> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/cortex-xdr-onboarding-checklist.md).

# Cortex XDR onboarding checklist

![XDR\_Onboard\_Flow.png](/files/C4XTcSjlZFa20Q9vXUt4)

We recommend reviewing the following steps to successfully deploy and onboard Cortex XDR:

<table data-header-hidden><thead><tr><th width="142.1953125"></th><th width="124.75390625"></th><th width="190.91796875"></th><th></th></tr></thead><tbody><tr><td>Step</td><td>Action</td><td>Details</td><td>See more</td></tr><tr><td>Step 1: Activate Cortex XDR</td><td>Activate and log in to Cortex Gateway</td><td><p>1. Follow the instructions in the activation email and sign in to Cortex Gateway.</p><p>2. Confirm license type.</p></td><td><a href="/pages/hxwinw9bBwBVcfKmUP8y">See topic</a></td></tr><tr><td></td><td></td><td>3. Enable access to Cortex XDR communication servers, storage buckets, and resources.</td><td><a href="/pages/xvsMPcxtoI0Tg2onrv4K">See topic</a></td></tr><tr><td>Step 2: Pre-installation steps for Cortex XDR agents</td><td>Assign user roles</td><td>Start assigning roles directly to users or create user groups and assign roles to those groups.</td><td><a href="/pages/8v5vS78yQpUnJWgu1mKQ">See topic</a></td></tr><tr><td></td><td></td><td><p></p><p>Configure how users access Cortex XDR. You can authenticate users by doing one or both of the following:</p><ul><li>User authentication through the Customer Support Portal</li><li>SAML single sign-on in the Cortex XDR tenant</li></ul></td><td><a href="/pages/HHCY85xskcoxOid0nZvX">See topic</a></td></tr><tr><td></td><td>Verify endpoint operating systems</td><td>Validate endpoint operating systems to ensure they are compatible with Cortex XDR.</td><td><a href="/spaces/fZ8QSMnkjnXpuOeuRcam/pages/dca3e59deeffddd47aa713e6d383a5df3f1c7976">See topic</a></td></tr><tr><td></td><td>Define endpoint groups</td><td>(Optional, can be performed post-deployment) Define an endpoint group to apply policy rules and manage specific endpoints. If you set up Cloud Identity Engine, you can also leverage your Active Directory user, group, and computer information in endpoint groups.</td><td><a href="/pages/pzE9meysM1NHCeB00QmY">See topic</a></td></tr><tr><td></td><td>Customize endpoint security profiles</td><td><p>Customize your Endpoint Security Profiles and assign them to your endpoints.</p><p>Cortex XDR provides default security profiles that you can use out-of-the-box to immediately begin protecting your endpoints from threats. Defaults include profiles for exploits, malware, restrictions, agent settings, and exceptions.</p><p>Review your policy rules and the security profiles assigned to these rules and make any necessary adjustments.</p></td><td><a href="/pages/HTkklwjFY5IVLahgdWU6">See topic</a></td></tr><tr><td></td><td>Enable enhanced data collection from endpoints</td><td><p></p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Enhanced data collection requires a Cortex XDR Pro per Endpoint license.</p></div><p>Cortex XDR provides out-of-the-box exploit and malware protection. However, at minimum, you must enable Data Collection in an Agent Settings profile to leverage endpoint data in Cortex XDR.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Data collection for Windows endpoints is available with Traps 6.0 and later releases and on endpoints running Windows 7 SP1 and later releases. Data collection on macOS and Linux endpoints are available with Traps 6.1 and later releases.</p></div><p>1. Enable data collection in an Agent Settings profile to leverage endpoint data in Cortex XDR and use features such as Analytics or Host Insights.</p><p>2. Attach the Agent Settings profile to a policy rule in order to apply it to selected endpoints.</p><p>3. Set global agent configurations that apply to all the endpoints in your network.</p></td><td><p><a href="/pages/hBtD75qu1WOwaw75C6xU">See topic</a></p><p><a href="/pages/qjp301gEFESz7QaFY0Yt">See topic</a></p><p><a href="/pages/kkvI3jxDGJZDWfwgi57n">See topic</a></p></td></tr><tr><td>Step 3: Install Cortex XDR agents</td><td>Plan agent deployment</td><td>Plan your agent deployment.</td><td><a href="/pages/o6V6n4ZIdOhQyfPASykG">See topic</a></td></tr><tr><td></td><td>Keep Cortex XDR agents and content updated</td><td>Recommended strategy and best practices for managing agent and content updates to help reduce the risk of downtime in a production environment, while helping ensure timely delivery of security content and capabilities.</td><td><a href="/pages/auh1Iwo2zs5dV20EV7Dg">See topic</a></td></tr><tr><td></td><td>Create installation packages</td><td>To reduce the network load and time typically required for the initial roll-out or major upgrades of the Cortex XDR agent, Cortex XDR offers an agent installation and content update distribution package.</td><td><a href="/pages/1T0THZGcDoJ5eOjn5Ncm">See topic</a></td></tr><tr><td></td><td>Review the Cortex XDR compatibility matrix</td><td><p></p><p>Until a Cortex XDR agent release reaches its end-of-life (EoL) status, Palo Alto Networks provides the following support:</p><ul><li>Microsoft operating systems are supported for three years beyond the end of Microsoft support</li><li>Other operating system vendors are supported until they reach end-of-life.