Capabilities
Permissions
Create an OAuth2 API client in Falcon with these scopes:
Falcon assigns the admin-command and put-file APIs to Real time response
(admin): Write. Forge therefore needs that scope even when the command being
executed is a read-only inventory probe. Forge validates command content and
scope separately before dispatch.
Connection
Setup
- In Falcon, open Support and resources → API clients and keys.
- Create an OAuth2 API client and grant all six required scopes above.
- Open Settings → Integrations → CrowdStrike Falcon in Forge. Enter the Falcon cloud URL, client ID and secret, and optional Member CID.
- Select Test connection. Forge validates authentication, host access, RTR session access, and RTR admin-command access independently.
- Import targetable hosts and explicitly bind them to the correct person. Conflicts and blocked hosts remain visible instead of creating ambiguous Forge device identities.
- Allow the scheduled inventory to run, or start an inventory or deployment operation and monitor progress for each device in Forge.
Host model
Operations
Endpoint inventory runs can target one imported device, a bounded device list, or all imported CrowdStrike devices in the organization. Each intentional run uses a client-generated idempotency key, and each device reports its ownqueued, dispatched, running, succeeded, failed, timed_out,
partially_succeeded, or canceled state.
Forge keeps provider references, execution evidence, accepted and rejected
inventory counts, and the resulting canonical inventory batch.
Full-fleet runs automatically continue through the complete Falcon host list.
Forge shows progress and per-device results throughout the run, so large
environments can be operated with the same workflow as a single endpoint.
Forge reconciles Falcon host identity with directory and endpoint sources such
as Microsoft Entra ID, Intune, Jamf Pro, and Forge for devices. Matching records
appear as one device in Forge while retaining their source history.