Overview
Sensor Update policies control which version of the Falcon sensor is deployed to endpoints and when updates occur. These policies allow you to manage sensor versions across your environment, ensuring controlled rollouts and maintenance windows.Required API Scope:
Sensor update policies: Read (for read operations) or Sensor update policies: Write (for write operations)Get Sensor Update Policies
Search for and retrieve Sensor Update policies.Get-FalconSensorUpdatePolicy
Parameters
Policy identifier(s). Pattern:
^[a-fA-F0-9]{32}$Falcon Query Language (FQL) expression to limit resultsExample:
platform_name:'Windows'+enabled:trueProperty and direction to sort resultsValid values:
created_by.asc, created_by.desc, created_timestamp.asc, created_timestamp.desc, enabled.asc, enabled.desc, modified_by.asc, modified_by.desc, modified_timestamp.asc, modified_timestamp.desc, name.asc, name.desc, platform_name.asc, platform_name.desc, precedence.asc, precedence.descMaximum number of results per request (1-5000)
Include additional propertiesValid values:
membersPosition to begin retrieving results
Retrieve detailed information
Repeat requests until all available results are retrieved
Display total result count instead of results
Examples
Create Sensor Update Policy
Create new Sensor Update policies.New-FalconSensorUpdatePolicy
Parameters
Policy name
Operating system platformValid values:
Windows, Mac, LinuxPolicy description
Policy settings controlling sensor version and update scheduleCommon properties:
build: Sensor build version to deployscheduler: Update scheduling configuration (enabled, timezone, start/end times)uninstall_protection: Enable/disable uninstall protection
One or more policies to create in a single request (for batch operations, max 100 per request)
Examples
Edit Sensor Update Policy
Modify existing Sensor Update policies.Edit-FalconSensorUpdatePolicy
Parameters
Policy identifier. Pattern:
^[a-fA-F0-9]{32}$Policy name
Policy description
Policy settings to update
One or more policies to modify in a single request (for batch operations, max 100 per request)
Examples
Remove Sensor Update Policy
Remove Sensor Update policies.Remove-FalconSensorUpdatePolicy
Parameters
Policy identifier(s) to remove. Pattern:
^[a-fA-F0-9]{32}$Example
Policy Actions
Perform actions on Sensor Update policies such as enabling/disabling or assigning to host groups.Invoke-FalconSensorUpdatePolicyAction
Parameters
Action to performValid values:
add-host-group, disable, enable, remove-host-groupHost group identifier. Pattern:
^[a-fA-F0-9]{32}$Required for: add-host-group, remove-host-groupPolicy identifier. Pattern:
^[a-fA-F0-9]{32}$Examples
Get Policy Members
Search for members (hosts) assigned to Sensor Update policies.Get-FalconSensorUpdatePolicyMember
Parameters
Policy identifier. Pattern:
^[a-fA-F0-9]{32}$Falcon Query Language expression to limit results
Property and direction to sort results
Maximum number of results per request (1-5000)
Position to begin retrieving results
Retrieve detailed information
Repeat requests until all available results are retrieved
Display total result count instead of results
Example
Set Policy Precedence
Set Sensor Update policy precedence order for a specific platform.Set-FalconSensorUpdatePrecedence
Parameters
Operating system platformValid values:
Windows, Mac, LinuxPolicy identifiers in desired precedence order (highest to lowest priority). Pattern:
^[a-fA-F0-9]{32}$All policy identifiers must be supplied in order, with the exception of the
platform_default policy.Example
Get Available Sensor Builds
Retrieve available Falcon Sensor builds for assignment in policies.Get-FalconBuild
Parameters
Operating system platformValid values:
linux, mac, windows (case-sensitive)Sensor release stageValid values:
early_adopter, prodExamples
Get Kernel Compatibility
Search for Falcon kernel compatibility information for Sensor builds (Linux).Get-FalconKernel
Parameters
Return values for a specific fieldValid values:
architecture, base_package_supported_sensor_versions, distro, distro_version, flavor, release, vendor, version, ztl_supported_sensor_versionsFalcon Query Language expression to limit results
Property and direction to sort results
Maximum number of results per request (1-500)
Position to begin retrieving results
Repeat requests until all available results are retrieved
Display total result count instead of results
Example
Get Uninstall Token
Retrieve an uninstallation or maintenance token for a host.Get-FalconUninstallToken
Parameters
Audit log comment for token retrieval
Include additional host propertiesValid values:
agent_version, cid, external_ip, first_seen, hostname, last_seen, local_ip, mac_address, os_build, os_version, platform_name, product_type, product_type_desc, serial_number, system_manufacturer, system_product_name, tagsHost identifier or
MAINTENANCE for maintenance token. Pattern: ^([a-fA-F0-9]{32}|MAINTENANCE)$Examples
Related Resources
Prevention Policies
Manage Prevention policies
Device Control Policies
Control USB and Bluetooth device usage