> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-global-endpoint-policy-exception.md).

# Add a global endpoint policy exception

As an alternative to adding an endpoint-specific exception in policy rules, you can define and manage global exceptions that apply across all of your endpoints. On the **Global Exception** page, you can manage all the global exceptions in your organization for all platforms. Profiles associated with one or more targets that are beyond your defined user scope are locked and cannot be edited.

{% hint style="info" %}

### Important

* Starting with version 3.5, Cortex XDR enables you to manage the Global Endpoint Policy exceptions from a central location and easily apply them across multiple profiles in the Legacy Agent Exceptions management page.&#x20;
* To manage the prevention profile exceptions from **Exception Configuration**, you must first migrate your existing exceptions configured via the Global exceptions.
* Your migrated rules are displayed on the **Settings** → **Exception Configurations** → **Legacy Agent Exceptions** page. For more information about the migration, see [Exception configuration](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/exception-configuration.md).
* To create new global endpoint policy exceptions using the **Legacy Agent Exceptions** page, see [Add a legacy exception rule](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule.md).
* If you don't migrate the legacy exceptions, you can continue to add exceptions as described below.
  {% endhint %}

<details>

<summary>Add a global process exception</summary>

Configure exception rules forCortex XDR protection and prevention actions in a centralized location, and apply them across multiple profiles.

1. Go to **Endpoints** → **Policy Management** → **Policy Exceptions**.
2. Select **Process exceptions**.
   1. Select the operating system.
   2. Enter the name of the process.
   3. Select one or more Endpoint Protection Modules that will allow this process to run. The modules displayed on the list are the modules relevant to the operating system defined for this profile. To apply the process exception on all security modules, **Select all**. To apply the process exception on all exploit security modules, select **Disable Injection**. Click the adjacent arrow to add the exception.
3. After you add all exceptions, **Save** your changes.

   The new process exception is added to the **Global Exceptions** in your network and will be applied across all rules and policies. To edit the exception, select it and click the edit icon. To delete it, select it and click the delete icon.

</details>

<details>

<summary>Add a global support exception</summary>

Configure support exception rules for Cortex XDR protection and prevention actions in a centralized location, and apply them across multiple profiles.

1. Go to **Endpoints** → **Prevention** → **Global Exceptions**.
2. Select **Support Exceptions**.

   Import the JSON file you received from the Palo Alto NetworksPalo Alto Networks support team by either browsing for it in your files or by dragging and dropping the file on the page.
3. Click **Save**.

   The new support exception is added to the **Global Exceptions** in your network and will be applied across all rules and policies.

</details>

<details>

<summary>Add a behavioral threat protection rule exception</summary>

When you view a Behavioral Threat alert in the **Alerts** table which you want to allow across your organization, you can create an exception for that rule.

1. Right-click the BTP alert and select **Create alert exception**.
2. Review the alert meta data (platform, generating alert number, and rule name) and then select the method for creating the exception rule:

   **Use recommended exception criteria**

   Base an exception on Cortex XDR’s recommended fields to define granular and precise exception criteria. The automated recommendations enable you to define exceptions for the specific behavior that triggered the alert and its parameters. This allows you to create exceptions for behaviors that are considered acceptable by your organization.

   1. Select the criteria that triggered the alert.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You can only select one criteria per alert.</p><p>To create an exception for more than one criteria in an alert, create an exception rule for each criteria separately by right clicking the BTP alert and creating another exception.</p></div>

   2. From the displayed parameters of the criteria, select one or more parameters that are relevant to your exception.

      By default, all parameters are unselected. To create an exception, you must select at least one parameter.

   3. In the editable parameters, change the parameter if needed.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><ul><li>The value you type is validated by Cortex XDR.</li><li>You can use wildcards, but we recommend being as specific as possible to avoid exceptions that are too broad.</li><li>Some parameters aren't open to editing.</li></ul></div>

   **Use CGO information**&#x20;

   1. Select CGO attributes to define general exception criteria.
      1. **CGO hash:** Causality Group Owner (CGO) hash value.
      2. **CGO signer:** CGO signer entity (for Windows and Mac only).
      3. **CGO process path:** Directory path of the CGO process.
      4. **CGO command arguments:** CGO command arguments. This option is available only if **CGO process path** is selected, and only if you are using Cortex XDR Agent 7.5 or later on your endpoints. After selecting this option, check the full path of each relevant command argument within quote marks. You can edit the displayed paths if needed.
3. From **Scope**, select **Global** or select the **Profile** to which you want to apply the exception rule.
4. Click **Create**.

   The relevant BTP exception is added to the **Global Exceptions** or to the **Profile** exceptions you selected in your network and will be applied across all rules and policies. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific exception, select it and click **X**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You cannot edit exceptions generated from a BTP security event.</p></div>

</details>

<details>

<summary>Add a global credential gathering protection exception</summary>

When you view a Credential Gathering Protection alert in the **Alerts** table that you want to allow across your organization, you can create a global exception for that rule.

1. Right-click the Credential Gathering Protection alert and select **Create alert exception**.
2. Review the alert data (platform and module name) and then select from the following options as needed:
   1. **CGO hash:** Causality Group Owner (CGO) hash value.
   2. **CGO signer:** CGO signer entity (for Windows and Mac only).
   3. **CGO process path:** Directory path of the CGO process.
   4. **CGO command arguments:** CGO command arguments. This option is available only if **CGO process path** is selected, and only if you are using Cortex XDR agent 7.5 or later on your endpoints. After selecting this option, check the full path of each relevant command argument within quote marks. You can edit the displayed paths if needed.
   5. From **Exception Scope**, select **Global**.
3. Click **Create**.

