongs to.

<div data-with-frame="true"><figure><img src="https://2975852473-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbVGYwk8aSk5yI1GDPEW9%2Fuploads%2FOSSApKHQSvLKVOxNZW75%2Fcrowdstrike-direct-configuration.png?alt=media" alt="The Direct Configuration section of the wizard showing the API Client ID, API Client Secret, Cloud Region and Customer ID fields"><figcaption><p><strong>Direct Configuration</strong> credential fields</p></figcaption></figure></div>

10. Click Next to move onto Optional Configuration.
11. Fill **Optional Configuration**, if required.

<div data-with-frame="true"><figure><img src="https://2975852473-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbVGYwk8aSk5yI1GDPEW9%2Fuploads%2FZbipc8nl8LTFl5YsVIaj%2Foptional-configuration.png?alt=media" alt="The Optional Configuration step, showing reviewer settings on the left and fulfillment options on the right"><figcaption><p>Optional Configuration</p></figcaption></figure></div>

12. Once you have filled in the information, click **Save**. Your integration is now configured and you will see the status of the integration displayed alongside other integrations on the Integrations page. When data is available, the integration Status column will read **Connected** and the integration Message will read **Data available**.

### Integration Scopes

| Read Only Scopes                                                                                                                                     | Lifecycle Management Scopes |
| ---------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------- |
| **User management (Read)** — the people who can sign in to your Falcon console, the Falcon roles available in it, and which roles each person holds. | N/A                         |

One scope covers everything this integration reads, so **User management: Read** is the only permission to enable on the API client.

A person can hold a Falcon role directly or inherit it through a user group. BalkanID reads both, and records how each role was granted, so a review shows whether removing someone from a group would actually take the role away.

Falcon console accounts carry no HR data, so no employee records are extracted. CrowdStrike's sensors are also not extracted — a Falcon sensor is an endpoint agent, not an identity that can hold access.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.balkan.id/getting-started/setting-up-your-tenant/application-integrations/direct-application-integrations/crowdstrike-integration-setup.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
