CrowdStrike Flight Control
CrowdStrike Flight Control
Overview
The CrowdStrike Flight Control integration is designed for MSSPs and multi-tenant CrowdStrike environments.
It lets the Praetorian Guard Platform (PGP) connect once using a parent or master CID, discover child tenants automatically, and create scoped integrations for each child tenant. PGP then pulls host and vulnerability data from each child tenant and correlates it with Guard exposure data.
Use this integration when you manage multiple CrowdStrike child CIDs from a parent tenant.
Prerequisites
Before you begin, make sure you have:
Access to the CrowdStrike Falcon console for the parent CID
Permission to create API clients in CrowdStrike
A parent tenant licensed for Flight Control
Your CrowdStrike cloud region
Create a CrowdStrike API Client
Sign in to the CrowdStrike Falcon console for the parent CID.
Navigate to Support & Resources → API Clients & Keys.
Click Create API Client.
Grant the following read-only scopes based on the modules you want enabled:
If you enable Spotlight, you must also grant Hosts: Read so PGP can map findings to the correct assets.
After saving the client, copy the following values and store them securely:
Client ID
Client Secret
Cloud Region from your Falcon console URL
Supported regions:
us-1—api.crowdstrike.comus-2—api.us-2.crowdstrike.comeu-1—api.eu-1.crowdstrike.comus-gov-1—api.laggar.gcw.crowdstrike.com
You will not be able to retrieve the client secret again later.
Configure the Integration in PGP
In PGP, go to Integrations.
Select Managed Detection & Response → CrowdStrike Flight Control.
Click Connect.
Enter the parent CID's Client ID, Client Secret, and Cloud Region.
Enable the modules you want applied across child tenants.
Click Connect.
PGP validates the credentials and confirms scope access for each enabled module before saving the integration.
What Happens After Connection
After Flight Control is connected, PGP automatically:
Discovers child CIDs using the Flight Control API
Creates a scoped CrowdStrike integration for each child tenant
Uses the parent credentials with
member_cidscoping for child-tenant accessApplies the module configuration you selected to each child integration
You do not need to create a separate API client for every child tenant.
What Data Is Synced
Hosts → PGP Assets
For enabled child tenants, PGP syncs:
Device hostname and local IP address
Devices seen in the last 7 days
Assets that can be mapped successfully from CrowdStrike host data
Spotlight → PGP Risks
For enabled child tenants, PGP ingests:
Open CVEs from Spotlight
Findings updated in the last 7 days
CVSS score, severity, description, remediation guidance, references, and proof artifacts
Findings correlated to assets using CrowdStrike agent IDs
All Spotlight vulnerability vectors are included, not just network-reachable findings.
Shield
The Shield module is currently limited to API scope validation.
Troubleshooting
Need Help?
If you run into issues during setup, contact support@praetorian.com.