   The relevant exception is added to the **Global Exceptions** in your network and will be applied across all rules and policies. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific global exception, select it and click **X**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You cannot edit global exceptions generated from a Credential Gathering Protection security event.</p></div>

</details>

<details>

<summary>Add a global anti webshell protection exception</summary>

When you view an Anti Webshell Protection alert in the **Alerts** table that you want to allow across your organization, you can create a global exception for that rule.

1. Right-click the Anti Webshell Protection alert and select **Create alert exception**.
2. Review the alert data (platform and module name) and then select from the following options as needed:
   1. **CGO hash:** Causality Group Owner (CGO) hash value.
   2. **CGO signer:** CGO signer entity (for Windows and Mac only).
   3. **CGO process path:** Directory path of the CGO process.
   4. **CGO command arguments:** CGO command arguments. This option is available only if **CGO process path** is selected, and only if you are using Cortex XDR Agent 7.5 or later on your endpoints. After selecting this option, check the full path of each relevant command argument within quote marks. You can edit the displayed paths if needed.
   5. From **Exception Scope**, select **Global**.
3. Click **Create**.

   The relevant exception is added to the **Global Exceptions** in your network and will be applied across all rules and policies. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific global exception, select it and click **X**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You cannot edit global exceptions generated from an Anti Webshell Protection security event.</p></div>

</details>

<details>

<summary>Add a global local analysis rules exception</summary>

When you view in the **Alerts** table a Local Analysis alert that was triggered as a result of local analysis rules, you can create a global exception to allow the rules across your organization.

1. Right-click the alert and select **Create alert exception**.
2. Review the alert data (platform and rule name) and select **Exception Scope:Global**.
3. Click **Add**.

   The relevant Local Analysis Rules exception is added to the **Global Exceptions** in your network and will be applied across all rules and policies. The exception allows all the rules that triggered the alert, and you cannot choose to allow only specific rules within the alert. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific global exception, select it and click **X**. You cannot edit global exceptions generated from a local analysis security event.

</details>

<details>

<summary>Review advanced analysis exceptions</summary>

With Advanced Analysis, Cortex XDR can provide a secondary validation of Cortex XDR agent alerts raised by exploit protection modules. To perform the additional analysis, Cortex XDR analyzes alert data sent by the Cortex XDR agent. If Advanced Analysis indicates an alert is benign, Cortex XDR can automatically create exceptions and distribute the updated security policy to your endpoints.

By enabling Cortex XDR to automatically create and distribute global exceptions you can minimize disruption for users when they subsequently encounter the same benign activity. To enable the automatic creation of Advanced Analysis Exceptions, configure the Advanced Analysis options in **Settings** → **Configurations** → **General** → **Agent Configurations**.

For each exception, Cortex XDR displays the affected platform, exception name, and the relevant alert ID for which Cortex XDR determined activity was benign. To drill down into the alert details, click the **Generating Alert ID**.

</details>

<details>

<summary>Add a global digital signer exception</summary>

When you view in the **Alerts** table a Digital Signer Restriction alert for a digital signer you trust and want to allow from now on across your network, create a Global Exception for that digital signer directly from the alert.

1. Right-click the alert and select **Create alert exception**.

   Review the alert data (Platform, signer, and alert ID) and select **Exception Scope:Global**.
2. Click **Add**.

   The relevant digital signer exception is added to the **Global Exceptions** in your network and will be applied across all rules and policies. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific global exception, select it and click **X**. You cannot edit global exceptions generated from a digital signer restriction security event.

</details>

<details>

<summary>Add a global java deserialization exception</summary>

When you view in the **Alerts** table a Suspicious Input Desensitization alert for a Java executable you want to allow from now on across your network, create a global exception for that executable directly from the alert of the security event that prevented it.

1. Right-click the alert and select **Create alert exception**.

   Review the alert data (Platform, Process, Java executable, and alert ID) and select **Exception Scope: Global**.
2. Click **Add**.

   The relevant digital signer exception is added to the **Global Exceptions** in your network and will be applied across all rules and policies. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific global exception, select it and click **X**. You cannot edit global exceptions generated from a digital signer restriction security event.

</details>

<details>

<summary>Add a global local file threat examination exception</summary>

When you view in the **Alerts** table a Local Threat Detected alert for a PHP file you want to allow from now on across your network, create a global exception for that file directly from the alert of the security event that prevented it.

1. Right-click the alert and select **Create alert exception**.

   Review the alert data (Process, Path, and Hash) and select **Exception Scope: Global**.
2. Click **Add**.

   The relevant PHP file is added to the **Global Exceptions** in your network and will be applied across all rules and policies. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific global exception, select it and click **X**. You cannot edit global exceptions generated from a local file threat examination exception restriction security event.

</details>

<details>

<summary>Add a global gatekeeper enhancement exception</summary>

When you view a Gatekeeper Enhancement security alert in the **Alerts** table, you can create a global exception for this specific bundle or source-child combination only, while allowing Cortex XDR to continue enforcing the Gatekeeper Enhancement protection module on the source process running other child processes.

1. Right-click the alert and select **Create alert exception**.

   Review the alert data (Platform, Source Process, Target Process, and Alert ID) and select **Exception Scope: Global**.
2. Click **Add**.

   The relevant source and target processes are added to the **Global Exceptions** in your network and will be applied across all rules and policies. At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. To delete a specific global exception, select it and click **X**. You cannot edit global exceptions generated from a gatekeeper enhancement security event.

</details>

<details>

<summary>Import and export exceptions</summary>

Select **+ Import/Export** to **Export** your exceptions list and/or **Import from File**.

{% hint style="info" %}

### Note

The exported file is encoded in Base64 and cannot be edited.
{% endhint %}

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-global-endpoint-policy-exception.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
