> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md).

# Set up agent settings profiles

Use agent settings profiles to customize Cortex XDR agent settings for different platforms and groups of users.

The tasks below are organized according to the operating systems used by your organization's endpoints.

<details>

<summary>Windows</summary>

1. Add a new profile and define basic settings.
   1. Select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile or import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **Windows** platform, and **Agent Settings** as the profile type.
   3. Click **Next**.
   4. For **Profile Name**, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include a case identification number or a link to a help desk ticket.
2. For **Disk Quota**, configure the amount of disk space to allot for Cortex XDR agent logs. Specify a value in MB from 100 to 10,000 (default is 5,000).
3. Configure the **User Interface** options for Cortex XDR.

   By default, Cortex XDR uses the settings specified in the default agent settings profile and displays the default configuration in parentheses. When you select a setting other than the default, you override the default configuration for the profile.

   | Item                         | Options                                            | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
   | ---------------------------- | -------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Tray Icon                    | <ul><li>Visible (default)</li><li>Hidden</li></ul> | Choose whether you want the Cortex XDR agent icon to be **Visible** or **Hidden** in the notification area (system tray).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
   | XDR Agent Console Access     | <ul><li>Enabled</li><li>Disabled</li></ul>         | When enabled, allows access to Cortex XSIAM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
   | XDR Agent User Notifications | <ul><li>Enabled</li><li>Disabled</li></ul>         | <p>Enable this option to operate display notifications in the notifications area on the endpoint. When you enable notifications, you can use the default notification messages that are displayed for each option, or provide custom text for each notification type. You can also customize a notification footer. Options include:</p><ul><li><p>Device Control Violation Notifications</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Disabling Device Control Violation notifications is only supported on endpoints running Cortex XDR agent version 8.6 and above.</p></div></li><li>Live Terminal User Notifications: You can select to <strong>Request end-user permission</strong> to start the session. If the end user denies the request, you will not be able to initiate a Live Terminal session on the endpoint.</li><li>Live Terminal Active Session Indication: Enable this option to display a blinking light (<img src="/files/nCVkm3n2T3EPWrT45Tt8" alt="live-terminal-indication.png">) on the tray icon for the duration of the remote session to indicate to the end user that a Live Terminal session is in progress.</li><li>Persistent Isolation Notification</li><li>Endpoint Network Isolation Notification</li><li>Endpoint Network Un-Isolation Notification</li><li>Blocked Connectivity Notification</li><li>Exploit/Malware Events Set to Block</li><li>Restriction Events Set to Block</li><li>Restriction Events Set to Notify User</li><li>Notification Footer Text</li><li>USB Device Was Blocked</li><li>USB Disk Drive Was Allowed in Read-Only Mode</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You can enable the option to maintain a persistent notification regarding the disconnection of the endpoint from the network. The settings <strong>Persistent Isolation Notification</strong> and <strong>Blocked Connectivity Notification</strong> must be enabled. Until the threat on the endpoint has been removed, the endpoint remains disconnected from the network.</p></div> |
4. Customize **Agent Security** settings. By default, the Cortex XDR agent protects all agent components. However, you can configure protection with more granularity for Cortex XDR agent services, processes, files, registry values and tampering protection.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>In Traps 5.0.6 and later releases, when protection is enabled, access will be read-only. In earlier Traps releases, enabling protection disables all access to services, processes, files, and registry values.</p></div>

   1. Enable **XDR Agent Tampering Protection**.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you choose the <strong>Enable</strong> option, you must also enable <strong>XDR Agent Tampering Protection</strong> in the malware profile and set it to <strong>Block</strong>. Ensure that both profiles are assigned to the same endpoints.</p></div>
   2. You can customize the following options:

   | Item                | Options                                    | More details                                                                                                                                                                   |
   | ------------------- | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Service Protection  | <ul><li>Enabled</li><li>Disabled</li></ul> | Protects against stopping agent services. When this protection is enabled, agent services won't accept operating system stop requests.                                         |
   | Process Protection  | <ul><li>Enabled</li><li>Disabled</li></ul> | Protects against attempts to tamper with agent processes; injecting into them, terminating them, reading, or writing into their virtual memory.                                |
   | File Protection     | <ul><li>Enabled</li><li>Disabled</li></ul> | Protects against attempts to tamper with agent files; deleting, replacing, renaming, moving, or writing files/directories.                                                     |
   | Registry Protection | <ul><li>Enabled</li><li>Disabled</li></ul> | Protects against attempts to tamper with agent registry settings and agent policies, such as deleting, adding, and renaming registry keys or values which belong to the agent. |
   | Pipe Protection     | <ul><li>Enabled</li><li>Disabled</li></ul> | Protects against attempts to tamper with the agent's pipe-based inter-process communication (IPC) mechanism.                                                                   |
5. For **Uninstall Password**, configure an uninstall password.

   Define and confirm an encrypted password that the user must specify to uninstall the Cortex XDR agent. The uninstall password, also known as the supervisor password, is also used to protect against tampering attempts using Cytool commands. The password must contain:

   * 8 to 32 characters
   * At least one of each of the following:
     * Lower-case letter
     * Upper-case letter
     * Number
     * Special character: *!@#%*
6. Configure **Windows Security Center Integration**.

   The Windows Security Center is a reporting tool that monitors the system health and security state of Windows endpoints on Windows 7 and later releases.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>When you enable Cortex XDR agent registration with the Windows Security Center, Windows automatically shuts down Microsoft Defender on Windows-based workstation endpoints. If you still want to allow Microsoft Defender to run on a workstation endpoint where Cortex XSIAM is installed, you must use the <strong>Disable</strong> option. However, Palo Alto Networks does not recommend running Windows Defender and the Cortex XDR agent on the same endpoint, because this might cause performance and incompatibility issues with Global Protect and other applications.</p><p>On Windows-based servers, ensure that Windows Defender is disabled. This can be done using a Group Policy Object (GPO) or another group management tool of your choice.</p></div>

   | Item                                                       | Options                                                                                                                                                                                                                         | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
   | ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Windows Security Integration                               | Enabled                                                                                                                                                                                                                         | <p>The Cortex XDR agent registers with the Windows Security Center as an official Antivirus (AV) software product. As a result, Windows automatically shuts down Microsoft Defender on the endpoint, except for endpoints that are running Windows Server versions.</p><p>To avoid performance issues, Palo Alto Networks recommends that you disable or remove Windows Defender from Windows Server-based endpoints where the Cortex XDR agent is installed.</p> |
   | Enabled No Patches                                         | (Traps 5.0 release only) Select this option if you want to register the agent with the Windows Security Center, but prevent Windows from automatically installing Meltdown/Spectra vulnerability patches on the endpoint.       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
   | Disabled                                                   | The Cortex XDR agent does not register with the Windows Action Center. As a result, Windows Action Center might indicate that virus protection is off, depending on other security products that are installed on the endpoint. |                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
   | Report Agent Out of Date Status to Windows Security Center | <ul><li>Enabled</li><li>Disabled</li></ul>                                                                                                                                                                                      | <p>When enabled, the Cortex XDR agent will report every time that the connection to the server is lost for more than seven days. Each time that the agent reconnects, the count restarts.</p><p>This setting is available when <strong>Windows Security Integration</strong> is set to either <strong>Enabled</strong> or <strong>Enabled No Patches</strong>.</p>                                                                                                |
7. Configure **Issues Data** collection options.

