-

CrowdStrike FalconID Extends Risk-Aware Identity Security to Multi-Factor Authentication

Zero-friction MFA stops AI-accelerated phishing attacks in real time and advances the shift from fragmented, static access controls to continuous, risk-aware authorization

AUSTIN, Texas--(BUSINESS WIRE)--CrowdStrike (NASDAQ: CRWD) today announced the general availability of FalconID, extending the Falcon® platform with zero-friction, phishing-resistant MFA. Identity is the front line of modern attacks, and this release advances CrowdStrike’s Next-Gen Identity Security leadership with real-time, risk-aware protection against AI-accelerated phishing attacks and credential abuse at the point of authentication. With an intelligent security fabric spanning the identity lifecycle, CrowdStrike eliminates friction, increases productivity, and stops breaches.

“Traditional MFA is architecturally broken. Disconnected from real-time risk signals, it’s blind to emerging threats, susceptible to MFA bypass attacks, and creates unnecessary friction,” said Elia Zaitsev, chief technology officer at CrowdStrike. “FalconID accelerates CrowdStrike’s identity security transformation, moving organizations beyond isolated, static access controls to continuous, risk-aware protection that stops breaches without slowing the business.”

AI-Accelerated Identity Threats

As adversaries weaponize AI, the risk, scale, and impact of social engineering and credential abuse increase dramatically. Highly convincing campaigns can be launched by nearly anyone, with attackers routinely bypassing traditional MFA through AI-enhanced phishing, MFA fatigue, and session hijacking. At the same time, friction-heavy MFA slows users to the point organizations often disable it entirely. The future of secure access requires protection that’s informed by real-time risk, adapts as conditions change, and doesn’t slow productivity.

Unified, Zero-Friction MFA

Traditional IAM and PAM were designed to manage access, not stop breaches. Even with MFA, they function as isolated, point-in-time controls – adding friction while lacking the real-time security context to stop AI-accelerated phishing attacks. FalconID reimagines authentication as a seamless, risk-informed experience built directly into the Falcon sensor and delivered through the Falcon for Mobile app. Using real-time Falcon platform risk signals, it determines when access is safe and when it’s not, without forcing users through unnecessary steps. FalconID eliminates friction without compromising security, transforming identity and access management at the speed of AI.

Falcon® Next-Gen Identity Security already secures the full hybrid identity lifecycle across human, non-human, and AI agent identities – spanning initial access, privileged access, identity threat detection and response (ITDR), and SaaS identity security. With the acquisitions of SGNL and Seraphic, CrowdStrike eliminates standing privileges and continuously secures interactions from the endpoint, through browser sessions, and into the cloud – starting at the point of authentication with FalconID.

Key features and benefits include:

  • Security-First Authentication: FalconID continuously evaluates Falcon platform risk signals across identity, endpoint, device, and behavior to determine when access is safe – and when it’s not. When certainty is high, users authenticate transparently. When risk changes, access adapts automatically.
  • Zero-Friction, Device-Bound Verification: Eliminates passwords, push notifications, and one-time codes through FIDO2-based biometric authentication that requires verified physical proximity between the MFA device (mobile) and authentication device (laptop, workstation) to approve access.
  • Unified Architecture: Delivered through the Falcon for Mobile app, FalconID verifies the user and device in real time – without redirects, third-party integrations, or bolt-on controls that create protection gaps and slow users down.
  • Next-Gen Identity Security Transformation: As the browser becomes the new endpoint, FalconID delivers passwordless browser authentication through Seraphic, extended by SGNL’s Continuous Access Evaluation Protocol (CAEP)-driven enforcement integrated into Falcon® Fusion SOAR. This continuously adapts access, eliminates standing privileges, protects users and interactions from first authentication through execution, and secures downstream systems as risk changes – without slowing users down.

To learn more about FalconID and how CrowdStrike is transforming identity security visit here.

About CrowdStrike

CrowdStrike (NASDAQ: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data.

Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft, and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting, and prioritized observability of vulnerabilities.

Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity, and immediate time-to-value.

CrowdStrike: We stop breaches.

Learn more: https://www.crowdstrike.com/
Follow us: Blog | X | LinkedIn | Instagram
Start a free trial today: https://www.crowdstrike.com/trial

© 2026 CrowdStrike, Inc. All rights reserved. CrowdStrike and CrowdStrike Falcon are marks owned by CrowdStrike, Inc. and are registered in the United States and other countries. CrowdStrike owns other trademarks and service marks and may use the brands of third parties to identify their products and services.

Contacts

Media Contact
Jake Schuster
CrowdStrike Corporate Communications
press@crowdstrike.com

CrowdStrike

NASDAQ:CRWD

Release Versions

Contacts

Media Contact
Jake Schuster
CrowdStrike Corporate Communications
press@crowdstrike.com

More News From CrowdStrike

CrowdStrike Fal.Con Gov Accelerates National Cyber Defense in the AI Threat Era

AUSTIN, Texas--(BUSINESS WIRE)--CrowdStrike (NASDAQ: CRWD) today announced Fal.Con Gov 2026 is taking place March 18 in Washington, D.C. Fal.Con Gov gathers government security leaders to advance strategy, operational execution, and AI-driven defense to protect the nation’s most critical systems. Now in its third year, this must-attend event brings together senior policymakers, national security, defense, and public sector cybersecurity leaders, including White House National Cyber Director Sea...

VAST Data and CrowdStrike Partner to Establish a Unified Security Model for the AI Lifecycle

AUSTIN, Texas & SALT LAKE CITY--(BUSINESS WIRE)--VAST Forward – Today at VAST Forward 2026, VAST Data, the AI Operating System company, and CrowdStrike (NASDAQ: CRWD) announced a strategic partnership that combines VAST’s native data-layer governance and platform-level controls with CrowdStrike’s enterprise-grade threat detection and automated response. By integrating these capabilities within the VAST AI Operating System and connecting telemetry with the CrowdStrike Falcon® cybersecurity platf...

2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface

AUSTIN, Texas--(BUSINESS WIRE)--CrowdStrike (NASDAQ: CRWD) today released its 2026 Global Threat Report, revealing that AI is accelerating the adversary and expanding the enterprise attack surface. The average eCrime breakout time fell to just 29 minutes in 2025, with the fastest observed breakout occurring in only 27 seconds. Adversaries are also actively exploiting AI systems themselves, injecting malicious prompts into GenAI tools at more than 90 organizations and abusing AI development plat...
Back to Newsroom