> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/manage-endpoints.md).

# Manage endpoints

The **All Endpoints** page provides a central location from which you can view and manage the endpoints on which the agent is installed. To access the **All Endpoints** page, go to **Inventory** → **Endpoints** → **All Endpoints**.

To ensure the **All Endpoints** table is displaying the most accurate list of endpoints, you can perform a one-time or periodic cleanup of duplicated entities. After the cleanup, duplicated entities are removed leaving only one endpoint entry, which is the last endpoint to connect with the server. Deleted endpoint data is retained for 90 days from the last connection timestamp. If a deleted endpoint reconnects, Cortex Cloud recovers and redisplays the endpoint’s existing data.

Go to Settings → Configurations → General → Agent Configurations → **Endpoint Administration Cleanup**. Enable the **Periodic duplicate cleanup** and select either **One-time cleanup** or define a periodic cleanup to run according to the Host Name, Host IP Address, and/or MAC Address fields at a specific time interval.

### **Endpoint actions**

The right-click pivot menu displays the actions you can perform on your endpoints. For more information about these actions, see the topics in this section, and the topics under [Manage endpoint protection](/cortex-cloud-runtime-security/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection.md).

{% hint style="info" %}

### Note

For the **Include endpoints from auto upgrade** action, you cannot enable auto upgrade for Mobile, VDI, and TS installations.
{% endhint %}

<details>

<summary>All Endpoints reference information</summary>

The following table describes both the default and additional optional fields that you can view in the **All Endpoints** table and lists. Clicking on a row in the **All Endpoints** table opens a detailed view of the endpoint.

<table><thead><tr><th width="210">Field</th><th>Description</th></tr></thead><tbody><tr><td>Active Directory</td><td>Active Directory Groups and Organizational Units to which the user belongs.</td></tr><tr><td>Assigned Extensions Policy</td><td>Policy related to extensions and devices connected to the endpoint.</td></tr><tr><td>Assigned Prevention Policy</td><td>Policy assigned to the endpoint.</td></tr><tr><td>Agent Version</td><td>Agent version that is installed on the endpoint.</td></tr><tr><td>Auto Upgrade Status</td><td><p>When Cortex XDR agent auto upgrades are enabled, this field indicates the action status.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If an endpoint is excluded, the auto upgrade profile configuration is not available.</p><p>If you exclude the endpoint from auto upgrade while the auto upgrade action is <strong>In progress</strong>, the ongoing upgrade will still take place.</p></div></td></tr><tr><td>Cloud Account ID</td><td>Unique identifier for the cloud account that owns or manages the workload.</td></tr><tr><td>Cloud Info</td><td>IBM and Alibaba Cloud metadata reported by the workload.</td></tr><tr><td>Cloud Instance ID</td><td>(Agent 8.9 and later) Unique identifier for the cloud instance hosting the workload.</td></tr><tr><td>Cloud Provider</td><td>(Agent 8.9 and later) Cloud service provider hosting the workload.</td></tr><tr><td>Cloud Region</td><td>(Agent 8.9 and later) Geographical region of the cloud infrastructure where the workload is hosted.</td></tr><tr><td>Cluster Name</td><td>(Agent 8.9 and later) Cluster name to which the workload belongs.</td></tr><tr><td>Content Auto Update</td><td>Whether automatic content updates are <strong>Enabled</strong> or <strong>Disabled</strong> for the endpoint in the agent settings profile.</td></tr><tr><td>Content Release Timestamp</td><td>Time and date of when the current content version was released.</td></tr><tr><td>Content Rollout Delay (days)</td><td>If you configured delayed content rollout, the number of days for delay is displayed here.</td></tr><tr><td>Content Version</td><td>Content update version used with the agent.</td></tr><tr><td>Disabled Capabilities</td><td><p>List of capabilities that were disabled on the endpoint. Options are <strong>Live Terminal</strong>, <strong>Script Execution</strong>, and <strong>File Retrieval</strong>.</p><p>You can disable these capabilities during agent installation on the endpoint or through <strong>Endpoint Administration</strong>. Disabling any of these actions is irreversible. If you later want to enable the action on the endpoint, you must uninstall the agent and install a new package on the endpoint.</p></td></tr><tr><td>Endpoint ID</td><td>Unique ID that identifies the endpoint.</td></tr><tr><td>Endpoint Name</td><td>Hostname of the endpoint. If the agent enables Pro features, this field also includes a <strong>PRO</strong> badge. For Android endpoints, the hostname comprises the &#x3C;<code>firstname</code>><code>—</code>&#x3C;<code>lastname</code>> of the registered user, with a separating dash.</td></tr><tr><td>Endpoint Type</td><td>Type of endpoint.</td></tr><tr><td>Endpoint Version</td><td>Versions of the agent that runs on the endpoint.</td></tr><tr><td>First Seen</td><td>Date and time the agent first checked in (registered) with Cortex Cloud.</td></tr><tr><td>Group Names</td><td>Endpoint Groups to which the endpoint is a member, if applicable.</td></tr><tr><td>IP Address</td><td>Last known IPv4 address of the endpoint.</td></tr><tr><td>IPv6 Address</td><td>Last known IPv6 address of the endpoint.</td></tr><tr><td>Last Scan</td><td>Date and time of the last malware scan on endpoint.</td></tr><tr><td>MAC Address</td><td>Endpoint MAC address that corresponds to the IP address. Currently, this information is available only for IPv4 addresses.</td></tr><tr><td>Operating System</td><td>Name of the operating system.</td></tr><tr><td>OS Description</td><td>Operating system version name.</td></tr><tr><td>OS Type</td><td>Name of the operating system.</td></tr><tr><td>OS Version</td><td>Operating system version number.</td></tr><tr><td>Platform</td><td>Platform architecture.</td></tr><tr><td>Tags</td><td><p>Tags associated with the endpoint.</p><p>Tags created in the agent are displayed with a shield icon.</p></td></tr><tr><td>User</td><td>User that was last logged into the endpoint. On Android endpoints, the Cortex Cloud tenant identifies the user from the email prefix specified during app activation.</td></tr></tbody></table>

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/investigate-endpoints/manage-endpoints.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