   When the Cortex XDR agent generates issues for process-related activity on the endpoint, the agent collects the contents of memory and other data about the event, in what is known as an issue data dump file. You can configure the Cortex XDR agent to automatically upload issue data dump files to Cortex XDR.

   | Item                                      | Options                                             | More details                                                                                             |
   | ----------------------------------------- | --------------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
   | Issue Data Dump File Size                 | <ul><li>Small</li><li>Medium</li><li>Full</li></ul> | The **Full** option creates the largest and most complete set of information.                            |
   | Automatically Upload Issue Data Dump File | <ul><li>Enabled</li><li>Disabled</li></ul>          | During event investigation, if automatic upload was disabled, you can still manually retrieve this data. |
8. Enable **XDR Pro Endpoint Capabilities**, and then configure the capabilities required by your organization. The Cortex XDR Pro features are hidden until you enable this option.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Notice</h3><p>Requires a Cortex XDR Pro per Endpoint license. When you enable this feature, a Cortex XDR Pro per Endpoint license is consumed.</p></div>

   | Item                                       | Options                                                                                                                                                                                                                                                                                                                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Monitor and Collect Enhanced Endpoint Data | <ul><li>Enabled</li><li>Disabled</li></ul>                                                                                                                                                                                                                                                                                                 | By default, the Cortex XDR agent collects information about events that occur on the endpoint. If you enable Behavioral Threat Protection in a Malware security profile, the Cortex XDR agent also collects information about all active file, process, network, and registry activity on an endpoint. When you enable the Cortex XDR agent to monitor and collect enhanced endpoint data, Cortex XSIAM shares the detailed endpoint information with other Cortex apps. The information can help to provide the endpoint context when a security event occurs, so that you can gain insight into the overall event scope during an investigation. The event scope includes all activities that took place during an attack, the endpoints that were involved, and the damage caused. When disabled, the Cortex XDR agent will not share endpoint activity logs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   | Enable Host Insights Capabilities          | <ul><li>Enabled</li><li>Disabled</li></ul>                                                                                                                                                                                                                                                                                                 | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Requires Host Insights add-on.</p></div><p>When enabled, the various host insight capabilities can be configured.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
   | Endpoint Information Collection            | <ul><li>Enabled</li><li>Disabled</li></ul>                                                                                                                                                                                                                                                                                                 | When enabled, the Cortex XDR agent collects host inventory information such as users, groups, services, drivers, hardware, and network shares, as well as information about applications installed on the endpoint, including CVE and installed KBs for Vulnerability Assessment.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
   | File Search and Destroy Action Mode        | <ul><li>Enabled</li><li>Disabled</li></ul>                                                                                                                                                                                                                                                                                                 | <p>When enabled, the Cortex XDR agent collects detailed information about files on the endpoint to create a files inventory database. The agent locally monitors any actions performed on these files and updates the local files inventory database in real-time.</p><p>With this option you can also select the <strong>File Search and Destroy Monitored File Types</strong> where Cortex XSIAM monitors all the files on the endpoint, or only common file types. If you choose <strong>Common</strong> file types, Cortex XSIAM monitors the following file types:</p><p><code>bin, msi, doc, docx, docm, rtf, xls, xlsx, xlsm, pdf, ppt, pptx, pptm, ppsm, pps, ppsx, mpp, mppx, vsd, xsdx</code> and <code>wsf</code>.</p><p>A hash will also be computed for these file types: <code>zip, pe,</code> and <code>ole</code>.</p><p>File size is limited to 30 MB by default. Searches of files larger than 30 MB by hash are not supported.</p><p>Additionally, you can exclude files that exist under a specific local path on the endpoint from inclusion in the files database.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | Monitor and Collect Forensics Data         | <ul><li>Enabled</li><li>Disabled</li></ul>                                                                                                                                                                                                                                                                                                 | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Requires Forensics Add-on.</p></div><p>When enabled, the Cortex XDR agent collects detailed information about what happened on your endpoint, to create a forensics database. Define the following to enable collection and collection time intervals for the following entity types:</p><ul><li>Process Execution</li><li>File Access</li><li>Persistence</li><li>Command History</li><li>Network</li><li>Remote Access</li><li>Search Collections</li></ul><p>Data collected by the agent is displayed on the tenant's <strong>Forensics</strong> page.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
   | Distributed Network Scan                   | <ul><li>Enabled</li><li>Disabled</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>To enable access to these options, scroll down to <strong>Network Location Configuration</strong>, and set <strong>Action Mode</strong> to <strong>Enabled</strong>.</p></div> | <p>When enabled, the Cortex XDR agent scans your network using Ping or Nmap to provide updated identifiers of your unmanaged network assets. Ping scans return the IP address, MAC address, Hostname, and Platform, whereas Nmap will scan the most common ports for the IP address, Hostname, Platform, and OS version.</p><p>Ping is a lighter scan, that generates icmp requests to peers and does not use external tools. Nmap will make more noise on the network, but the resulting can be better, and also supports operating system detection.</p><p>Ping scans are performed in 30 minute intervals. Nmap scans are performed in 60 minute intervals.</p><p>The scan is performed according to the subnets detected in each network interface found on the endpoint, and up to a maximum of \~1K IP addresses calculated according to agent\_ip/22. For example, an agent with the IP address 121.121.121.121 will be assigned the scan range: 121.121.120.1 - 121.121.123.254 (1024 addresses). Each agent is assigned scan ranges randomly from all the scannable subnets, so the same agent can scan multiple subnets.</p><p>The following criteria affect the scan:</p><ul><li>There must be at least two endpoints detected in order to assign a scan.</li><li><strong>Network Location Configuration</strong> must be enabled.</li><li>Subnet masking settings and service name configurations influence the scan.</li><li>Excluded IP address ranges are not scanned.</li></ul><p>1. In the <strong>Network Location Configuration</strong> section, set the <strong>Action Mode</strong> to <strong>Enabled</strong>.</p><p>2. In the <strong>Distributed Network Scan</strong> section, set the <strong>Action Mode</strong> to <strong>Enabled</strong>.</p><p>3. In <strong>Scan Mode</strong>, select <strong>Nmap</strong> or <strong>Ping</strong>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When using Nmap, the Cortex XDR agent downloads an Nmap driver for the duration of the scan and removes the driver upon completion. If an Nmap scan is in process, Cortex XSIAM identifies the Nmap driver and places any additional scans in a queue.</p></div><p>The scan is performed according to the subnets detected in each network interface found on the endpoint.</p><p>4. If you want to exclude IP address ranges, select <strong>Excluded IP Address Ranges</strong>. The IP address ranges are populated from your network configurations.</p><p>5. If you selected Nmap, enable or disable <strong>OS Fingerprinting</strong> of the IP address.</p><p>Depending on the type of scan you defined, the agent Ping scan takes 30 minutes, and Nmap takes 60 minutes. Following each scan, Cortex XDR aggregates the IP addresses that were collected, and displays the results in the <strong>Asset Management</strong> table.</p> |
9. Configure **XDR Cloud** for hosts running on cloud platforms. By default (auto-detect mode), the agent detects whether an endpoint is a cloud-based (container) installation or a permanent installation, and uses license allocation accordingly.

   | Item      | Options                                       | More details                                                                                                                                        |
   | --------- | --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
   | XDR Cloud | <ul><li>Auto-detect</li><li>Enabled</li></ul> | If you set this to **Enabled** in the profile, any agent using this profile will be treated as if it is a cloud-based agent for licensing purposes. |
10. Configure **Response Actions** for specific applications or processes, using an Allow list.

    If you need to isolate an endpoint, but want to allow access for a specific application or process, add it to the **Network Isolation Allow List**. Keep the following considerations in mind:

    * When you add a specific application to your allow list from network isolation, the Cortex XDR agent continues to block some internal system processes. This is because some applications, for example, ping.exe, can use other processes to facilitate network communication. As a result, if the Cortex XDR agent continues to block an application you included in your allow list, you may need to perform additional network monitoring to determine the process that facilitates the communication, and then add that process to the allow list.

    * For VDI sessions, use of the network isolation response action can disrupt communication with the VDI host management system, thereby stopping access to the VDI session. Therefore, before using the response action, you must add the VDI processes and corresponding IP addresses to your allow list.

    1. Click **Add** to add an entry to the allow list.
    2. Specify the Process Path that you want to allow, and the IPv4 or IPv6 address of the endpoint. Use the **`*`** wildcard on either side to match any process or IP address. For example, specify **`*`** as the process path and an IP address to allow any process to run on the isolated endpoint with that IP address. Conversely, specify **`*`** as the IP address and a specific process path to allow the process to run on any isolated endpoint that receives this profile.
    3. Click the check mark.
11. Configure **Backup Management** to backup endpoint data.

    | Item                  | Options                                    | More details                                                                                                                                                                                                     |
    | --------------------- | ------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Shadowcopy Activation | <ul><li>Enabled</li><li>Disabled</li></ul> | When enabled, the Cortex XDR agent automatically turns on the system protection of the endpoint. This ensures that the data is backed up and may be recovered in cases of any security breaches or loss of data. |
    | Disk Space Limitation | Disk space in MB                           | Limits the amount of disk space in MB that can be used for endpoint data backup.                                                                                                                                 |
12. Configure the method used to update content on your endpoints.

