For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Set up Identity profiles

Configure the Identity Profile to unify AD-SPM, Conditional Access, and LDAP Protection controls in one centralized hub.

License

The Identity Profile centralizes identity security policies for Domain Controllers. It supports consistent security controls across your environment. This Windows-only profile must be mapped to policies for Domain Controller endpoints.

Note

Identity Profile requires Cortex XDR 3.6, Cortex XDR 5.1, or Cortex Cloud Runtime 2.1 or later. It also requires Cortex XDR agent 9.1 or later. It is unavailable for Cortex XDR 2.x and Cortex XDR 3.x tenants.

Policies can contain an Identity Profile in mixed-agent environments. Agents earlier than version 9.1 ignore these settings.

To customize settings for specific agents, create an Identity Profile and assign it to policy rules for Domain Controller endpoints.

  1. Add a profile and define its basic settings.

    1. Go to InventoryEndpointsPolicy ManagementPreventionProfiles. Select + Add Profile, then select whether to create or import a profile.

      Imported profiles are added. They do not replace existing profiles.

    2. Select the Windows platform and Identity profile type.

    3. Click Next.

    4. Enter a unique Profile Name. Use only letters, numbers, or spaces. Names must contain 30 characters or fewer.

    5. Add a Description with the profile's purpose or business reason. For example, include a case ID or help desk ticket link.

  2. Configure LDAP Protection to analyze and act on suspicious LDAP queries sent to Domain Controllers. This feature detects and blocks Active Directory reconnaissance attacks. Use the toggle to enable or disable it.

    LDAP Protection takes effect after an agent restart.

    Item
    Options
    More details

    Action Mode

    Block, Report, Disabled

    The Cortex XDR agent performs this action when it detects suspicious Domain Controller queries.

    Monitor and Collect Domain Controller LDAP Events

    Enabled, Disabled

    When enabled, the agent collects LDAP query information and creates events for investigating suspicious queries.

  3. Click Create to save the profile.

What to do next

Apply the new profile by adding it to a policy rule. You can also define other profiles first. Policy rules let you select the endpoints that receive the policy.

Create a policy rule from the Prevention Profiles page
  1. Go to InventoryEndpointsPolicy ManagementPreventionProfiles.

  2. Right-click the new profile and select Create a new policy rule using this profile.

  3. Configure the policy rule.

Edit an existing policy rule from the Policy Rules page
  1. Go to InventoryEndpointsPolicy ManagementPreventionPolicy Rules.

  2. Right-click an existing policy and select Edit.

  3. Add the new profile to the policy rule.

Create a new policy rule from the Policy Rules page
  1. Go to InventoryEndpointsPolicy ManagementPreventionPolicy Rules.

  2. Click Add Policy.

  3. Configure a policy that includes the new profile.

Last updated

Was this helpful?