Capabilities
Before you start
Choose an online pilot host in the correct Falcon cloud and record its AID, platform, and owner. Confirm your Falcon subscription and host policy permit RTR before scheduling local collection.Create credentials and permissions
Create an OAuth2 API client in Falcon with these scopes:
Falcon assigns the admin-command and put-file APIs to Real time response
(admin): Write. Forge therefore needs that scope even when the command being
executed is a read-only inventory probe. Forge validates command content and
scope separately before dispatch. See CrowdStrike’s Real Time Response Admin API reference
for the upstream scope requirements.
Connection
Setup
- In Falcon, open Support and resources → API clients and keys.
- Create an OAuth2 API client and grant all six required scopes above.
- Open Integrations → CrowdStrike Falcon in Forge. Enter the Falcon API URL, client ID and secret, and optional Member CID.
- Select Test connection. Forge validates authentication, host access, RTR session access, and RTR admin-command access independently.
- Import targetable hosts and explicitly bind them to the correct person. Conflicts and blocked hosts remain visible instead of creating ambiguous Forge device identities.
- Allow the scheduled inventory to run, or start an inventory or deployment operation and monitor progress for each device in Forge.
Host model
Operations
Endpoint inventory runs can target one imported device, a bounded device list, or all imported CrowdStrike devices in the organization. Each intentional run uses a client-generated idempotency key, and each device reports its ownqueued, dispatched, running, succeeded, failed, timed_out,
partially_succeeded, or canceled state.
Forge keeps provider references, execution evidence, accepted and rejected
inventory counts, and the resulting canonical inventory batch.
Full-fleet runs automatically continue through the complete Falcon host list.
Forge shows progress and per-device results throughout the run, so large
environments can be operated with the same workflow as a single endpoint.
Forge reconciles Falcon host identity with directory and endpoint sources such
as Microsoft Entra ID, Intune, Jamf Pro, and Forge for devices. Matching records
appear as one device in Forge while retaining their source history.
Validate coverage and troubleshoot
Use one online pilot host with a confirmed Falcon AID and person assignment. Check host discovery, a completed inventory operation, and the resulting Forge records separately. MCP and skill discovery depends on supported local profile paths and readable configuration; a Falcon software list alone is insufficient. A denied RTR capability needs its corresponding Falcon scope and endpoint policy. An offline host needs connectivity before an execution canary can pass. Review the recorded per-device failure before expanding permissions or retrying. Rotate the API client secret in both Falcon and Forge, then test the same pilot before revoking the previous credential.Platform coverage
This is the Forge operation surface, not a promise that every provider tenant
or endpoint grants execution. Each action still requires a compatible published
helper, provider permissions, an online agent, and the target/profile evidence
required by that collector. Provider inventory can include platforms without
Forge remote-operation support.