    <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h3>Warning</h3><p>If you disable or delay automatic-content updates provided by Palo Alto Networks, it may affect the security level in your organization.</p></div>

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><ul><li>If you disable content updates for a newly installed agent, the agent retrieves the content for the first time from Cortex XSIAM, and then disables content updates on the endpoint.</li><li>When you add a Cortex XDR agent to an endpoint group with a disabled content auto-upgrades policy, the policy is applied to the added agent as well.</li></ul></div>

    | Item                | Options                                              | More details                                                                                                                                                                                                                                                                                                                                                               |
    | ------------------- | ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Content Auto-update | <ul><li>Enabled</li><li>Disabled (default)</li></ul> | <p>By default, the Cortex XDR agent always retrieves the most updated content and deploys it on the endpoint, to ensure that it is always protected with the latest security measures.</p><p>If you disable content updates, the agent stops retrieving them from the Cortex XSIAM tenant, and keeps working with the current content on the endpoint.</p>                 |
    | Content Staging     | <ul><li>Enabled</li><li>Disabled (default)</li></ul> | Enable users to deploy agent staging content on selected test environments. Staging content is released before production content, allowing for early evaluation of the latest content update.                                                                                                                                                                             |
    | Content Rollout     | <ul><li>Immediately</li><li>Delayed</li></ul>        | The Cortex XDR agent can retrieve content updates immediately as they are available, or after a pre-configured delay period. When you delay content updates, the Cortex XDR agent will retrieve the content according to the configured delay. For example, if you configure a delay period of two days, the agent will not use any content released in the last 48 hours. |
13. Agent Auto-Upgrade is disabled by default. Before enabling Auto-Update for Cortex XDR agents, make sure to consult with all relevant stakeholders in your organization.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Automatic upgrades are not supported with non-persistent VDI and temporary sessions.</p></div>

    | Item                    | Options                                                                                                                                                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
    | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
    | Agent Auto-Upgrade      | <ul><li>Enabled</li><li>Disabled (Default)</li></ul>                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
    | Automatic Upgrade Scope | <ul><li>Latest agent release</li><li>One release before the latest one</li><li>Only maintenance releases</li><li>Only maintenance releases in a specific version</li></ul> | <p>For <strong>One release before the latest one</strong>, Cortex XSIAM upgrades the agent to the previous release before the latest, including maintenance releases. Major releases are numbered X.X, such as release 8.0, or 8.2. Maintenance releases are numbered X.X.X, such as release 8.2.2.</p><p>For <strong>Only maintenance releases in a specific version</strong>, select the required release version.</p>                                                                               |
    | Upgrade Rollout         | <ul><li>Immediate</li><li>Delayed</li></ul>                                                                                                                                | <p>For <strong>Delayed</strong>, set the delay period (number of days) to wait after the version release before upgrading endpoints. Choose a value between 7 and 45.</p><p>To control the number of parallel upgrades in your network, configure Global Agent Settings.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The delay timer starts from the date of the target agent version's availability in the tenant.</p></div> |
    | Scheduling              | <ul><li>Hours</li><li>Days of the week</li></ul>                                                                                                                           | Schedule the upgrade task for a specific time and days of the week.                                                                                                                                                                                                                                                                                                                                                                                                                                    |
14. Specify a **Download Source**, or multiple sources, from which Cortex XDR agent retrieves agent and content updates. The options provided help you to reduce external network bandwidth loads during updates. When all sources are selected, the download sources are prioritized in the following order: P2P > Broker VM > Cortex XSIAM Server.

    To ensure your agents remain protected, the **Cortex Server** download source is always enabled to allow all Cortex XDR agents in your network to retrieve the content directly from the Cortex XSIAM server on their following heartbeat.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Limitations in the content download process:</p><ul><li>When you install the Cortex XDR agent, the agent retrieves the latest content update version available. A freshly installed agent can take between five to ten minutes (depending on your network and content update settings) to retrieve the content for the first time. During this time, your endpoint is not protected.</li><li>When you upgrade a Cortex XDR agent to a newer Cortex XDR agent version, if the new agent cannot use the content version running on the endpoint, the new content update will start within one minute in P2P, and within five minutes from Cortex XSIAM.</li></ul></div>

    | Item       | Options                                                                                                                                             | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
    | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Select all | <ul><li>Selected</li><li>Clear</li></ul>                                                                                                            | When selected, all download source options are enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
    | P2P        | <ul><li>33221 (default port)</li><li>custom port</li></ul>                                                                                          | <p>Cortex XSIAM deploys serverless peer-to-peer distribution to Cortex XDR agents in your LAN network by default. Within the six hour randomization window during which the Cortex XDR agent attempts to retrieve the new version, it will broadcast its peer agents on the same subnet twice: once within the first hour, and once again during the following five hours. If the agent did not retrieve the files from other agents in both queries, it will proceed to the next download source defined in your profile.</p><p>To enable P2P, you must enable UDP and TCP over the port specified for <strong>P2P Port</strong>. By default, Cortex XSIAM uses port 33221. You can change the port number, if required by your organization.</p>                                                                                                                                                  |
    | Broker VM  | <ul><li>Select all</li><li>Brokers</li><li>Clusters</li></ul><p>(only Broker VMs that are connected and configured for caching can be selected)</p> | <p>(Requires Broker VM 12.0 and later)</p><p>If you have a Palo Alto Networks Broker VM in your network, you can leverage the Local Agent Settings applet to cache release upgrades and content updates. When the Broker VM is enabled and configured appropriately (refer to <a href="/pages/83G95qAez8GnRwIsDHz6">Activate Local Agent Settings</a>) , it retrieves the latest installers and content files every 15 minutes, downloading them only if they are not already stored locally. The Broker VM stores this content for 7 days and agent installers for up to 30 days from the agent's last request.</p><p>If the files are not available on the Broker VM at the time of the request, the agent proceeds to download the files directly from the Cortex XSIAM server.</p><p>When you select multiple Broker VMs, the agent chooses a Broker VM randomly for each download request.</p> |
15. Configure **Network Location Configuration** for your Cortex XDR agents. If you configure host firewall rules in your network, you must:

    * Enable **Network Location Configuration Action Mode**, so that Cortex XDR can test the network location of your device.
    * Configure your network's DNS name and its internal IP address.

    If the Cortex XDR agent detects a network change on the endpoint, the agent triggers the device location test and re-calculates the policy according to the new location.

    | Item        | Options                                    | More details                                                                                                                                                                                                                                                                                                                                     |
    | ----------- | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
    | Action Mode | <ul><li>Enabled</li><li>Disabled</li></ul> | When **Enabled**, a domain controller (DC) test checks whether the device is connected to the internal network or not. If the device is connected to the internal network, it is determined to be in the organization. If the DC test fails or returns an external domain, Cortex XSIAM performs a DNS connectivity test.                        |
    | DNS Name    | Your network's DNS name                    | The Cortex XDR agent tests network location by submitting a Domain Name Server (DNS) name that is known only to the internal network. If the DNS returns the pre-configured internal IP address, the device is determined to be within the organization. If the DNS IP address cannot be resolved, the device is deemed to be located elsewhere. |
    | IP Address  | Your network's DNS internal IP address     | Enter the internal DNS IP address to be used by the DNS test.                                                                                                                                                                                                                                                                                    |
16. Define **Agent Proxy Settings**.

