Disk encryption
Cortex Cloud provides full visibility into encrypted Windows and Mac endpoints that were encrypted using BitLocker and FileVault, respectively. Additionally, you can apply Cortex Cloud Disk Encryption rule on the endpoints by creating disk encryption rules and policies that leverage BitLocker and FileVault capabilities.
Before you start applying disk encryption policy rules, ensure you meet the following requirements and refer to these known limitations:
Endpoint Prerequisites
The endpoint must be running a Microsoft Windows version that supports BitLocker.
The endpoint must be within the organization's network domain.
To allow the agent to encrypt the endpoint, Trusted Platform Module (TPM) must be supported and enabled on the endpoint.
Active Directory Domain Services is required for recovery key backup.
The endpoint must be running a macOS version that supports FileVault.
Disk Encryption Scope
You can enforce Cortex Cloud disk encryption policy rules only on the Operating System volume.
You can enforce XDR disk encryption policy rules only on the Operating System volume.
The Cortex XDR Disk Encryption profile for Mac can encrypt the endpoint disk, however, it cannot decrypt it. After you disable the Cortex Cloud policy rule on the endpoint, you can decrypt the endpoint manually.
Other
Group Policy configuration:
Make sure the GPO configuration applying to the endpoint enables Save BitLocker recovery information to AD DS for operating system drives.
Make sure your Cortex Cloud disk encryption policy does not conflict with the GPO configuration to Choose drive encryption method and cipher strength.
Provide a FileVaultMaster certificate / institutional recovery key (IRK) that is signed by a valid authority.
It can take the agent up to 5 minutes to report the disk encryption status to Cortex Cloud if the endpoint was encrypted through Cortex Cloud, and up to one hour if it was encrypted through another MDM.
In line with the operating system requirements, the Cortex Cloud encryption profile will take place on the endpoint after the user logs off and back on, and approves the prompt to enable the endpoint encryption.
Palo Alto Networks recommends that you do not apply an encryption enforcement from another MDM on the endpoint together with the Cortex Cloud encryption profile.
Follow this high-level workflow to deploy the Cortex Cloud disk encryption in your network:
Last updated
Was this helpful?
