How can we help?

CrowdStrike Falcon Integration

Netanel Hugi
Netanel Hugi
Torii SMP
Torii Identity

Overview

Torii integrates with CrowdStrike Falcon and syncs:

  • Console users — the people who log into the Falcon platform
  • Each user's role
  • Each user's creation date and last login

Torii does not sync devices or endpoints protected by Falcon — only the people who have access to the Falcon console.

You can constantly stay updated with application information from our Integrations Page >> Integration Capabilities button >> Integration Capabilities table.

Requirements

Accounts & Permissions

  • An administrator-level account in your CrowdStrike Falcon console, to create an API client.

Scopes

  • User Management: Read. This is the only scope Torii needs.

Required keys

  • Region, Client ID, Client Secret.

How to Generate the Required Values

Step 1: Find your CrowdStrike region

Check the address you already use to log into Falcon:

If you log into Falcon at… Select this Region in Torii
falcon.crowdstrike.com US-1
falcon.us-2.crowdstrike.com US-2
falcon.eu-1.crowdstrike.com EU-1
A GovCloud environment US-GOV-1 or US-GOV-2 — confirm which with CrowdStrike support if you are unsure

Step 2: Create an API client with the minimum scope

  1. Log in to the Falcon console as an administrator.
  2. Open the Falcon menu (top left) and go to Support and resources > API Clients and Keys.
  3. Click Add new API client.
  4. Enter a Client Name (for example, "Torii") and, optionally, a Description.
  5. Under API Scopes, find User Management and check only the READ box. Do not check WRITE — Torii does not need it.
  6. Click Add.

Important
Copy your Client ID and Client Secret immediately. CrowdStrike shows the Client Secret only once and you cannot retrieve it later — if you lose it you will need to reset it, which generates a new secret.

An API client with more scopes, or an existing admin-level client, will also work — but it grants Torii more access than it needs. We recommend a client with only User Management: Read.

How to Connect the Integration

Step 3: Connect in Torii

  1. Go to the Integrations page in Torii.
  2. Search for CrowdStrike Falcon and click Connect.
  3. Select your Region, then enter the Client ID and Client Secret.
  4. Click Connect.

Q&A

Q: Does Torii sync devices or endpoints protected by Falcon?

A: No. This integration syncs only Falcon console users — the people who can log into the Falcon platform — not devices, sensors, or endpoints.

Q: What does the user's status show in Torii?

A: Torii shows each user's status exactly as CrowdStrike reports it, in an "external status" field. Torii doesn't interpret or act on this value — it's a direct passthrough of what CrowdStrike sends.

Q: I manage more than one Falcon tenant. How do I connect them?

A: One Torii connection covers one Falcon tenant. Connect each tenant separately, using the API client created in that tenant.



For any further questions, please contact Torii Support.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request