There's potentially a huge issue here for people using BitLocker with on-prem AD, because they'll need the BitLocker recovery keys for each endpoint to go in an fix it.
And if all those recovery keys are stored in AD (as they usually are), and the Domain Controllers all had Crowdstrike on them...
Most of the large deployments I've seen don't use pre-boot PINs, because of the difficulty of managing them with users - they just use TPM and occasionally network unlock.
So might save a few people, but I suspect not many.
And if all those recovery keys are stored in AD (as they usually are), and the Domain Controllers all had Crowdstrike on them...