    Select whether to **Enable** or **Disable** **Direct Server Access** for the agent when connected using a proxy.
17. Configure **Agent Certificates**. For improved security, enforce the use of root CA that is provided by Palo Alto Networks rather than on the local machine.

    | Item                    | Options                                                              | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
    | ----------------------- | -------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Certificate Enforcement | <ul><li>Enabled</li><li>Disabled</li><li>Disabled (Notify)</li></ul> | <p>When enabled, certificate enforcement is enabled.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If the Cortex XDR agent is initially unable to communicate without the local store, enforcement is not enabled and the agent will show as partially protected.</p></div><p>When set to <strong>Disabled (Notify)</strong>, Cortex XDR agents with this policy will trigger a banner in the server to notify customers about potential risk, and will direct them to change the certificate and the setting. The <strong>Last Certificate Enforcement Fallback</strong> column of the <strong>All Endpoints</strong> table is updated, and management audit logs related to the local store fallback are received by the server.</p><p>When set to <strong>Disabled</strong>, Cortex XDR agents with this policy will trigger a banner in the server to notify customers about potential risk, and will direct them to change the certificate and the setting. The <strong>Last Certificate Enforcement Fallback</strong> column of the <strong>All Endpoints</strong> table is not updated, and no management audit logs related to the local store fallback are received by the server.</p> |
18. Configure **IT Metrics**, to define setting for collecting IT metrics on the endpoint.

    | Item            | Options                                    | More details                                                                                                   |
    | --------------- | ------------------------------------------ | -------------------------------------------------------------------------------------------------------------- |
    | Collect IT Data | <ul><li>Enabled</li><li>Disabled</li></ul> | When enabled, the Cortex XDR agent collects IT data that provides visibility into IT performance on the agent. |
19. Configure **Data Generation Providers**, to define data generation provider types from which endpoints collect data. By default, all data generation provider types are enabled. We do not recommend disabling data generation providers unless really necessary, because it has an impact on the security coverage of your endpoints. Consult with Customer Support before you disable any of these options.

    | Item                                       | Options                                                                                                                                                                                                 | More details                                                                                                                                                                    |
    | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Disable Specific Data Generation Providers | <ul><li>Data Generation Module</li><li>Event Log Provider</li><li>System Call Provider</li><li>Remote Procedure Call Provider</li><li>.NET Provider</li><li>Device Driver IO Control Provider</li></ul> | To disable data collection from specific data generation provider types, select one or more options. If you select **Data Generation Module**, all provider types are disabled. |
20. Configure **Agentic Endpoint Security (AES)** to secure the non-binary endpoint attack surface, including AI agents, AI coding tools, MCP servers, IDE extensions, browser plugins, and code packages such as npm and pip. The Cortex XDR agent discovers agentic software running on the endpoint and remediates risks based on your AES policy. To learn more, or for information about AES policies, discovered agentic software, and remediating findings, see [Agentic Endpoint Security with Koi](https://docs.koi.ai/).

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>License Type</h3><p>Requires the Agentic Endpoint Security (AES) add-on license. AES is supported on Platform XDR and XSIAM tenants only (legacy tenants are not supported).</p></div>

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You configure this setting per platform. AES is supported on Windows and Mac endpoints only.</p></div>

    | Item         | Options                                            | More Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
    | ------------ | -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | AES run-mode | <p>Disabled (default)<br>AES only<br>XDR + AES</p> | <p>Configure the integration run-mode for the AES module in Cortex XDR. The run-mode determines how the Cortex XDR agent operates on the endpoint. Changes take effect on each endpoint at its next check-in.<br><br><strong>Disabled</strong> (default). AES is not active on the endpoint. If you change the run-mode from an active state (AES only or XDR + AES) to Disabled, the Cortex XDR agent runs the AES uninstall scripts on next check-in to remove AES-related persistent data and local artifacts from the endpoint. AES data already collected and sent to your AES tenant is retained on the AES side and is not affected by the endpoint cleanup.<br><br><strong>AES only</strong>. The endpoint runs a lightweight agent configuration that provides only AES functionality plus agent management functions such as heartbeats, policy and content updates, and upgrades. No event collection or prevention modules run in this mode. The tray icon and Check-in option remain available, but the Cortex XDR agent Console UI is disabled on AES-only endpoints. Agent version downgrade is not supported from AES-only mode (mode changes back to XDR + AES or Disabled are supported).<br><br><strong>XDR + AES</strong>. The endpoint runs the full Cortex XDR agent with all XDR protection modules, plus the AES module for agentic endpoint security. Cortex XDR anti-tampering protection covers the AES scripts along with the rest of the agent. Use this run-mode on endpoints that need both endpoint protection and AES.<br><br>You can switch between the three run-modes at any time by re-editing the Agent Settings profile and re-applying the policy. Switching from AES only to XDR + AES or from XDR + AES to AES only preserves AES data on the endpoint; only switching to Disabled (or uninstalling the Cortex XDR agent) removes it.<br><br>To restore the default value, select Use Default (Disabled).</p> |
21. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>

<details>

<summary>macOS</summary>

1. Add a new profile and define basic settings.
   1. Select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile or import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **macOS** platform, and **Agent Settings** as the profile type.
   3. Click **Next**.
   4. Enter a unique **Profile Name** for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include a case identification number or a link to a help desk ticket.
2. For **Disk Quota**, configure the amount of disk space to allot for Cortex XDR agent logs. Specify a value in MB from 100 to 10,000 (default is 5,000).
3. Configure the **User Interface** options for Cortex XDR.

   By default, Cortex XDR uses the settings specified in the default agent settings profile and displays the default configuration in parentheses. When you select a setting other than the default, you override the default configuration for the profile.

   | Item                         | Options                                            | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   | ---------------------------- | -------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Tray Icon                    | <ul><li>Visible (default)</li><li>Hidden</li></ul> | Choose whether you want the Cortex XDR agent icon to be **Visible** or **Hidden** in the notification area (system tray).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
   | XDR Agent Console Access     | <ul><li>Enabled</li><li>Disabled</li></ul>         | When enabled, allows access to Cortex XSIAM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   | XDR Agent User Notifications | <ul><li>Enabled</li><li>Disabled</li></ul>         | <p>Enable this option to operate display notifications in the notifications area on the endpoint. When you enable notifications, you can use the default notification messages that are displayed for each option, or provide custom text for each notification type. You can also customize a notification footer. Options include:</p><ul><li><p>Device Control Violation Notifications</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Disabling Device Control Violation notifications is only supported on endpoints running Cortex XDR agent version 8.6 and above.</p></div></li><li><p>Live Terminal User Notifications: You can select to <strong>Request end-user permission</strong> to start the session. If the end user denies the request, you will not be able to initiate a Live Terminal session on the endpoint.</p><p>You can select to <strong>Request end-user permission</strong> to start the session. If the end user denies the request, you will not be able to initiate a Live Terminal session on the endpoint.</p></li><li>Live Terminal Active Session Indication: Enable this option to display a blinking light (<img src="/files/nCVkm3n2T3EPWrT45Tt8" alt="live-terminal-indication.png">) on the status bar for the duration of the remote session to indicate to the end user that a Live Terminal session is in progress.</li><li>Persistent Isolation Notification</li><li>Endpoint Network Isolation Notification</li><li>Endpoint Network Un-Isolation Notification</li><li>Blocked Connectivity Notification</li><li>Exploit/Malware Events Set to Block</li><li>Restriction Events Set to Block</li><li>Restriction Events Set to Notify User</li><li>Notification Footer Text</li><li>USB Device Was Blocked</li><li><p>USB Disk Drive Was Allowed in Read-Only Mode</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You can enable the option to maintain a persistent notification regarding the disconnection of the endpoint from the network. The settings <strong>Persistent Isolation Notification</strong> and <strong>Blocked Connectivity Notification</strong> must be enabled. Until the threat on the endpoint has been removed, the endpoint remains disconnected from the network.</p></div></li></ul> |
4. For **Agent Security**, configure **XDR Agent Tampering Protection** (default is **Enabled**). By default, the Cortex XDR agent protects all agent components.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you choose the <strong>Enabled</strong> option, you must also set <strong>Anti Tampering Protection</strong> in the malware security profile to <strong>Block</strong>, and ensure that both profiles are assigned to the same endpoints.</p></div>

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>When protection is enabled, access to services, processes, files, and registry values will be read-only.</p></div>
5. For **Uninstall Password**, configure an uninstall password.

   Define and confirm an encrypted password that the user must specify to uninstall the Cortex XDR agent. The uninstall password, also known as the supervisor password, is also used to protect against tampering attempts via Cytool commands. The password must contain:

   * 8 to 32 characters
   * At least one of each of the following:
     * Lower-case letter
     * Upper-case letter
     * Number
     * Special character: *!@#%*
6. Configure **Issues Data** collection options.

