Skip to main content

May 4, 2026

Workspace ONE Vulnerability Defense with CrowdStrike Assessment

Workspace ONE Vulnerability Defense provides a defense-in-depth solution for vulnerability assessment, prioritization and remediation.

Assess vulnerabilities with CrowdStrike Falcon

You can integrate Workspace ONE UEM with CrowdStrike Exposure Management to assess vulnerabilities affecting managed Windows endpoints and impacted products.

Use context-rich dashboards that combine data from CrowdStrike and industry-standard sources such as the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) to prioritize vulnerabilities based on risk, exposure, and impact. Use the Vulnerability Defense Remediation Wizard to find and deploy relevant updates to mitigate risk.

Prerequisites

To use Workspace ONE Vulnerability Defense, you must meet these requirements.

Omnissa

  • Workspace ONE UEM 2604 or later
  • Omnissa Workspace ONE Vulnerability Defense add-on license

CrowdStrike

  • CrowdStrike Exposure Management
  • CrowdStrike Falcon Sensor deployed to Windows devices
  • Access to the CrowdStrike Falcon console to create OAuth 2.0 API client credentials

Configuration

To integrate Workspace ONE UEM with CrowdStrike, complete these tasks.

CrowdStrike Falcon Console

Workspace ONE UEM authenticates with CrowdStrike using OAuth 2.0 credentials. Generate an OAuth 2.0 API client in the CrowdStrike Falcon console.

  1. Sign in to the CrowdStrike Falcon console.
  2. Go to Support and Resources > API Clients and Keys.
  3. Select the OAuth2 API Clients tab.
  4. Copy and save the base URL for use in Workspace ONE UEM
  5. Click Create API Client.
  6. Enter a Client Name.
  7. Under API Scopes (read access required), select:
    • API Integrations
    • Apps
    • Detections
    • Hosts
    • Assets
    • Vulnerabilities
  8. Save the Client ID and Client Secret for use in Workspace ONE UEM.

Workspace ONE UEM

In the Workspace ONE UEM console, complete these steps at your Customer-type Organization Group (OG).

  1. Go to Groups & Settings > Configurations.
  2. Search for and open Vulnerability Defense.
  3. Select Add Provider > CrowdStrike.
  4. Complete the integration fields using information obtained from the CrowdStrike Falcon console:
    • Service URL (Base URL from CrowdStrike Falcon, for example: https://api.us-2.crowdstrike.com)
    • Client ID
    • Client Secret
  5. Select Validate Credentials.
  6. When validation succeeds, select Save, and then select Connect.

Vulnerability Assessment and Prioritization

Workspace ONE UEM correlates vulnerability assessment information from CrowdStrike with managed endpoints to provide dashboards that enable risk-based assessment and prioritization.

Vulnerabilities

In Vulnerability Defense, you can access the Vulnerabilities list view, which shows vulnerabilities detected by CrowdStrike that affect Workspace ONE managed endpoints.

You can prioritize vulnerabilities by searching, filtering, or sorting based on the following risk indicators:

  • CVSS Score
  • ExPRT.AI Rating
  • Known Exploited Status
  • Impacted Devices count
  • First Detected

You can also see whether any products were deployed using the Remediation Wizard to remediate a vulnerability.

See the image.

Vulnerability Details

Select a vulnerability ID to open the Vulnerability Details page that provides granular insight into the vulnerability.

Vulnerability Summary

You can assess the overall risk posture at a glance through key metrics, including:

  • ExPRT.AI Rating (as reported by CrowdStrike)
  • KEV Status (whether the vulnerability has been exploited in the wild as determined by CISA's KEV catalog)
  • Vulnerability description (from NIST NVD), including:
    • A detailed technical description
    • The CVSS vector string
    • A direct link to the official NVD entry for deeper analysis
  • Number of impacted products
  • Number of impacted devices
  • Average Vulnerability Age (how long the vulnerability has been present in your environment)
  • First Detected date (when the vulnerability was first detected in your environment)

See the image.

Impacted Products and Remediation Products

The Impacted Products list provides a list of apps or operating systems affected by the vulnerability, including:

  • Vendor
  • Version (if reported by CrowdStrike)
  • Product type (application or operating system)
  • Platform
  • Total vulnerabilities associated with the product
  • Number of impacted devices

The Remediation Products count indicates whether an app or OS update was deployed through the Vulnerability Defense Remediation Wizard to remediate the vulnerability.

Select an impacted product to view the CrowdStrike recommendation for remediating the vulnerability.

The Remediation Products tab lists all products deployed through the Remediation Wizard to address the vulnerability.

See the image.

Impacted Devices

The Impacted Devices section lists devices impacted by the vulnerability, including:

  • Platform
  • Device Risk (as assigned in CrowdStrike)
  • Total vulnerabilities affecting the device
  • Vulnerability Detected date (when the vulnerability was first found on the device)

Device Vulnerability Details

From Device Details > Vulnerabilities, you can inspect application and OS vulnerabilities for an individual devices and assess its overall vulnerability risk posture.

Vulnerability Remediation

Remediation Wizard for Applications

The Vulnerability Defense Remediation Wizard for applications integrates with Workspace ONE UEM application management to enable remediation for Windows app vulnerabilities. The Remediation Wizard uses the CrowdStrike recommendation to automatically find suitable remediating applications.

To deploy an app remediation:

  1. From the Vulnerability Details page, select an impacted product and select Set Up Remediation.
  2. Review the apps that match the CrowdStrike recommendation. This list can include:
    • Managed apps already added to your console
    • Apps available in the Workspace ONE UEM Enterprise App Repository (EAR)
  3. Refine results using search, and then do one of the following:
    • Select a managed app, update properties as needed, assign to relevant devices, and deploy.
    • Import an app from EAR, update properties (including prepopulated install/uninstall criteria), assign to relevant devices, and deploy.
    • Select Upload App File to use a custom app packaged within your organization, configure its properties, assign to relevant devices, and deploy.

You can track the progress of the deployment from the Application details page under Resources > Apps > Native Apps

When the remediation product is installed on a device, CrowdStrike detects the update and recognizes that the vulnerability is remediated. After Vulnerability Defense retrieves updated information, the device is removed from the Impacted Devices list for the vulnerability.

Remediate OS vulnerabilities

Windows OS vulnerabilities can be remediated by deploying an OS patch from Devices > Device Updates > Windows > Update Deployments. Once you've identified the recommended update from the Vulnerability details page, you can follow these steps to configure and deploy an OS update.

  1. From Devices > Device Updates > Windows > Update Deployments, search for the relevant KB to determine whether it was previously imported into your Workspace ONE UEM console.
  2. If the update exists:
    1. Select the update and select Assign.
    2. Add assignments (and optionally exclusions), and configure deployment parameters.
    3. Select Save & Assign to preview assigned devices, and then deploy.
  3. If the update does not exist:
    1. Select Add Update and search for the KB in the catalog.
    2. Select the relevant KB and select Select Update.
    3. On the Review Update page, choose the architecture and review KB details (for example, supported OS, device type, revision), and then continue to Assignments.
    4. Add assignments (and optionally exclusions), configure deployment parameters, and then select Save & Assign to preview assigned devices and deploy.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…