Pause endpoint protection
Pause endpoint protection when investigation requires it.
As of agent 7.7 and above, you can pause the agent protection capabilities on one or more endpoints while the agent remains fully connected to Cortex Cloud. When protection is paused, the agent runs with all prevention profiles disabled, meaning nothing is blocked, quarantined, or terminated on the endpoint. EDR telemetry collection is not affected. The agent continues to collect and forward endpoint events to Cortex Cloud, and the server can still push policy and response actions to the agent. When you are ready, you can resume the endpoint protection.
How to pause endpoint protection modules
Go to Inventory+Endpoints → All Endpoints.
In the All Endpoints page, select the endpoints on which you want to pause protection, right-click and select Endpoint Control → Pause Endpoint Protection.
Verify the endpoints, add an optional comment that appears in the Management Audit log, and Pause the protection.
Paused endpoints display a pause icon in the Endpoint Name field, and one of the following the action statuses in Manual Protection Pause field:
Protection Active
Pending Pause
Protection Paused
Pending Activation
When you are ready to resume protection, select the paused endpoints, right-click and select Endpoint Control → Resume Endpoint Protection and Resume protection on the listed endpoints.
The All Endpoint table fields are updated accordingly.
Track your pause and resume endpoint protection actions.
Go to Investigation & Response → Response → Action Center and locate Action Type Pause Endpoint Protection or Resume Endpoint Protection.
Last updated
Was this helpful?