   When the Cortex XDR agent generates issues for process-related activity on the endpoint, the agent collects the contents of memory and other data about the event, in what is known as an issue data dump file. You can configure the Cortex XDR agent to automatically upload issue data dump files to Cortex XDR.

   | Item                                      | Options                                             | More details                                                                                             |
   | ----------------------------------------- | --------------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
   | Issue Data Dump File Size                 | <ul><li>Small</li><li>Medium</li><li>Full</li></ul> | The **Full** option creates the largest and most complete set of information.                            |
   | Automatically Upload Issue Data Dump File | <ul><li>Enabled</li><li>Disabled</li></ul>          | During event investigation, if automatic upload was disabled, you can still manually retrieve this data. |
7. <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Notice</h3><p>Requires a Cortex XDR Pro per Endpoint license. When you enable this feature, a Cortex XDR Pro per Endpoint license is consumed.</p></div>

   Enable **XDR Pro Endpoint Capabilities**, and then configure the capabilities required by your organization. The Cortex XDR Pro features are hidden until you enable this option.

   | Item                                       | Options                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | ------------------------------------------ | ------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Monitor and Collect Enhanced Endpoint Data | <ul><li>Enabled</li><li>Disabled</li></ul> | By default, the Cortex XDR agent collects information about events that occur on the endpoint. If you enable Behavioral Threat Protection in a Malware security profile, the Cortex XDR agent also collects information about all active file, process, network, and registry activity on an endpoint. When you enable the Cortex XDR agent to monitor and collect enhanced endpoint data, Cortex XSIAM shares the detailed endpoint information with other Cortex apps. The information can help to provide the endpoint context when a security event occurs, so that you can gain insight into the overall event scope during an investigation. The event scope includes all activities that took place during an attack, the endpoints that were involved, and the damage caused. When disabled, the Cortex XDR agent will not share endpoint activity logs.                                                                                                                                                        |
   | Enable Host Insights Capabilities          | <ul><li>Enabled</li><li>Disabled</li></ul> | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Requires Host Insights add-on.</p></div><p>When enabled, the various host insight capabilities can be configured.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
   | Endpoint Information Collection            | <ul><li>Enabled</li><li>Disabled</li></ul> | When enabled, the Cortex XDR agent collects Host Inventory information such as users, groups, services, drivers, hardware, and network shares, as well as information about applications installed on the endpoint, including CVE and installed KBs for Vulnerability Assessment.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
   | File Search and Destroy Action Mode        | <ul><li>Enabled</li><li>Disabled</li></ul> | <p>When enabled, the Cortex XDR agent collects detailed information about files on the endpoint to create a files inventory database. The agent locally monitors any actions performed on these files and updates the local files inventory database in real-time.</p><p>With this option you can also select the <strong>File Search and Destroy Monitored File Types</strong> where Cortex XSIAM monitors all the files on the endpoint, or only common file types. If you choose <strong>Common</strong> file types, Cortex XSIAM monitors the following file types:</p><p><code>acm, apk, ax, bat, bin, bundle, csv, dll, dmg, doc, docm, docx, dylib, efi, hta, jar, js, jse, jsf, lua, mpp, mppx, mui, o, ocx, pdf, pkg, pl, plx, pps, ppsm, ppsx, ppt, pptm, pptx, py, pyc, pyo, rb, rtf, scr, sh, vds, vsd, wsf, xls, xlsm, xlsx, xsdx,</code> and <code>zip</code>.</p><p>Additionally, you can exclude files that exist under a specific local path on the endpoint from inclusion in the files database.</p> |
   | Monitor and Collect Forensics Data         | <ul><li>Enabled</li><li>Disabled</li></ul> | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Requires Forensics Add-on.</p></div><p>When enabled, the Cortex XDR agent collects detailed information about what happened on your endpoint, to create a forensics database. Define the following to enable collection and collection time intervals for the following entity types:</p><ul><li>Process Execution</li><li>File Access</li><li>Persistence</li><li>Command History</li><li>Network</li><li>Search Collections</li></ul><p>Data collected by the agent is displayed on the tenant's <strong>Forensics</strong> page.</p>                                                                                                                                                                                                                                                                                                                                                             |
8. Configure **XDR Cloud** for hosts running on cloud platforms. By default (auto-detect mode), the agent detects whether an endpoint is a cloud-based (container) installation or a permanent installation, and uses license allocation accordingly.

   | Item      | Options                                       | More details                                                                                                                                        |
   | --------- | --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
   | XDR Cloud | <ul><li>Auto-detect</li><li>Enabled</li></ul> | If you set this to **Enabled** in the profile, any agent using this profile will be treated as if it is a cloud-based agent for licensing purposes. |
9. Configure **Response Actions** for specific applications or processes, using an Allow list.

   If you need to isolate an endpoint, but want to allow access for a specific application or process, add it to the **Network Isolation Allow List**. Keep the following considerations in mind:

   When you add a specific application to your allow list from network isolation, the Cortex XDR agent continues to block some internal system processes. This is because some applications, for example, ping.exe, can use other processes to facilitate network communication. As a result, if the Cortex XDR agent continues to block an application you included in your allow list, you may need to perform additional network monitoring to determine the process that facilitates the communication, and then add that process to the allow list.

   1. Click **Add** to add an entry to the allow list.
   2. Specify the Process Path that you want to allow, and the IPv4 or IPv6 address of the endpoint. Use the **`*`** wildcard on either side to match any process or IP address. For example, specify **`*`** as the process path and an IP address to allow any process to run on the isolated endpoint with that IP address. Conversely, specify **`*`** as the IP address and a specific process path to allow the process to run on any isolated endpoint that receives this profile.
   3. Click the check mark.
10. Configure **Backup Management**.

    | Item                    | Options                                    | More details                                                                                                                                                                                                   |
    | ----------------------- | ------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Time Machine Activation | <ul><li>Enabled</li><li>Disabled</li></ul> | When enabled, this option automatically turns on the **Time Machine** setting of the endpoint. This ensures that the data is backed up and may be recovered in cases of any security breaches or loss of data. |
11. Configure the method used to update content on your endpoints.

    <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h3>Warning</h3><p>If you disable or delay automatic-content updates provided by Palo Alto Networks, it may affect the security level in your organization.</p></div>

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you disable content updates for a newly installed agent, the agent retrieves the content for the first time from Cortex XSIAM, and then disables content updates on the endpoint.</p></div>

    | Item                | Options                                              | More details                                                                                                                                                                                                                                                                                                                                                               |
    | ------------------- | ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Content Auto-update | <ul><li>Enabled (default)</li><li>Disabled</li></ul> | <p>By default, the Cortex XDR agent always retrieves the most updated content and deploys it on the endpoint, to ensure that it is always protected with the latest security measures.</p><p>If you disable content updates, the agent stops retrieving them from the Cortex XSIAM tenant, and keeps working with the current content on the endpoint.</p>                 |
    | Staging Content     | <ul><li>Enabled</li><li>Disabled (default)</li></ul> | Enable users to deploy agent staging content on selected test environments. Staging content is released before production content, allowing for early evaluation of the latest content update.                                                                                                                                                                             |
    | Content Rollout     | <ul><li>Immediately</li><li>Delayed</li></ul>        | The Cortex XDR agent can retrieve content updates immediately as they are available, or after a pre-configured delay period. When you delay content updates, the Cortex XDR agent will retrieve the content according to the configured delay. For example, if you configure a delay period of two days, the agent will not use any content released in the last 48 hours. |
12. Agent Auto-Upgrade is disabled by default. Before enabling Auto-Update for Cortex XDR agents, make sure to consult with all relevant stakeholders in your organization.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Automatic upgrades are not supported with non-persistent VDI and temporary sessions.</p><p>When a Cortex XDR agent is added to an endpoint group, it inherits the group's policy, including the disabled content auto-upgrades setting.</p></div>

    | Item                    | Options                                                                                                                                                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
    | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Agent Auto-Upgrade      | <ul><li>Enabled</li><li>Disabled (Default)</li></ul>                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
    | Automatic Upgrade Scope | <ul><li>Latest agent release</li><li>One release before the latest one</li><li>Only maintenance releases</li><li>Only maintenance releases in a specific version</li></ul> | <p>For <strong>One release before the latest one</strong>, Cortex XSIAM upgrades the agent to the previous release before the latest, including maintenance releases. Major releases are numbered X.X, such as release 8.0, or 8.2. Maintenance releases are numbered X.X.X, such as release 8.2.2.</p><p>For <strong>Only maintenance releases in a specific version</strong>, select the required release version.</p>                                                                                                                |
    | Upgrade Rollout         | <ul><li>Immediate</li><li>Delayed</li></ul>                                                                                                                                | <p>For <strong>Delayed</strong>, set the delay period (number of days) to wait after the version release before upgrading endpoints. Choose a value between 7 and 45.</p><p>To control the agent auto upgrade scheduler and number of parallel upgrades in your network, configure Global Agent Settings.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The delay timer starts from the date of the target agent version's availability in the tenant.</p></div> |
    | Scheduling              | <ul><li>Hours</li><li>Days</li><li>Weeks</li></ul>                                                                                                                         | Schedule the upgrade task for a specific time and days of the week.                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
13.
14. Specify a **Download Source**, or multiple sources, from which Cortex XDR agent retrieves agent and content updates. The options provided help you to reduce external network bandwidth loads during updates. When all sources are selected, the download sources are prioritized in the following order: P2P > Broker VM > Cortex XSIAM Server.

