For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Uninstall the Cortex XDR agent

Uninstall Cortex XDR agent from one or more endpoints at any time using the Action Center, or one-by-one using the All Endpoints page.

If you want to uninstall the Cortex XDR agent from the endpoint, you can do so from the Cortex Cloud tenant at any time. You can uninstall them from an unlimited number of endpoints in a single bulk action using the Action Center. You can also uninstall each endpoint one-by-one, using the All Endpoints page.

Uninstallation of an endpoint triggers the following lifespan flow:

  • When you uninstall the agent from the endpoint, the action is immediate. All agent files and protections are removed from the endpoint, leaving the endpoint unprotected.

  • The endpoint status changes to Uninstalled , and the license returns immediately to the license pool. After a retention period of 7 days, the agent is deleted from the database and is displayed in Cortex Cloud as Endpoint Name - N/A (Uninstalled).

  • Data associated with the deleted endpoint is displayed in the Action Center tables and the Causality View for the standard 90-day retention period.

  • Issues that already include the endpoint data at the time of the issue creation are not affected.

Uninstall endpoints using the Action Center

1

Log in to Cortex Cloud. Go to Investigation & Response → ResponseAction Center.

2

Click + New Action.

3

Select Agent Uninstall.

4

Click Next.

5

Select the target endpoints (up to 100) from which you want to uninstall the Cortex XDR agent.

Tip:

If needed, use the filter to filter the list of endpoints by attribute or group name.

6

Click Next.

7

Review the action summary and click Done when finished.

8

To track the status of the uninstallation, return to the Action Center.

Uninstall endpoints using the All Endpoints page

1

Log in to Cortex Cloud. Go to Inventory → Endpoints → All Endpoints.

2

Find and then right-click the agent that you want to uninstall, and select Endpoint Control → Uninstall Agent.

3

In the confirmation dialog box that appears, select I agree, and click OK.

Last updated

Was this helpful?