> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-new-exceptions-security-profile.md).

# Add a new exceptions security profile

You can configure exceptions that apply to specific groups of endpoints or you can add a global endpoint policy exception.

{% hint style="info" %}

### Important

Starting with version 3.5, Cortex XDR enables you to manage the exception security rules from a central location and easily apply them across multiple profiles in the **Legacy Agent Exceptions management** page.&#x20;

To manage the exceptions from **Exception Configuration**, you must first migrate your existing exceptions configured via the exceptions security profiles.

To create new exception security profile rules using the **Legacy Agent Exceptions management** page, see [Add a legacy exception rule](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule.md).

If you don't migrate the legacy exceptions, you can continue to create exceptions as described below.
{% endhint %}

How to create an endpoint-specific exception

1. Add a new profile.
   1. From Cortex XDR, select **Endpoints** → **Policy Management** → **Prevention** → **Profiles** → **+Add Profile** and select whether to **Create New** or **Import from File** a new profile.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New imported profiles are added and not replaced.</p></div>
   2. Select the platform to which the profile applies and **Exceptions** as the profile type.
   3. Click **Next**.
2. Define the basic settings.
   1. Select a unique **Profile Name** to identify the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   2. To provide additional context for the purpose or business reason for creating the profile, specify a profile **Description**. For example, you might include an incident identification number or a link to a help desk ticket.
3. Configure the exceptions profile.

<details>

<summary>Configure a process exception</summary>

1. Select the operating system.
2. Enter the name of the process.
3. Select one or more endpoint protection modules that will allow this process to run. The modules displayed in the list are the modules relevant to the operating system defined for this profile.

   * To apply the process exception on all security modules, **Select all**.
   * To apply the process exception on the following exploit modules, select **Disable Injection**.

     APC Guard, CPL Execution Protection, DEP, DLL Hijacking Protection, DLL Security, EPM D02, Exception Heap Spray Check, Exception SysExist Check, Exploit Kit Fingerprinting Protection, Font Protection, Hot Patch Protection, JIT Mitigation, Library Preallocation, Memory Limit Heap Spray Check, Null Dereference Protection, Password Theft Protection, ROP Mitigation, SEH Protection, Shellcode Preallocation, UASLR
4. Click the adjacent arrow.
5. After you've added all the processes, select **Create**.

   You can return to the Process Execution profile from the **Endpoint Profile** page at any point and edit the settings. For example, if you want to add or remove security modules.

</details>

<details>

<summary>Configure a support exception</summary>

1. Import the json file you received from the Palo Alto Networks support team by either browsing for it in your files or by dragging the file on the page.
2. Click **Create**.

</details>

<details>

<summary>Configure module-specific exceptions relevant for the selected profile platform</summary>

* **Behavioral Threat Protection Rule Exception:** When you view an alert for a Behavioral Threat event that you want to allow in your network from now on, right-click the alert and **Create alert exception**. Review the alert data (Platform and Rule name) and select from the following options as needed.

  * **CGO hash**: Causality Group Owner (CGO) hash value
  * **CGO signer**: CGO signer entity (for Windows and Mac only)
  * **CGO process path**: Directory path of the CGO process
  * **CGO command arguments**: This option is available only if **CGO process path** is selected, and only if you are using Cortex XDR Agent 7.5 or later on your endpoints. After selecting this option, check the full path of each relevant command argument within quote marks. You can edit the displayed paths if needed.

    From **Exception Scope**, select **Profile** and click **Create.**
* **Digital Signer Exception:** When you view an alert for a Digital Signer Restriction that you want to allow in your network from now on, right-click the alert and **Create alert exception**. Cortex XDR displays the alert data (Platform, Signer, and Generating Alert ID). Select **Exception Scope: Profile** and select the exception profile name. Click **Add**.
* **Java Deserialization Exception:** When you identify a Suspicious Input Deserialization alert that you believe to be benign and want to suppress future alerts, right-click the alert and **Create alert exception**. Cortex XDR displays the alert data (Platform, Process, Java executable, and Generating Alert ID). Select **Exception Scope: Profile** and select the exception profile name. Click **Add**.
* **Local File Threat Examination Exception:** When you view an alert for a PHP file that you want to allow in your network from now on, right-click the alert and **Create alert exception**. Cortex XDR displays the alert data (Process, Path, and Hash). Select **Exception Scope: Profile** and select the exception profile name. Click **Add**.
* **Gatekeeper Enhancement Exception:** When you view a Gatekeeper Enhancement security alert for a bundle or specific source-child combination you want to allow in your network from now on, right-click the alert and **Create alert exception**. Cortex XDR displays the alert data (Platform, Source Process, Target Process, and Alert ID). Select **Exception Scope: Profile** and select the exception profile name. Click **Add**. This exception allows Cortex XDR to continue enforcing the Gatekeeper Enhancement protection module on the source process running other child processes.

At any point, you can click the **Generating Alert ID** to return to the original alert from which the exception originated. You cannot edit module specific exceptions.

</details>

4. [Apply profiles to endpoints](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/apply-profiles-to-endpoints.md).

   If you want to remove an exceptions profile from your network, go to the **Profiles** page, right-click, and select **Delete**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-new-exceptions-security-profile.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
