Skip to main content
See All Integrations

CrowdStrike Falcon

Use selected CrowdStrike Falcon data in Pomerium policy through a custom external data source.

Custom customer-owned connector

Category
Context Data Sources

Overview

The CrowdStrike Falcon platform provides security data and operations across endpoints and other security domains. Its APIs can expose selected host and detection records when the caller has the required product access and API scopes. In this custom pattern, Falcon is a context source.

Selected Falcon records can add organization-defined security context to an access decision. A narrow record set reduces data exposure and makes each policy condition easier to review. It does not replace a live proof from the device that made the request.

Pomerium Enterprise can import external records and use them in access policy. Pomerium does not read Falcon telemetry directly. A customer-owned connector must map selected records to user.id, user.email, request.ip, or request.client_certificate.fingerprint.

How it works

Build and operate a custom connector. Give it a least-privilege Falcon API client. The connector requests an OAuth 2.0 token and reads only the records required for access policy.

Convert selected fields to a stable JSON or CSV record format. Expose those records to a Pomerium Enterprise external data source over a protected connection.

Configure a record type and a foreign key that Pomerium can match to the current request. Use a Pomerium Policy Language record matcher to test the imported fields.

Example

A customer-owned connector reads a limited set of host records with the required Falcon API scope. It maps approved records to a verified request key and publishes an organization-defined access state. A Pomerium policy then requires a matching external record with the approved value.

Considerations

  • Pomerium does not include a named or bundled CrowdStrike Falcon connector.
  • This pattern needs Pomerium Enterprise external data sources.
  • The customer owns the connector, schema, credentials, polling process, and key mapping.
  • Imported data is updated on the connector schedule.
  • A Falcon AID is not a supported Pomerium foreign key and does not prove which device made the current request.
  • Pomerium does not install Falcon sensors or change endpoint state.

Sources and official resources

  • Use selected Microsoft Intune device data in Pomerium policy through a custom external data source.

  • Use selected Jamf Pro device data in Pomerium policy through a custom external data source.

  • Use selected SentinelOne Singularity Endpoint records in Pomerium policy through a customer-owned external data source.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo