{"id":225420,"date":"2024-07-23T06:22:34","date_gmt":"2024-07-23T13:22:34","guid":{"rendered":"https:\/\/zpesystems.com\/?p=225420"},"modified":"2025-02-06T08:55:54","modified_gmt":"2025-02-06T16:55:54","slug":"the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage","status":"publish","type":"post","link":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/","title":{"rendered":"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;0px||||false|false&#8221; custom_padding=&#8221;0px||||false|false&#8221; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg&#8221; alt=&#8221;CrowdStrike Outage BSOD&#8221; title_text=&#8221;CrowdStrike Outage BSOD&#8221; _builder_version=&#8221;4.27.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\"><strong>On July 19, 2024,<\/strong> CrowdStrike, a leading cybersecurity firm renowned for its advanced endpoint protection and threat intelligence solutions, <\/span><a href=\"https:\/\/www.darkreading.com\/application-security\/fallout-from-faulty-friday-crowdstrike-update-persists\"><span style=\"font-weight: 400;\">experienced a significant outage<\/span><\/a><span style=\"font-weight: 400;\"> that disrupted operations for many of its clients. This outage, triggered by a software upgrade, resulted in crashes for Windows PCs, creating a wave of operational challenges for banks, airports, enterprises, and organizations worldwide. This blog post explores what transpired during this incident, what caused the outage, and the broader implications for the cybersecurity industry.<\/span><\/p>\n<h2>What happened?<\/h2>\n<p><span style=\"font-weight: 400;\">The incident began on the morning of July 19, 2024, when numerous CrowdStrike customers started reporting issues with their Windows PCs. Users experienced the BSOD (blue screen of death), which is when Windows crashes and renders devices unusable. As the day went on, it became evident that the problem was widespread and directly linked to a recent software upgrade deployed by CrowdStrike.<\/span><\/p>\n<p><b>Timeline of Events<\/b><\/p>\n<ol>\n<li><span style=\"font-weight: 400;\">Initial Reports: Early in the day, airports, hospitals, and critical infrastructure operators began experiencing unexplained crashes on their Windows PCs. The issue was quickly reported to CrowdStrike&#8217;s support team.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Incident Acknowledgement: CrowdStrike acknowledged the issue via their social media channels and direct communications with affected clients, confirming that they were investigating the cause of the crashes.<\/span><\/li>\n<li>Root Cause Analysis: CrowdStrike&#8217;s engineering team worked diligently to identify the root cause of the problem. They soon determined that a software upgrade released the previous night was responsible for the crashes.<\/li>\n<li>Mitigation Efforts: Upon isolating the faulty software update, <a href=\"https:\/\/www.crowdstrike.com\/falcon-content-update-remediation-and-guidance-hub\/\">CrowdStrike issued guidance<\/a> on how to roll back the update and provided patches to fix the issue.<\/li>\n<\/ol>\n<h2>What caused the CrowdStrike outage?<\/h2>\n<p><span style=\"font-weight: 400;\">The root cause of the outage was a software upgrade intended to enhance the functionality and security of CrowdStrike&#8217;s Falcon sensor endpoint protection platform. However, this upgrade contained a bug that conflicted with certain configurations of Windows PCs, leading to system crashes. Several factors contributed to the incident:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Insufficient Testing: The software update did not undergo adequate testing across all possible configurations of Windows PCs. This oversight meant that the bug was not detected before the update was deployed to customers.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Complex Interdependencies: The incident highlights the complex interdependencies between software components and operating systems. Even minor changes can have unforeseen impacts on system stability.<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Rapid Deployment: In the cybersecurity industry, quick responses to emerging threats are crucial. However, the pressure to deploy updates rapidly can sometimes lead to insufficient testing and quality assurance processes.<\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">We need to remember one important fact: whether software is written by humans or AI, there will be mistakes in coding and testing. When an issue slips through the cracks, the customer lab is the last resort to catch it. Usually, this can be done with a controlled rollout, where the IT team first upgrades their lab equipment, performs further testing, puts in place a rollback plan, and pushes the update to a less critical site. But in a cloud-connected SaaS world, the customer is no longer in control. That\u2019s why they sign waivers stating that if such an incident occurs, the company that caused the problem is not liable. Experts are saying the only way to address this challenge is to have an infrastructure that\u2019s designed, deployed, and operated for resilience. We discuss this architecture further down in this article.<\/span><\/p>\n<h2>How to recover from the CrowdStrike outage<\/h2>\n<p><strong>CrowdStrike gives two options for recovering:<\/strong><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5042421-crowdstrike-issue-impacting-windows-endpoints-causing-an-0x50-or-0x7e-error-message-on-a-blue-screen-b1c700e0-7317-4e95-aeee-5d67dd35b92f\"><span style=\"font-weight: 400;\">Option 1: Reboot in Safe Mode<\/span><\/a><span style=\"font-weight: 400;\"> &#8211; Reboot the affected device in Safe Mode, locate and delete the file \u201cC-00000291*.sys\u201d, and then restart the device.