CrowdStrikeintermediate

How to Configure CrowdStrike Falcon Sensor Update Policies

Learn how to create and manage CrowdStrike Falcon sensor update policies. Control sensor versions, automate updates, and protect sensors from unauthorized uninstallation across Windows, Mac, and Linux hosts.

8 min readUpdated January 2025

Sensor update policies in CrowdStrike Falcon control the update process for sensors across your entire host fleet. Use these policies to manage sensor versions, automate updates, protect against unauthorized uninstallation, and schedule maintenance windows.

Understanding Sensor Update Policies

Sensor update policies let you:

  • Lock host groups to specific sensor versions
  • Automate updates with Auto-Latest, N-1, or N-2 settings
  • Protect sensors from unauthorized uninstallation
  • Schedule exclusion windows to prevent updates during maintenance
  • Test new versions on pilot groups before production deployment

Each platform (Windows, Mac, Linux) has separate sensor update policies. Hosts are assigned to policies through host groups.

Requirements

  • Subscriptions: Falcon Prevent or Falcon Insight XDR
  • Roles: Falcon Administrator or Endpoint Manager

Creating a Sensor Update Policy

    - **Navigate to Sensor Update Policies**
    • Go to Host Setup and Management > Deploy > Sensor Update Policies

    • Create the Policy

    • Click Create Policy

    • Enter a Policy name

    • Select the Platform (Windows, Mac, or Linux)

    • Add an optional Description

    • Click Create Policy

    • Configure Sensor Settings

    • On the Sensor Settings tab, select a sensor version option

    • Configure Uninstall and maintenance protection

    • Click Save


Sensor Version Options

OptionDescriptionBest For
**Auto - Early Adopter**Updates to early adopter builds 4 days before general availabilityEarly testing environments
**Auto - Latest**Updates to the newest version on scheduled releaseTest/QA environments
**Auto - N-1**Updates to second-newest versionPilot groups
**Auto - N-2**Updates to third-newest versionProduction environments
**Specific Version**Locked to a specific version numberControlled rollouts
**Sensor version updates off**No cloud-pushed updatesManual management, maintenance

Recommendation: Update sensors monthly and maintain hosts at N-2 or newer for optimal protection. If your organization values stability over new features, consider using Long-Term Support (LTS) sensors—available through CrowdStrike's Customer Center.


Assigning Policies to Host Groups

    - Open the sensor update policy you want to modify - Click the **Assigned Host Groups** tab - Click **Assign Host Groups** - Select the groups to assign - Click **Assign Groups**

Note: Host groups can only be assigned to one sensor update policy. If a group is already assigned elsewhere, you must remove it from the current policy first.


Protecting Sensors from Uninstallation

The Uninstall and maintenance protection setting prevents unauthorized sensor removal:

  • When enabled: Requires a maintenance token to uninstall, upgrade, or modify the sensor
  • When disabled: End users with local admin permissions can uninstall the sensor

Best Practice: Keep protection enabled for all policies except one dedicated maintenance policy. Move hosts to the maintenance policy temporarily when changes are needed.

For detailed instructions, see our guide on enabling uninstall protection for CrowdStrike Falcon.


Deleting a Sensor Update Policy

Before deleting a policy, you must disable it first:

    - Open the policy you want to delete - Click **Disable Policy**, then confirm - Click **Delete Policy**, then confirm

When a policy is deleted, hosts from that policy are reassigned to another policy based on policy precedence rules.


We recommend creating a tiered testing and deployment structure:

Policy/GroupSensor VersionPurpose
Test-QA GroupAuto - LatestTest newest versions on non-production hosts
Tech Pilot GroupSpecific or N-1Limited non-critical production testing
Business Pilot GroupSpecific or N-1Broader production testing across departments
Production (Default)Specific or N-2Stable version for all production hosts
Maintenance PolicyUpdates offTemporary policy for uninstallation/upgrades

Best Practices

  • Update monthly: Keep sensors at N-2 or newer for optimal protection
  • Don't interrupt installations: Never shut down or reboot hosts during sensor installation
  • Use protection: Keep Uninstall and maintenance protection enabled on all policies except your maintenance policy
  • Test before deploying: Always test new sensor versions on pilot groups before production rollout
  • One maintenance policy: Create a single policy with protection disabled for all maintenance tasks

Frequently Asked Questions

Find answers to common questions

A sensor update policy in CrowdStrike Falcon controls the update process for sensors on your hosts. Policies let you lock hosts to specific sensor versions, automate updates with Auto-Latest/N-1/N-2 settings, protect sensors from unauthorized uninstallation, and schedule update exclusion windows. Each host is assigned to a sensor policy based on its host group, with separate policies for Windows, Mac, and Linux platforms.

Need Expert CrowdStrike Management?

Our team manages CrowdStrike deployments for businesses like yours. Get 24/7 threat detection and response with expert oversight.