# Global IT Outage involving Windows linked to Crowdstrike

**URL:** <https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498>\
**Category:** Internet\
**Created:** [July 19, 2024, 8:22am UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498 "2024-07-19T08:22:12Z")\
**Posts on this page:** 11\
**Page:** 2

<div class="post-metadata">

**Author:** ![PHolder](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/pholder/32/2439_2.png) [@PHolder](https://www.twit.community/u/PHolder)\
**Post date:** [July 21, 2024, 2:37am UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/21 "2024-07-21T02:37:46Z")

</div>

Microsoft has created a specific tool and instructions to assist with recovery

> **[New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints](https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959)**
>
> Steps for how to access and use the recovery tool Microsoft created to generate a USB recovery drive to expedite the repair process from the CrowdStrike issue..

---

<div class="post-metadata">

**Author:** ![Pommster](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/pommster/32/530_2.png) [@Pommster](https://www.twit.community/u/Pommster)\
**Post date:** [July 21, 2024, 12:50pm UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/22 "2024-07-21T12:50:05Z")

</div>

So that’s like a WinPE boot stick. Still need the Bitlocker recovery key. If the recovery key is being managed on a server that has Crowdstrike Falcon then you’re a bit stuffed.

---

<div class="post-metadata">

**Author:** ![AaronK](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@AaronK](https://www.twit.community/u/AaronK)\
**Post date:** [July 21, 2024, 3:52pm UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/23 "2024-07-21T15:52:19Z")

</div>

The bigger issue is that with most people working from home nowadays, you need people with the knowledge on how to make the USB stick and boot from it.

---

<div class="post-metadata">

**Author:** ![Jamze](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/jamze/32/3151_2.png) [@Jamze](https://www.twit.community/u/Jamze)\
**Post date:** [July 21, 2024, 6:47pm UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/24 "2024-07-21T18:47:35Z")

</div>

They could ship them out with instructions I guess. Getting the recovery key is the difficult bit isn’t it?

---

<div class="post-metadata">

**Author:** ![AaronK](https://avatars.discourse-cdn.com/v4/letter/a/90db22/32.png) [@AaronK](https://www.twit.community/u/AaronK)\
**Post date:** [July 21, 2024, 7:00pm UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/25 "2024-07-21T19:00:38Z")

</div>

The key is stored either in Active Directory or Azure Active Directory. For AAD, it’s easy. For AD, as long as a domain controller is back up, you’re good.

---

<div class="post-metadata">

**Author:** ![big\_D](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/big_d/32/1023_2.png) [@big\_D](https://www.twit.community/u/big_D)\
**Post date:** [July 22, 2024, 3:52am UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/26 "2024-07-22T03:52:35Z")

</div>

We have ours in the AD and in our asset management system, which runs on Linux.

---

<div class="post-metadata">

**Author:** ![PHolder](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/pholder/32/2439_2.png) [@PHolder](https://www.twit.community/u/PHolder)\
**Post date:** [July 22, 2024, 4:59am UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/27 "2024-07-22T04:59:22Z")

</div>

Some explanation from [Dave Plummer](https://en.wikipedia.org/wiki/Dave_Plummer) (ex employee of Microsoft)

[![](https://us1.discourse-cdn.com/flex020/uploads/twit/original/3X/f/f/ff2330d2f9b0f68f39eb520e59c6b6bfe9b4e005.jpeg "CrowdStrike IT Outage Explained by a Windows Developer") ](https://www.youtube.com/watch?v=wAzEJxOo1ts)

---

<div class="post-metadata">

**Author:** ![big\_D](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/big_d/32/1023_2.png) [@big\_D](https://www.twit.community/u/big_D)\
**Post date:** [July 22, 2024, 6:17am UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/28 "2024-07-22T06:17:27Z")

</div>

So, it looks like it was probably some dodgy P-Code in the “definitions” file that might have caused the problem. Very interesting analysis, given the limited facts.

So, we are down to, how did this get into the production pipeline.

---

<div class="post-metadata">

**Author:** ![Pommster](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/pommster/32/530_2.png) [@Pommster](https://www.twit.community/u/Pommster)\
**Post date:** [July 22, 2024, 2:10pm UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/29 "2024-07-22T14:10:59Z")

</div>

Monday back was a little chaotic apparently. Colleague sent a picture of one of the lines of staff waiting to get laptops fixed. This is just one campus. There are several around the city!

 ![IMG_8734](https://us1.discourse-cdn.com/flex020/uploads/twit/original/3X/b/1/b18e5bf5aa0b92131da47f35b38d9b1ff8932fb7.jpeg)

---

<div class="post-metadata">

**Author:** ![vernonlvincent](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/vernonlvincent/32/22110_2.png) [@vernonlvincent](https://www.twit.community/u/vernonlvincent)\
**Post date:** [July 22, 2024, 4:52pm UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/30 "2024-07-22T16:52:05Z")

</div>

Title edit suggestion: Global IT Outage involving Windows linked to Crowdstrike

I think there’s enough history to show that this isn’t so much Microsoft’s fault as it is CrowdStrike’s. Both Paul Thurrott and Ed Bott have some good articles outlining the history behind why companies like CrowdStrike and MacAfee and some others have the kind of access they do.

---

<div class="post-metadata">

**Author:** ![knewman](https://sea2.discourse-cdn.com/flex020/user_avatar/www.twit.community/knewman/32/1153_2.png) [@knewman](https://www.twit.community/u/knewman)\
**Post date:** [July 23, 2024, 4:03am UTC](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498/31 "2024-07-23T04:03:08Z")

</div>

> [@big\_D](#):
>
> So, we are down to, how did this get into the production pipeline

I’m betting some overzealous machine learning scheme is involved. Hopefully we get a real root cause analysis out of Crowdstrike at some point.

[Previous page](https://www.twit.community/t/global-it-outage-involving-windows-linked-to-crowdstrike/16498.md?page=1)
