Upgrade and configure Premium
This guide covers the upgrade process itself and the configuration steps that follow. Complete Plan your Premium deployment before you start here.
Before you beginโ
| Requirement | Detail |
|---|---|
| Organization role | Organization Admin |
| Billing | A valid payment method on the account |
| Scope | The upgrade applies to one organization; repeat for each organization you want on Premium |
| Recommended engine version | Latest stable release of CrowdSec Agent |
Upgrade your organizationโ
- Log in to the CrowdSec Console.
- Switch to the organization you want to upgrade using the organization switcher in the top-left corner.
- Navigate to Organization Settings โ Plan.
- Select Upgrade to Premium and choose your plan.
- Enter payment details or confirm the 30-day trial.
- Confirm the upgrade.
Premium entitlements are active immediately after confirmation.
What changes immediatelyโ
The following entitlements are unlocked automatically the moment you upgrade. No additional configuration is needed for them to take effect.
| Feature | What changes |
|---|---|
| Community Blocklist (Premium) | Your enrolled Security Engines begin receiving the top 50k IP list instead of 3k |
| Alert quota | Raised to 10k alerts per Security Engine per month |
| Alert retention | Extended to 365 days |
| Threat Forecast Blocklist | Generated automatically from your organization's shared signals; no action required |
| Console IP investigations | Raised to 100 per week |
| CTI API calls | Raised to 1,500 per month |
| Organization seats | Expanded to 5 included seats |
| Am I Under Attack | Available in the Console immediately |
What requires configurationโ
These features are available after upgrading but do not become active until you configure them.
Subscribe to Premium blocklistsโ
Premium tier blocklists and unlimited subscriptions are unlocked, but you must subscribe to each list you want.
- Go to Blocklists in the Console.
- Browse the Premium-tier lists.
- Subscribe to the lists relevant to your infrastructure (bruteforce, botnets, TOR, scanners, proxies, and so on).
Enable Remediation Syncโ
Remediation Sync propagates decisions from the Console to all enrolled Security Engines and blocklist integration endpoints. It is off by default.
- Go to Organization Settings โ Remediation Sync.
- Enable Remediation Sync for the organization.
- Verify that your Security Engines are enrolled and reachable.
Enable Background Noise filteringโ
Background Noise filtering removes mass-scanner and crawler traffic from your alert view. Choose a level (Low, Medium, or High) based on how aggressively you want to suppress background activity.
- Go to Alerts โ Background Noise.
- Select a filtering level.
- Apply.
Background Noise filtering โ
Invite team membersโ
Premium includes 5 seats. Add team members with appropriate roles.
- Go to Organization Settings โ Members.
- Invite members by email.
- Assign roles: Viewer, Editor, or Admin.
Organization seats and roles โ
Configure notificationsโ
Set up push notifications so your team receives alerts when Security Engines go offline, become outdated, or when abnormal attack surges are detected.
- Go to Organization Settings โ Notifications.
- Connect integrations (Slack, PagerDuty, webhooks, or others).
- Configure which events trigger each notification channel.
Create Service API credentialsโ
The Service API allows programmatic management of blocklists, decisions, and enrollments. Access requires credentials scoped to your organization.
- Go to Organization Settings โ Service API.
- Create a new API key.
- Note the key โ it is shown only once.
Enable Auto Enrollโ
Auto Enroll lets new Security Engines join your organization automatically when they are deployed with your enrollment key, without manual approval in the Console.
- Go to Organization Settings โ Auto Enroll.
- Enable Auto Enroll.
- Use the organization enrollment key in your deployment configuration.
Configure centralized allowlistsโ
Create organization-wide allowlists that apply to all enrolled Security Engines and integrations. These replace per-engine allowlists.
- Go to Allowlists in the Console.
- Create allowlist entries.
- Set expiration dates for temporary allowlisting if needed.
Feature states at a glanceโ
| Feature | State after upgrading |
|---|---|
| Community Blocklist (50k) | Automatic |
| Threat Forecast Blocklist | Automatic |
| Extended alert quota | Automatic |
| 365-day retention | Automatic |
| Increased Console IP investigations | Automatic |
| Increased CTI API quota | Automatic |
| Am I Under Attack | Automatic โ check Console for alerts |
| Premium blocklist subscriptions | Requires subscribing to each list |
| Remediation Sync | Requires enabling |
| Background Noise filtering | Requires enabling and selecting a level |
| Additional team seats | Requires inviting members |
| Push notifications | Requires connecting integrations |
| Service API | Requires creating API credentials |
| Auto Enroll | Requires enabling |
| Centralized allowlists | Requires creating entries |
Verify your upgradeโ
After completing configuration, confirm the following.
- Organization plan shows Premium in Organization Settings โ Plan
- Security Engines show the Premium Community Blocklist in their active blocklists
- Alert quota and retention settings reflect Premium limits (check Alerts โ Quotas)
- Remediation Sync is enabled and shows enrolled engines as reachable
- At least one team member has been invited (if applicable)
- Notifications are connected and receiving test events
Downgrading or ending a trialโ
If you downgrade or let a trial expire without converting:
| Item | What happens |
|---|---|
| Community Blocklist | Reverts to top 3k IPs |
| Alert quota | Returns to 500 per month |
| Alert retention | Returns to 60 days; alerts older than 60 days become inaccessible |
| Remediation Sync | Disabled; engines stop receiving centralized decisions |
| Background Noise | Disabled |
| Am I Under Attack | Disabled |
| Premium blocklist subscriptions | Reverted to 3 maximum; excess subscriptions are deactivated |
| Service API credentials | Deactivated |
| Team seats above 1 | Members above the Community limit lose access |
| Historical alert data | Data beyond the Community retention window is not deleted immediately but becomes inaccessible until you re-upgrade |
Contact CrowdSec support if you have questions about data retention during a plan change.
Continue to Evaluate your Premium trial โ