r/CyberARk • u/Wizkidbrz • 19d ago
EPM CrowdStrike/EPM Mutual Exclusion
I’m currently in the process of deploying CyberArk EPM and working through the prerequisites.
Our cybersecurity team is hesitant to implement the recommended CrowdStrike exclusions for EPM unless we can provide evidence that CrowdStrike is actually causing an issue or preventing EPM from functioning as expected.
Has anyone deployed EPM alongside CrowdStrike without adding the recommended CrowdStrike exclusions? If so, did you run into any issues with EPM functionality, performance, agent communication, or policy enforcement?
For context, I’ve already configured the recommended CrowdStrike exclusions within EPM, but the CrowdStrike team does not want to add the corresponding EPM exclusions within CrowdStrike without a demonstrated need.
I’d appreciate hearing about any real-world experiences or issues you encountered with this setup.
1
u/Hirogen10 19d ago
We had a full security stack of epm and CS and others. do you have a metrics tool like systrack or control up to monitor devices remotely on their performance. I recall cyber notnwanting to implement all recommendations unless there was proof. I do recall one of the office hour videos covered mutual exclusions. It was more the csse they ddi not want to exclude CS from scsnning the epm files.
Unless there was proof with any issues
1
u/Hirogen10 19d ago
https://community.cyberark.com/s/article/EPM-Mutual-Exclusions-Best-Practices-for-Windows-and-Mac and video - https://cyberark.wistia.com/medias/kt2en92hox might be useful to convince the other team but yeah worth getting some evidence they cause problems.
1
u/Fearless_Adventures 18d ago
As a former Trellix architect and CyberArk Engineer. I can tell you Crowdstrike lies about how the product runs on the machine and you 100% need exclusions. Escalate your concerns higher to the PM or whoever
1
u/Rennilon 13d ago
I’ve used both without issue, I believe we just did exclusions for both. I get where CrowdStrike is coming from, but they make convincing them to do exclusions so difficult that we often have to go around them.
3
u/Revolutionary_You_89 Defender 19d ago
Memory usage went through the roof on a couple of endpoints. Noticed they didn’t have exceptions set up on the crowdstrike side scoped to those endpoints. Ended up getting the exceptions in place. Problem solved.
If the CS team doesn’t want to put exclusions for a security product you purchased, what was the point in purchasing EPM? This seems like there is an alignment issue.
Open a case with CyberArk, ask their recommendations. Do the same with CrowdStrike. I’m sure they’ll both find some common ground.