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.crowdstrike.com\/wp-content\/uploads\/2024\/07\/Using-the-Microsoft-Recovery-Tool-for-Automated-Host-Remediation.pdf\" data-lf-fd-inspected-xz1a5d7772wdp3k2=\"true\"><span style=\"font-weight: 400;\">Option 2: Re-image<\/span><\/a><span style=\"font-weight: 400;\"> &#8211; Download and configure the recovery utility to create a new Windows image, add this image to a USB drive, and then insert this USB drive into the target device. The utility will automatically find and delete the file that\u2019s causing the crash.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">The biggest obstacle that is costing organizations a lot of time and money is that with either of these recovery methods, IT staff need to be physically present to work on each affected device. They need to go one by one manually remediating via Safe Mode or physically inserting the USB drive. What makes this more difficult is that many organizations use physical and software\/management security controls to limit access. Locked device cabinets slow down physical access to devices, and things like role-based access policies and disk encryption can make Safe Mode unusable. Because this outage is affecting more than <\/span><a href=\"https:\/\/www.bbc.com\/news\/articles\/cpe3zgznwjno\"><span style=\"font-weight: 400;\">8.5 million computers<\/span><\/a><span style=\"font-weight: 400;\">, this kind of work won\u2019t scale efficiently. That\u2019s why organizations are turning to Isolated Management Infrastructure (IMI) and the Isolated Recovery Environment (IRE).<\/span><\/p>\n<h2>How IMI and IRE help you recover faster<\/h2>\n<p><span style=\"font-weight: 400;\">IMI is a dedicated control plane network that\u2019s meant for administration and recovery of IT systems, including Windows PCs affected by the CrowdStrike outage. It uses the concept of out-of-band management, where you deploy a management device that is connected to dedicated management ports of your IT infrastructure (e.g., serial ports, IPMI ports, and other ethernet management ports). IMI also allows you to deploy recovery services for your digital estate that is immutable and near-line when recovery needs to take place.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">IMI does not rely at all on the production assets, as it has its own dedicated remote access via WAN links like 4G\/5G, and can contain and encrypt recovery keys and tools with zero trust.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">IMI gives teams remote, low-level access to devices so they can recover their systems remotely without the need to visit sites. Organizations that employ IMI are able to revert back to a golden image through automation, or deploy bootable tools to all the computers at the site to rescue them without data loss.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The dedicated out-of-band access to serial\/IPMI and management ports gives automation software the same abilities as if a physical crash cart was pulled up to the servers. ZPE Systems\u2019 Nodegrid (now a brand of Legrand) enables this architecture as explained next. Using Nodegrid and ZPE Cloud, teams can use either option to <strong>recover<\/strong> <strong>from the CrowdStrike outage:<\/strong><\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Option 1<\/strong>: Reboot in Pre-Execution Environment Software &#8211; Nodegrid gives low-level network access to connected Windows as if teams were sitting directly in front of the affected device. This means they can remote-in, reboot to a network image, remote into the booted image, delete the faulty file, and restart the system.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Option 2<\/strong>: Re-image &#8211; ZPE Cloud serves as a file repository and orchestration engine. Teams can upload their working Windows image, and then automatically push this across their global fleet of affected devices. This option speeds up recovery times exponentially.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><strong>Option 3<\/strong>: &#8211; Run Windows Deployment server on the IMI device at the location and re-image servers and workstations if a good backup of the data has been located. This backup can be made available through the IMI after the initial image has been deployed. The IMI can provide dedicated secure access to the InTune services in your M365 cloud, and the backups do not have to transit the entire internet for all workstations at the time, speeding up recovery many times over.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">All of these options can be performed at scale or even automated. Server recovery with large backups, although it may take a couple of hours, can be delivered locally and tracked for performance and consistency.<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">But what about the risk of making mistakes when you have to repeat these tasks? Won\u2019t this cause more damage and data loss?<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">Any team can make a mistake repeating these recovery tasks over a large footprint, and cause further damage or loss of data, slowing the recovery further. <\/span><b>Automated recovery through the IMI addresses this<\/b><span style=\"font-weight: 400;\">, and can provide reliable recording and reporting to ensure that the restoration is complete and trusted.\u00a0<\/span><\/p>\n<h2>What does IMI look like?<\/h2>\n<p><span style=\"font-weight: 400;\">Here\u2019s a simplified view of Isolated Management Infrastructure. You can see that ZPE\u2019s Nodegrid device is needed, which sits beside production infrastructure and provides the platform for hosting all the tools necessary for fast recovery.<\/span><\/p>\n<p><img decoding=\"async\" class=\"wp-image-225260 alignnone size-full\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/IMI-with-Nodegrid1.jpg\" alt=\"A diagram showing how to use Nodegrid Gen 3 OOB to enable IMI.\" width=\"1920\" height=\"1378\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/IMI-with-Nodegrid1.jpg 1920w, https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/IMI-with-Nodegrid1-1280x919.jpg 1280w, https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/IMI-with-Nodegrid1-980x703.jpg 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/IMI-with-Nodegrid1-480x345.jpg 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 1920px, 100vw\" \/><\/p>\n<p><strong>What you need to deploy IMI for recovery:<\/strong><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Out-of-band appliance with serial, USB, ethernet interfaces (e.g., ZPE\u2019s Nodegrid Net SR)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Switchable PDU: Legrand Server Tech or Raritan PDU<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Windows PXE Boot image<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Here\u2019s the order of operations for a faster CrowdStrike outage recovery:<\/span><b><\/b><\/p>\n<ul>\n<li aria-level=\"1\"><b>Option 1 &#8211; Recover<\/b><\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">IMI deployed with a ZPE Nodegrid device that will start Pre-Execution Environment (PXE) which are Windows boot images that the Nodegrid will push to the computers when they boot up<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Send recovery keys from Intune to IMI remote storage over ZPE Cloud\u2019s zero trust platform easily available in cloud or air-gapped through Nodegrid Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Enable PXE service (automated across entire enterprise) and define the PXE recovery image<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Use serial or IP control of power to the computers, or if possible Intel vPro or IPMI capable machines, to reboot all machines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">All machines will boot and check in to a control tower for PXE, or be made available to remote into using stored passwords on the PXE environment, Windows AD, or other Privileged Access Management (PAM)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Delete Files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Reboot<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ul>\n<li aria-level=\"1\"><b>Option 2 &#8211; Lean re-image<\/b><\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">IMI deployed with a Windows Pre-Execution boot image running PXE service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Enable access to cloud and Azure Intune to the IMI remote storage for the local image for the PC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Enable PXE service (automated across entire enterprise) and define the PXE recovery image<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Use serial or IP control of power to the computers, or if possible, Intel vPro or IPMI capable machines, to reboot all machines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Machines will boot and check in to Intune either through the IMI or through normal Internet access and finish imaging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Once the machine completes the InTune tasks, InTune will signal backups to come down to the machines. If these backups are offsite, they can be staged on the IMI through backup software running on a virtual machine located on the IMI appliance to speed up recovery and not impede the Internet connection at the remote site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Pre-stage backups onto local storage, push recovery from the virtual machine on the IMI<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ul>\n<li aria-level=\"1\"><b>Option 3 &#8211; Windows controlled re-image<\/b><\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Windows Deployment Server (WDS) installed as a virtual machine running on the IMI appliance (offline to prevent issues or online but under a slowed deployment cycle in case there was an issue)\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Send recovery keys from Intune to IMI remote storage over a zero trust interface in cloud or air-gapped<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Use serial or IP control of power to the computers, or if possible, Intel vPro or IPMI capable machines, to reboot all machines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Machines will boot and check in to the WDS for re-imaging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Machines will boot and check in to Intune either through the IMI or through normal Internet access and finish imaging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Once the machine completes the InTune tasks, InTune will signal backups to come down to the machines. If these backups are offsite, they can be staged on the IMI through backup software running on a virtual machine located on the IMI appliance to speed up recovery and not impede the Internet connection at the remote site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">Pre-stage backups onto local storage, push recovery from the virtual machine on the IMI<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>Deploy IMI to avoid the next outage<\/h2>\n<p><span style=\"font-weight: 400;\">Get in touch for help choosing the right size IMI deployment for your organization. Nodegrid and ZPE Cloud are the drop-in solution to recovering from outages, with plenty of device options to fit any budget and environment size. Contact ZPE Sales now or download the blueprint to help you begin implementing IMI.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;https:\/\/zpesystems.com\/contact\/&#8221; button_text=&#8221;Contact ZPE sales&#8221; _builder_version=&#8221;4.27.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_button][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_button button_url=&#8221;https:\/\/zpesystems.com\/network-automation-blueprint\/&#8221; button_text=&#8221;Download blueprint&#8221; _builder_version=&#8221;4.27.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_button][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here&#8217;s how to recover fast and avoid the next outage.<\/p>\n","protected":false},"author":5,"featured_media":225437,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[92,98,103,102,156,101,93,82,99,169,97,81,112,134],"tags":[],"class_list":["post-225420","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-consolidation","category-data-logging","category-improve-network-security","category-increase-productivity","category-micro-segmentation","category-minimize-impact-of-disruptions","category-network-automation","category-out-of-band-management","category-remote-network-management","category-serial-consoles","category-user-management","category-virtualization","category-zero-touch-provisioning","category-zero-trust-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v26.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage<\/title>\n<meta name=\"description\" content=\"The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here&#039;s how to recover fast and avoid the next outage.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage\" \/>\n<meta property=\"og:description\" content=\"The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here&#039;s how to recover fast and avoid the next outage.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/\" \/>\n<meta property=\"og:site_name\" content=\"ZPE Systems\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-23T13:22:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-06T16:55:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jordan Baker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jordan Baker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/\",\"url\":\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/\",\"name\":\"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage\",\"isPartOf\":{\"@id\":\"https:\/\/zpesystems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg\",\"datePublished\":\"2024-07-23T13:22:34+00:00\",\"dateModified\":\"2025-02-06T16:55:54+00:00\",\"author\":{\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\"},\"description\":\"The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here's how to recover fast and avoid the next outage.\",\"breadcrumb\":{\"@id\":\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#primaryimage\",\"url\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg\",\"contentUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg\",\"width\":1200,\"height\":627,\"caption\":\"BSOD from crashed Windows PCs due to CrowdStrike failure\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/zpesystems.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zpesystems.com\/#website\",\"url\":\"https:\/\/zpesystems.com\/\",\"name\":\"ZPE Systems\",\"description\":\"Rethink the Way Networks are Built and Managed\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zpesystems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\",\"name\":\"Jordan Baker\",\"url\":\"https:\/\/zpesystems.com\/author\/jordan\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage","description":"The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here's how to recover fast and avoid the next outage.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/","og_locale":"en_US","og_type":"article","og_title":"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage","og_description":"The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here's how to recover fast and avoid the next outage.","og_url":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/","og_site_name":"ZPE Systems","article_published_time":"2024-07-23T13:22:34+00:00","article_modified_time":"2025-02-06T16:55:54+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg","type":"image\/jpeg"}],"author":"Jordan Baker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jordan Baker","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/","url":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/","name":"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage","isPartOf":{"@id":"https:\/\/zpesystems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#primaryimage"},"image":{"@id":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#primaryimage"},"thumbnailUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg","datePublished":"2024-07-23T13:22:34+00:00","dateModified":"2025-02-06T16:55:54+00:00","author":{"@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567"},"description":"The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here's how to recover fast and avoid the next outage.","breadcrumb":{"@id":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#primaryimage","url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg","contentUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg","width":1200,"height":627,"caption":"BSOD from crashed Windows PCs due to CrowdStrike failure"},{"@type":"BreadcrumbList","@id":"https:\/\/zpesystems.com\/the-crowdstrike-outage-how-to-recover-fast-and-avoid-the-next-outage\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zpesystems.com\/"},{"@type":"ListItem","position":2,"name":"The CrowdStrike Outage: How to Recover Fast and Avoid the Next Outage"}]},{"@type":"WebSite","@id":"https:\/\/zpesystems.com\/#website","url":"https:\/\/zpesystems.com\/","name":"ZPE Systems","description":"Rethink the Way Networks are Built and Managed","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zpesystems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567","name":"Jordan Baker","url":"https:\/\/zpesystems.com\/author\/jordan\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg",1200,627,false],"landscape":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg",1200,627,false],"portraits":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg",1200,627,false],"thumbnail":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-150x150.jpg",150,150,true],"medium":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-300x157.jpg",300,157,true],"large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-1024x535.jpg",1024,535,true],"1536x1536":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg",1200,627,false],"2048x2048":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg",1200,627,false],"et-pb-post-main-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-1080x627.jpg",1080,627,true],"et-pb-portfolio-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-1080x564.jpg",1080,564,true],"et-pb-gallery-module-image-portrait":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg",1200,627,false],"et-pb-image--responsive--desktop":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD.jpg",1200,627,false],"et-pb-image--responsive--tablet":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-980x512.jpg",980,512,true],"et-pb-image--responsive--phone":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/07\/CrowdStrike-Outage-BSOD-480x251.jpg",480,251,true]},"rttpg_author":{"display_name":"Jordan Baker","author_link":"https:\/\/zpesystems.com\/author\/jordan\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/zpesystems.com\/category\/simplify-branch-infrastructure\/consolidation\/\" rel=\"category tag\">Consolidation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/data-logging\/\" rel=\"category tag\">Data Logging<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/\" rel=\"category tag\">Improve Network Security<\/a> <a href=\"https:\/\/zpesystems.com\/category\/increase-productivity\/\" rel=\"category tag\">Increase Productivity<\/a> <a href=\"https:\/\/zpesystems.com\/category\/micro-segmentation\/\" rel=\"category tag\">Micro-segmentation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/minimize-impact-of-disruptions\/\" rel=\"category tag\">Minimize Impact of Disruptions<\/a> <a href=\"https:\/\/zpesystems.com\/category\/increase-productivity\/network-automation\/\" rel=\"category tag\">Network Automation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/remote-network-management\/out-of-band-management\/\" rel=\"category tag\">Out of Band Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/remote-network-management\/\" rel=\"category tag\">Remote Network Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/serial-consoles\/\" rel=\"category tag\">Serial Consoles<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/user-management\/\" rel=\"category tag\">User Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/simplify-branch-infrastructure\/virtualization\/\" rel=\"category tag\">Virtualization<\/a> <a href=\"https:\/\/zpesystems.com\/category\/streamline-deployments\/zero-touch-provisioning\/\" rel=\"category tag\">Zero Touch Provisioning (ZTP)<\/a> <a href=\"https:\/\/zpesystems.com\/category\/zero-trust-security\/\" rel=\"category tag\">Zero Trust Security<\/a>","rttpg_excerpt":"The CrowdStrike outage on July 19, 2024 affected millions of critical organizations. Here's how to recover fast and avoid the next outage.","_links":{"self":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/225420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/comments?post=225420"}],"version-history":[{"count":10,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/225420\/revisions"}],"predecessor-version":[{"id":227824,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/225420\/revisions\/227824"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media\/225437"}],"wp:attachment":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media?parent=225420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/categories?post=225420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/tags?post=225420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}