Disk encryption
For enhanced security, you can configure and apply disk encryption profiles to the disks of your Windows and Mac endpoints.
Cortex XDR provides full visibility into encrypted Windows and Mac endpoints that were encrypted using BitLocker and FileVault, respectively. Additionally, you can apply Cortex XDR Disk Encryption rule on the endpoints by creating disk encryption rules and policies that leverage BitLocker and FileVault capabilities.
Before you start applying disk encryption policy rules, ensure you meet the following requirements and refer to these known limitations:
Requirement / Limitation
Windows
Mac
Endpoint Prerequisites
The endpoint must be running a Microsoft Windows version that supports BitLocker.
The endpoint must be within the organization's network domain.
The endpoint must be running a Cortex XDR agent 7.1 or later.
To allow the agent to encrypt the endpoint, Trusted Platform Module (TPM) must be supported and enabled on the endpoint.
Active Directory Domain Services is required for recovery key backup.
The endpoint must be running a macOS version that supports FileVault.
The endpoint must be running a Cortex XDR agent 7.2 or later.
Disk Encryption Scope
You can enforce XDR disk encryption policy rules only on the Operating System volume.
You can enforce XDR disk encryption policy rules only on the Operating System volume.
The Cortex XDR Disk Encryption profile for Mac can encrypt the endpoint disk, however, it cannot decrypt it. After you disable the Cortex XDR policy rule on the endpoint, you can decrypt the endpoint manually.
Other
Group Policy configuration:
Make sure the GPO configuration applying to the endpoint enables Save BitLocker recovery information to AD DS for operating system drives.
Make sure your Cortex XDR disk encryption policy does not conflict with the GPO configuration to Choose drive encryption method and cipher strength.
Provide a FileVaultMaster certificate / institutional recovery key (IRK) that is signed by a valid authority.
It can take the agent up to 5 minutes to report the disk encryption status to Cortex XDR if the endpoint was encrypted through Cortex XDR, and up to one hour if it was encrypted through another MDM.
In line with the operating system requirements, the Cortex XDR encryption profile will take place on the endpoint after the user logs off and back on, and approves the prompt to enable the endpoint encryption.
Palo Alto Networksrecommends that you do not apply an encryption enforcement from another MDM on the endpoint together with the Cortex XDR encryption profile.
Follow this high-level workflow to deploy the Cortex XDR disk encryption in your network:
Last updated
Was this helpful?