    To ensure your agents remain protected, the **Cortex Server** download source is always enabled to allow all Cortex XDR agents in your network to retrieve the content directly from the Cortex XSIAM server on their following heartbeat.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Limitations in the content download process:</p><ul><li>When you install the Cortex XDR agent, the agent retrieves the latest content update version available. A freshly installed agent can take between five to ten minutes (depending on your network and content update settings) to retrieve the content for the first time. During this time, your endpoint is not protected.</li><li>When you upgrade a Cortex XDR agent to a newer Cortex XDR agent version, if the new agent cannot use the content version running on the endpoint, the new content update will start within one minute in P2P, and within five minutes from Cortex XSIAM.</li></ul></div>

    | Item       | Options                                                                                                                                             | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Select all | <ul><li>Selected</li><li>Clear</li></ul>                                                                                                            | When selected, all download source options are enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
    | P2P        | <ul><li>33221 (default port)</li><li>custom port</li></ul>                                                                                          | <p>Cortex XSIAM deploys serverless peer-to-peer distribution to Cortex XDR agents in your LAN network by default. Within the six hour randomization window during which the Cortex XDR agent attempts to retrieve the new version, it will broadcast its peer agents on the same subnet twice: once within the first hour, and once again during the following five hours. If the agent did not retrieve the files from other agents in both queries, it will proceed to the next download source defined in your profile.</p><p>To enable P2P, you must enable UDP and TCP over the port specified for <strong>P2P Port</strong>. By default, Cortex XSIAM uses port 33221. You can change the port number, if required by your organization.</p>               |
    | Broker VM  | <ul><li>Select all</li><li>Brokers</li><li>Clusters</li></ul><p>(only Broker VMs that are connected and configured for caching can be selected)</p> | <p>(Requires Broker VM 12.0 and later)</p><p>If you have a Palo Alto Networks Broker VM in your network, you can leverage the Local Agent Settings applet to cache release upgrades and content updates. When the Broker VM is enabled and configured appropriately (refer to Activate the Local Agent Settings) , it retrieves the latest installers and content every 6 hours. The Broker VM stores them for a 24-hour retention period since an agent last asked for them.</p><p>If the files are not available on the Broker VM at the time of the request, the agent proceeds to download the files directly from the Cortex XSIAM server.</p><p>When you select multiple Broker VMs, the agent chooses a Broker VM randomly for each download request.</p> |
15. Configure **Network Location Configuration** for your Cortex XDR agents. If you configure host firewall rules in your network, you must:

    * Enable **Network Location Configuration Action Mode**, so that Cortex XSIAM can test the network location of your device.
    * Configure your network's DNS name and its internal IP address.

    If the Cortex XDR agent detects a network change on the endpoint, the agent triggers the device location test and re-calculates the policy according to the new location.

    | Item        | Options                                    | More details                                                                                                                                                                                                                                                                                                                                     |
    | ----------- | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
    | Action Mode | <ul><li>Enabled</li><li>Disabled</li></ul> | When **Enabled**, a domain controller (DC) test checks whether the device is connected to the internal network or not. If the device is connected to the internal network, it is determined to be in the organization. If the DC test fails or returns an external domain, Cortex XSIAM performs a DNS connectivity test.                        |
    | DNS Name    | Your network's DNS name                    | The Cortex XDR agent tests network location by submitting a Domain Name Server (DNS) name that is known only to the internal network. If the DNS returns the pre-configured internal IP address, the device is determined to be within the organization. If the DNS IP address cannot be resolved, the device is deemed to be located elsewhere. |
    | IP Address  | Your network's DNS internal IP address     | Enter the internal DNS IP address to be used by the DNS test.                                                                                                                                                                                                                                                                                    |
16. Define **Agent Proxy Settings**.

    Select whether to **Enable** or **Disable** **Direct Server Access** for the agent when connected using a proxy.
17. Configure **Agent Certificates**. For improved security, enforce the use of root CA that is provided by Palo Alto Networks rather than on the local machine.

    | Item                    | Options                                                              | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
    | ----------------------- | -------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Certificate Enforcement | <ul><li>Enabled</li><li>Disabled</li><li>Disabled (Notify)</li></ul> | <p>When enabled, certificate enforcement is enabled.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If the Cortex XDR agent is initially unable to communicate without the local store, enforcement is not enabled and the agent will show as partially protected.</p></div><p>When set to <strong>Disabled (Notify)</strong>, Cortex XDR agents with this policy will trigger a banner in the server to notify customers about potential risk, and will direct them to change the certificate and the setting. The <strong>Last Certificate Enforcement Fallback</strong> column of the <strong>All Endpoints</strong> table is updated, and management audit logs related to the local store fallback are received by the server.</p><p>When set to <strong>Disabled</strong>, Cortex XDR agents with this policy will trigger a banner in the server to notify customers about potential risk, and will direct them to change the certificate and the setting. The <strong>Last Certificate Enforcement Fallback</strong> column of the <strong>All Endpoints</strong> table is not updated, and no management audit logs related to the local store fallback are received by the server.</p> |
18. Configure **Agentic Endpoint Security (AES)** to secure the non-binary endpoint attack surface, including AI agents, AI coding tools, MCP servers, IDE extensions, browser plugins, and code packages such as npm and pip. The Cortex XDR agent discovers agentic software running on the endpoint and remediates risks based on your AES policy. To learn more, or for information about AES policies, discovered agentic software, and remediating findings, see [Agentic Endpoint Security with Koi](https://docs.koi.ai/).

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>License Type</h3><p>Requires the Agentic Endpoint Security (AES) add-on license. AES is supported on Platform XDR and XSIAM tenants only (legacy tenants are not supported).</p></div>

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>You configure this setting per platform. AES is supported on Windows and Mac endpoints only.</p></div>

    | Item         | Options                                            | More Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
    | ------------ | -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | AES run-mode | <p>Disabled (default)<br>AES only<br>XDR + AES</p> | <p>Configure the integration run-mode for the AES module in Cortex XDR. The run-mode determines how the Cortex XDR agent operates on the endpoint. Changes take effect on each endpoint at its next check-in.<br><br><strong>Disabled</strong> (default). AES is not active on the endpoint. If you change the run-mode from an active state (AES only or XDR + AES) to Disabled, the Cortex XDR agent runs the AES uninstall scripts on next check-in to remove AES-related persistent data and local artifacts from the endpoint. AES data already collected and sent to your AES tenant is retained on the AES side and is not affected by the endpoint cleanup.<br><br><strong>AES only</strong>. The endpoint runs a lightweight agent configuration that provides only AES functionality plus agent management functions such as heartbeats, policy and content updates, and upgrades. No event collection or prevention modules run in this mode. The tray icon and Check-in option remain available, but the Cortex XDR agent Console UI is disabled on AES-only endpoints. Agent version downgrade is not supported from AES-only mode (mode changes back to XDR + AES or Disabled are supported).<br><br><strong>XDR + AES</strong>. The endpoint runs the full Cortex XDR agent with all XDR protection modules, plus the AES module for agentic endpoint security. Cortex XDR anti-tampering protection covers the AES scripts along with the rest of the agent. Use this run-mode on endpoints that need both endpoint protection and AES.<br><br>You can switch between the three run-modes at any time by re-editing the Agent Settings profile and re-applying the policy. Switching from AES only to XDR + AES or from XDR + AES to AES only preserves AES data on the endpoint; only switching to Disabled (or uninstalling the Cortex XDR agent) removes it.<br><br>To restore the default value, select Use Default (Disabled).</p> |
19. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>

<details>

<summary>Linux</summary>

1. Add a new profile and define basic settings.
   1. Select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile or import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **Linux** platform, and **Agent Settings** as the profile type.
   3. Click **Next**.
   4. Enter a unique **Profile Name** for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include a case identification number or a link to a help desk ticket.
2. For **Disk Quota**, configure the amount of disk space to allot for Cortex XDR agent logs. Specify a value in MB from 100 to 10,000 (default is 5,000).
3. Configure **Issues Data** collection options.

