How can we help?

CrowdStrike Falcon Shield Integration

Netanel Hugi
Netanel Hugi
Torii SMP
Torii Identity

Overview

Torii integrates with CrowdStrike Falcon Shield and syncs:

  • Discovered end users, the people Falcon Shield finds across the SaaS platforms you connected to it
  • Falcon Shield console administrators, with their console role and last login
  • Discovered applications, and for each one the people using it

Torii does not sync devices, endpoints, alerts, or security findings. If you want the people who log into the Falcon platform itself, that is a separate integration: CrowdStrike Falcon.

You can constantly stay updated with application information from our Integrations Page >> Integration Capabilities button >> Integration Capabilities table.

Requirements

Accounts & Permissions

  • An administrator-level account in your CrowdStrike Falcon console, with Falcon Shield enabled, to create an API client.

Scopes

  • SaaS Security (Falcon Shield): READ, required. This is the only scope Torii needs, and the only one that returns Falcon Shield data.

There is no write counterpart to select. Falcon Shield offers no user management operations, so Torii only reads from it.

Required keys

  • Region, Client ID, Client Secret.

How to Generate the Required Values

Step 1: Find your CrowdStrike region

Check the address you already use to log into Falcon:

If you log into Falcon at… Select this Region in Torii
falcon.crowdstrike.com US-1
falcon.us-2.crowdstrike.com US-2
falcon.eu-1.crowdstrike.com EU-1
A GovCloud environment US-GOV-1 or US-GOV-2, confirm which with CrowdStrike support if you are unsure

Step 2: Create an API client with the minimum scope

  1. Log in to the Falcon console as an administrator.
  2. Open the Falcon menu (top left) and go to Support and resources > API Clients and Keys.
  3. Click Add new API client.
  4. Enter a Client Name (for example, "Torii Falcon Shield") and, optionally, a Description.
  5. Under API Scopes, find SaaS Security (Falcon Shield) and check READ. Leave every other scope unchecked.
  6. Click Add.

Important
Copy your Client ID and Client Secret immediately. CrowdStrike shows the Client Secret only once and you cannot retrieve it later. If you lose it you will need to reset it, which generates a new secret.

An API client with more scopes, or an existing admin-level client, will also work, but it grants Torii more access than it needs. A client holding only SaaS Security (Falcon Shield): READ is enough for everything described here.

How to Connect the Integration

Step 3: Connect in Torii

  1. Go to the Integrations page in Torii.
  2. Search for CrowdStrike Falcon Shield and click Connect.
  3. Select your Region, then enter the Client ID and Client Secret.
  4. Click Connect.

Q&A

Q: What should I enter in the "Account Name" field?

A: The Account Name field lets you connect multiple CrowdStrike Falcon Shield accounts to Torii. The value can be anything you choose, it is only used to distinguish between your connected accounts. Make sure to use a unique Account Name for each account: connecting a different account with an Account Name that is already in use will overwrite the existing account's data, so choosing distinct names is your responsibility.

Q: How is this different from the CrowdStrike Falcon integration?

A: The CrowdStrike Falcon integration syncs the people who log into the Falcon platform, a small group of security staff. This integration syncs what Falcon Shield discovers across your SaaS estate: the end users on your connected platforms, and the applications they use. The two cover different populations and can both be connected at the same time.

Q: Where do the discovered applications come from?

A: From the sources you connected to Falcon Shield. Applications authorized through your identity or productivity platforms, applications people sign into through your identity provider, and browser extensions reported by the Falcon sensor. An application appears in Torii once Falcon Shield has discovered it.

Q: Why do some discovered applications show no users in Torii?

A: Falcon Shield identifies the users of an application in different ways depending on where it was discovered, and some of those identifiers cannot be traced back to a person, for example a shared service account. Torii attaches the people it can identify with confidence and leaves the rest off rather than attributing usage to the wrong person.



For any further questions, please contact Torii Support.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request