</li><li>Cortex XDR agents for macOS and 32-bit Windows are not FedRamp compliant.</li></ul></td><td><a href="/spaces/fZ8QSMnkjnXpuOeuRcam/pages/dca3e59deeffddd47aa713e6d383a5df3f1c7976">See topic</a></td></tr><tr><td></td><td>Review Cortex XDR agent compatibility with third-party security products</td><td>Check the list of agent versions that Cortex XDR is compatible with. Contact Cortex XDR teams for insights on agent versions that aren't listed.</td><td><a href="/spaces/fZ8QSMnkjnXpuOeuRcam/pages/e3012204c745d058421bafad1d03b0292b8121a9">See topic</a></td></tr><tr><td></td><td>Deploy agent installation packages</td><td>Deploy agent installation packages using a third-party tool such as an SCCM, or manually on the endpoint.</td><td><a href="/pages/1yHLVVX6kHqmYGMHHBPD">See topic</a></td></tr><tr><td>Step 4: Configure and deploy Cortex XDR</td><td>Enable Cortex XDR Analytics</td><td>Set up monitoring for internal networks.</td><td><a href="/pages/bwEnsVPF8r18WBZBHtFp">See topic</a></td></tr><tr><td></td><td></td><td>Activate Cortex XDR - Analytics to enable the analytics engine to analyze your endpoint data to develop a baseline and raise Analytics and Analytics BIOC alerts when anomalies and malicious behaviors are detected.</td><td><a href="/pages/omF1Mnba4vONikwHYyxc">See topic</a></td></tr><tr><td></td><td></td><td><p></p><p>(Optional but highly recommended) Enable Identity Analytics to aggregate and display user profile details, activities, and alerts related to a user-based analytics type alert and Analytics BIOC rule during an investigation.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Prerequisite</strong></p><p>Cloud Identity Engine must be set up.</p></div></td><td><a href="/pages/omF1Mnba4vONikwHYyxc">See topic</a></td></tr><tr><td></td><td>(Optional but highly recommended) Install Broker VM</td><td>Broker VM is used to proxy all Cortex XDR/Traps agent communication to provide a more predictable flow of traffic to and from the cloud for heartbeats, agent updates, content updates and more. It is also used to serve as a Syslog collection point for all third-party log ingestion.</td><td><a href="/pages/fkNL3r14bCeZpXnygTKl">See topic</a></td></tr><tr><td></td><td>(Optional but highly recommended) Install Cloud Identity Engine</td><td>Cloud Identity Engine is a complimentary service that enables you to leverage Active Directory user, group, and computer details in Cortex XDR to provide context when you investigate alerts. You can also use Active Directory information in policy configuration and endpoint management of Traps agents.</td><td><a href="/pages/lsPebsLRqFZtgBLqlBH3">See topic</a></td></tr><tr><td>Step 5: Define data sources</td><td>Configure data ingestion</td><td><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Ingestion of logs and data requires a Cortex XDR Pro per GB license.</p></div><p>To provide you with a more complete and detailed picture of the activity involved in an incident, Cortex XDR can ingest data from a variety of Palo Alto Networks and third-party sources.</p><ul><li>Configure Palo Alto Networks integrations for streaming data and ingesting logs.</li><li>Configure external data ingestion to ingest data from third-party sources.</li></ul></td><td><a href="/pages/S71Pwrrm3Yduupt3c4Yr">See topic</a> <br><a href="/pages/UTkihviDKgoO8UKDJ08j">See topic</a></td></tr><tr><td>Step 6: Perform health checks</td><td>Prevention policies</td><td>Update your policies and profiles action mode to Block for each module.</td><td><a href="/pages/HTkklwjFY5IVLahgdWU6">See topic</a></td></tr><tr><td></td><td>Monitor operational status</td><td>Verify that Cortex XDR agents are protecting endpoints according to predefined security policies and profiles.</td><td><a href="/pages/L2osMIah9DmawbHlWHJE">See topic</a></td></tr><tr><td></td><td>Test sample malware</td><td>Use a malware PE, MacOSX, or APK test file, to test end-to-end WildFire sample processing.</td><td><a href="https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-api/get-wildfire-information-through-the-wildfire-api/get-a-malware-test-file-wildfire-api">See topic</a></td></tr><tr><td></td><td>Validate detectors for alerts and incidents</td><td><p></p><p>Check alerts and their associated alert sources.</p><p>Validate that all the configurations on the policy level and on the agent deployment level meet the requirements to generate alerts and incidents on Cortex XDR.</p><p>For example, check the following:</p><ul><li>Cortex XDR agent generates WildFire malware alerts.</li><li>NFGW alerts are listed by PAN NGFW.</li></ul></td><td></td></tr><tr><td></td><td>Validate log ingestion from external integrations</td><td><p>Verify what datasets are being created.</p><p>The <strong>Dataset Management</strong> page enables you to manage your datasets and understand your overall data storage duration for different retention periods and datasets based on your Hot and Cold Storage licenses, and retention add-ons to extend your storage. </p></td><td><a href="/pages/6l3WeEkLkIn8m5G868gd">See topic</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/cortex-xdr-onboarding-checklist.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