   When the Cortex XDR agent generates issues for process-related activity on the endpoint, the agent collects the contents of memory and other data about the event, in what is known as an issue data dump file. You can configure the Cortex XDR agent to automatically upload issue data dump files to Cortex XDR.

   | Item                                      | Options                                             | More details                                                                                             |
   | ----------------------------------------- | --------------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
   | Issue Data Dump File Size                 | <ul><li>Small</li><li>Medium</li><li>Full</li></ul> | The **Full** option creates the largest and most complete set of information.                            |
   | Automatically Upload Issue Data Dump File | <ul><li>Enabled</li><li>Disabled</li></ul>          | During event investigation, if automatic upload was disabled, you can still manually retrieve this data. |
4. <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Notice</h3><p>Requires a Cortex XDR Pro per Endpoint license. When you enable this feature, a Cortex XDR Pro per Endpoint license is consumed.</p></div>

   Enable **XDR Pro Endpoint Capabilities**, and then configure the capabilities required by your organization. The Cortex XDR Pro features are hidden until you enable this option.

   | Item                                       | Options                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
   | ------------------------------------------ | ------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Monitor and Collect Enhanced Endpoint Data | <ul><li>Enabled</li><li>Disabled</li></ul> | By default, the Cortex XDR agent collects information about events that occur on the endpoint. If you enable Behavioral Threat Protection in a Malware security profile, the Cortex XDR agent also collects information about all active file, process, network, and registry activity on an endpoint. When you enable the Cortex XDR agent to monitor and collect enhanced endpoint data, Cortex XSIAM shares the detailed endpoint information with other Cortex apps. The information can help to provide the endpoint context when a security event occurs, so that you can gain insight into the overall event scope during an investigation. The event scope includes all activities that took place during an attack, the endpoints that were involved, and the damage caused. When disabled, the Cortex XDR agent will not share endpoint activity logs. |
   | Enable Host Insights Capabilities          | <ul><li>Enabled</li><li>Disabled</li></ul> | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Requires Host Insights add-on</p></div><p>When enabled, the various host insight capabilities can be configured.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Endpoint Information Collection            | <ul><li>Enabled</li><li>Disabled</li></ul> | When enabled, the Cortex XDR agent collects Host Inventory information such as users, groups, services, drivers, hardware, and network shares, as well as information about applications installed on the endpoint, including CVE and installed KBs for Vulnerability Assessment.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
   | Enable Compliance Collection               | <ul><li>Enabled</li><li>Disabled</li></ul> |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
5. Configure **XDR Cloud** for hosts running on cloud platforms. By default (auto-detect mode), the agent detects whether an endpoint is a cloud-based (container) installation or a permanent installation, and uses license allocation accordingly.

   | Item      | Options                                       | More details                                                                                                                                        |
   | --------- | --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
   | XDR Cloud | <ul><li>Auto-detect</li><li>Enabled</li></ul> | If you set this to **Enabled** in the profile, any agent using this profile will be treated as if it is a cloud-based agent for licensing purposes. |
6. Configure **Response Actions** for specific applications or processes, using an Allow list.

   If you need to isolate an endpoint, but want to allow access for a specific application or process, add it to the **Network Isolation Allow List**. Keep the following considerations in mind:

   * When you add a specific application to your allow list from network isolation, the Cortex XDR agent continues to block some internal system processes. This is because some applications, for example, ping.exe, can use other processes to facilitate network communication. As a result, if the Cortex XDR agent continues to block an application you included in your allow list, you may need to perform additional network monitoring to determine the process that facilitates the communication, and then add that process to the allow list.

   1. Click **Add** to add an entry to the allow list.
   2. Specify the Process Path that you want to allow, and the IPv4 or IPv6 address of the endpoint. Use the **`*`** wildcard on either side to match any process or IP address. For example, specify **`*`** as the process path and an IP address to allow any process to run on the isolated endpoint with that IP address. Conversely, specify **`*`** as the IP address and a specific process path to allow the process to run on any isolated endpoint that receives this profile.
   3. Click the check mark.
7. Configure settings to automatically **Revert Endpoint Isolation** of an agent. When this feature is enabled, agent isolation will be cancelled when a connection with the managing server is lost for the defined continuous period of time.
   1. Either keep the recommended default setting (**Enabled**), or change it by selecting **Disabled** in the **Revert Isolation** field.
   2. Set a time unit and enter the number of hours or days. We recommend 24 hours (default).
8. Configure the method used to update content on your endpoints.

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h3>Warning</h3><p>If you disable or delay automatic-content updates provided by Palo Alto Networks, it may affect the security level in your organization.</p></div>

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><ul><li>If you disable content updates for a newly installed agent, the agent retrieves the content for the first time from Cortex XSIAM, and then disables content updates on the endpoint.</li><li>When you add a Cortex XDR agent to an endpoint group with a disabled content auto-upgrades policy, the policy is applied to the added agent as well.</li></ul></div>

   | Item                | Options                                              | More details                                                                                                                                                                                                                                                                                                                                                               |
   | ------------------- | ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Content Auto-update | <ul><li>Enabled (default)</li><li>Disabled</li></ul> | <p>By default, the Cortex XDR agent always retrieves the most updated content and deploys it on the endpoint, to ensure that it is always protected with the latest security measures.</p><p>If you disable content updates, the agent stops retrieving them from the Cortex XSIAM tenant, and keeps working with the current content on the endpoint.</p>                 |
   | Staging Content     | <ul><li>Enabled</li><li>Disabled (default)</li></ul> | Enable users to deploy agent staging content on selected test environments. Staging content is released before production content, allowing for early evaluation of the latest content update.                                                                                                                                                                             |
   | Content Rollout     | <ul><li>Immediately</li><li>Delayed</li></ul>        | The Cortex XDR agent can retrieve content updates immediately as they are available, or after a pre-configured delay period. When you delay content updates, the Cortex XDR agent will retrieve the content according to the configured delay. For example, if you configure a delay period of two days, the agent will not use any content released in the last 48 hours. |
9. Agent Auto-Upgrade is disabled by default. Before enabling Auto-Update for Cortex XDR agents, make sure to consult with all relevant stakeholders in your organization.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Automatic upgrades are not supported with non-persistent VDI and temporary sessions.</p></div>

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Automatic upgrades are not supported for XDR agents running on K8s.</p></div>

   | Item                    | Options                                                                                                                                                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Agent Auto-Upgrade      | <ul><li>Enabled</li><li>Disabled (Default)</li></ul>                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
   | Automatic Upgrade Scope | <ul><li>Latest agent release</li><li>One release before the latest one</li><li>Only maintenance releases</li><li>Only maintenance releases in a specific version</li></ul> | <p>For <strong>One release before the latest one</strong>, Cortex XSIAM upgrades the agent to the previous release before the latest, including maintenance releases. Major releases are numbered X.X, such as release 8.0, or 8.2. Maintenance releases are numbered X.X.X, such as release 8.2.2.</p><p>For <strong>Only maintenance releases in a specific version</strong>, select the required release version.</p>                                                                                                                |
   | Upgrade Rollout         | <ul><li>Immediate</li><li>Delayed</li></ul>                                                                                                                                | <p>For <strong>Delayed</strong>, set the delay period (number of days) to wait after the version release before upgrading endpoints. Choose a value between 7 and 45.</p><p>To control the agent auto upgrade scheduler and number of parallel upgrades in your network, configure Global Agent Settings.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The delay timer starts from the date of the target agent version's availability in the tenant.</p></div> |
10. Specify a **Download Source**, or multiple sources, from which Cortex XDR agent retrieves agent and content updates. The options provided help you to reduce external network bandwidth loads during updates. When all sources are selected, the download sources are prioritized in the following order: P2P > Broker VM > Cortex XSIAM Server.

