Troubleshoot Falcon on macOS (Students)

Overview

If you are have issues installing, configuring, or uninstalling CrowdStrike Falcon on your Mac, please review the information below.

Details

Downloading:

If you are unable to successfully download CrowdStrike Falcon on your Mac, review the below suggestions:

  • If you are on campus, connect to the urwin wireless network before navigating to Box. While you will be restricted from accessing other websites until CrowdStrike Falcon and ClearPass OnGuard are successfully installed, you will be able to access the UR Software Downloads Box page in order to download the required software.
  • Use your university NetID and password to log into the UR Software Downloads Box page.
  • Ensure you are downloading the macOS version:
    • Verify you are in the CrowdStrike Falcon for macOS folder in Box.
    • Verify the file name ends with .pkg, not .exe.

 

Installing:

If you have successfully downloaded the CrowdStrike Falcon installer but are having issues installing it, check the steps below:

  • Confirm your version of macOS is compatible with CrowdStrike Falcon and upgrade your Mac if needed. Currently, CrowdStrike Falcon is supported on:
    • macOS Sonoma (macOS 14)
    • macOS Sequoia (macOS 15)
    • macOS Tahoe (macOS 26)
    • macOS Golden Gate (macOS 27)
  • Ensure you are an admin on your Mac or can authenticate as an administrator. Standard users will not be able to install or approve System Extensions for CrowdStrike Falcon.
    • To check if you an admin, click the Apple icon in the menu bar and select Users & Groups. Your user account type will be listed just below your name.
  • Ensure you have the latest version of the CrowdStrike Falcon installer. The version number is included in the CrowdStrike Falcon installer file name. The current CrowdStrike Falcon installer is CSFalcon 7.38.pkg.
    • Note: Do not use the CSFalcon 7.24.pkg or older on Macs running macOS Sequoia or newer.
  • During installation ensure you enable the System Extension, when prompted. If the Falcon System Extension is not enabled, the installation will fail.
  • If the installation fails or you need to reinstall CrowdStrike Falcon, follow the steps below before attempting to run the CrowdStrike Falcon installer again:
    1. Open a new Finder window and navigate to the Applications folder.
    2. Find Falcon.app and drag it to the Trash.
    3. Enter your computer password when prompted.
    4. Click OK at the System Extension removal notification.
    5. Restart your Mac.

Uninstalling:

You may need to uninstall Falcon in order to troubleshoot an issue, if you are purchasing a new Mac, or are graduating or leaving the University. In those cases, we strongly encourage you to uninstall Falcon. To uninstall the app, simply drag the Falcon app from your Applications folder to the Trash, entering your password when prompted, then restart your Mac. You may need to accept the prompt to turn off the system extension. If you are still unable to uninstall the Falcon app, contact the Help Desk at (804) 287-6400.

Miscellaneous:

  • If your Mac is quarantined by ClearPass after upgrading to a new version of macOS, uninstall and reinstall ClearPass OnGuard
  • If you have allowed all permissions and ClearPass will still not detect Falcon when it runs a health scan, restart your computer.
  • ClearPass will only run a health scan on your computer when connected to the urwin network but Falcon will continue to update and run. If you are off campus for an extended period of time, ClearPass will need to run a longer scan the first time you connect back to the urwin network. There's no need to reinstall any software, just allow the scan to complete.

See Also

Install CrowdStrike Falcon on macOS (Students)

Uninstall CrowdStrike Falcon on macOS (Students)

Print Article

Related Articles (1)

Instructions for uninstalling CrowdStrike Falcon