    To ensure your agents remain protected, the **Cortex Server** download source is always enabled to allow all Cortex XDR agents in your network to retrieve the content directly from the Cortex XSIAM server on their following heartbeat.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Limitations in the content download process:</p><ul><li>When you install the Cortex XDR agent, the agent retrieves the latest content update version available. A freshly installed agent can take between five to ten minutes (depending on your network and content update settings) to retrieve the content for the first time. During this time, your endpoint is not protected.</li><li>When you upgrade a Cortex XDR agent to a newer Cortex XDR agent version, if the new agent cannot use the content version running on the endpoint, the new content update will start within one minute in P2P, and within five minutes from Cortex XSIAM.</li></ul></div>

    | Item       | Options                                                                                                                                             | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Select all | <ul><li>Selected</li><li>Clear</li></ul>                                                                                                            | When selected, all download source options are enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
    | P2P        | <ul><li>33221 (default port)</li><li>custom port</li></ul>                                                                                          | <p>Cortex XSIAM deploys serverless peer-to-peer distribution to Cortex XDR agents in your LAN network by default. Within the six hour randomization window during which the Cortex XDR agent attempts to retrieve the new version, it will broadcast its peer agents on the same subnet twice: once within the first hour, and once again during the following five hours. If the agent did not retrieve the files from other agents in both queries, it will proceed to the next download source defined in your profile.</p><p>To enable P2P, you must enable UDP and TCP over the port specified for <strong>P2P Port</strong>. By default, Cortex XSIAM uses port 33221. You can change the port number, if required by your organization.</p>               |
    | Broker VM  | <ul><li>Select all</li><li>Brokers</li><li>Clusters</li></ul><p>(only Broker VMs that are connected and configured for caching can be selected)</p> | <p>(Requires Broker VM 12.0 and later)</p><p>If you have a Palo Alto Networks Broker VM in your network, you can leverage the Local Agent Settings applet to cache release upgrades and content updates. When the Broker VM is enabled and configured appropriately (refer to Activate the Local Agent Settings) , it retrieves the latest installers and content every 6 hours. The Broker VM stores them for a 24-hour retention period since an agent last asked for them.</p><p>If the files are not available on the Broker VM at the time of the request, the agent proceeds to download the files directly from the Cortex XSIAM server.</p><p>When you select multiple Broker VMs, the agent chooses a Broker VM randomly for each download request.</p> |
11. Define **Agent Proxy Settings**.

    Select whether to **Enable** or **Disable** **Direct Server Access** for the agent when connected using a proxy.
12. Configure **Advanced Vulnerability Scanning** for periodic Active Vulnerability Analysis (AVA) scans. This option is only available for tenants that are paired with Prisma Cloud.

    | Item                            | Options                                    | More details                                                                                                                                                                                                                                                                                                                    |
    | ------------------------------- | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Advanced Vulnerability Scanning | <ul><li>Enabled</li><li>Disabled</li></ul> |                                                                                                                                                                                                                                                                                                                                 |
    | Periodic Scan                   | <ul><li>24 Hours</li><li>Custom</li></ul>  | <p>For the default setting, select <strong>24 Hours</strong>.</p><p>For other time frames, select <strong>Custom</strong>, and then configure the desired time frame. Where relevant, select the start day and time for the periodic scans. If you select monthly scans, you can also configure a timeout period, in hours.</p> |
13. Configure **Agent Operation Mode**. Three modes of operation exist:

    * Kernel module-based operation, offering synchronous anti-malware protection, event collection from kernel level, and anti-lpe protection
    * User Space Agent: user mode agent, for agents running Linux kernel 5.0.0 or higher, offering synchronous anti-malware and event collection from kernel level
    * Neither of the above. When working in Kernel module-based operation running on an endpoint with an unsupported kernel, or installing with installation flag `--no-km` , or when working in User Space Agent mode on a Linux kernel older than 5.0.0, the agent will run in Asynchronous mode. In such cases, the anti-malware protection is asynchronous, and there is no event collection, no BTP, no EDR and no anti-lpe. This operation mode frequently shows "partially protected" endpoints. To avoid this, you can configure the profile to give preference to Kernel mode, but to switch to User Space Agent mode when the kernel module for an endpoint is not supported by a content update, and switch back when a the kernel module in use is supported in a newer content update.

    Endpoints running the Cortex XDR agent in Kernel mode can now be configured to automatically fall back to User Space Agent mode when a content update does not contain a kernel module for the kernel used by an endpoint.

    | Item                                                 | Options                                           | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
    | ---------------------------------------------------- | ------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Mode                                                 | <ul><li>Kernel</li><li>User Space Agent</li></ul> | <p>We recommend using <strong>Kernel</strong> mode.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Danger</strong></p><p><strong>User Space Agent</strong> mode requires Linux kernel 5.0.0 or higher.</p></div>                                                                                                                                                                                                                                                                                                                                                                                               |
    | When Kernel Mode is unavailable, use User Space Mode | <ul><li>Enabled</li><li>Disabled</li></ul>        | <p>When Kernel mode is used, to ensure continued full protection when a kernel version is not supported by a content update, select the <strong>Enabled</strong> option.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>User Space Agent mode requires Linux kernel 5.0.0 or higher. Endpoints running an older Linux kernel version with this fallback enabled, will not start using User Space Agent mode, and will operate asynchronously.</p></div><p>When a newer content update supports the endpoint's kernel module, fallback is canceled, and Kernel mode is automatically resumed.</p> |
14. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>

<details>

<summary>Android</summary>

1. Add a new profile and define basic settings.
   1. Select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile or import a profile from a file.
   2. Select the **Android** platform, and **Agent Settings** as the profile type.
   3. Click **Next**.
   4. For **Profile Name**, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include a case identification number or a link to a help desk ticket.
2. Configure the method used to update content on your endpoints.

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h3>Warning</h3><p>If you disable or delay automatic-content updates provided by Palo Alto Networks, it may affect the security level in your organization.</p></div>

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><ul><li>If you disable content updates for a newly installed agent, the agent retrieves the content for the first time from Cortex XSIAM, and then disables content updates on the endpoint.</li><li>When you add a Cortex XDR agent to an endpoint group with a disabled content auto-upgrades policy, the policy is applied to the added agent as well.</li></ul></div>

   | Item                | Options                                       | More details                                                                                                                                                                                                                                                                                                                                                               |
   | ------------------- | --------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Content Auto-update | <ul><li>Enabled</li><li>Disabled</li></ul>    | <p>By default, the Cortex XDR agent always retrieves the most updated content and deploys it on the endpoint, to ensure that it is always protected with the latest security measures.</p><p>If you disable content updates, the agent stops retrieving them from the Cortex XSIAM tenant, and keeps working with the current content on the endpoint.</p>                 |
   | Content Rollout     | <ul><li>Immediately</li><li>Delayed</li></ul> | The Cortex XDR agent can retrieve content updates immediately as they are available, or after a pre-configured delay period. When you delay content updates, the Cortex XDR agent will retrieve the content according to the configured delay. For example, if you configure a delay period of two days, the agent will not use any content released in the last 48 hours. |
3. Configure network usage preferences.

   When the option **Upload Using Cellular Data** is enabled, the Cortex XDR agent uses cellular data to send unknown apps to the Cortex XDR for inspection. Standard data charges may apply. When this option is disabled, the Cortex XDR agent queues any unknown files and sends them when the endpoint connects to a Wi-Fi network. If configured, the data usage setting on the Android endpoint takes precedence over this configuration.
4. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>

<details>

<summary>iOS</summary>

1. Add a new profile and define basic settings.
   1. Select **Inventory** → **Endpoints** → **Policy Management** → **Prevention** → **Profiles**. Click **+Add Profile**, and select whether to create a new profile or import a profile from a file.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>New profiles based on imported profiles are added, and do not replace existing ones.</p></div>
   2. Select the **iOS** platform, and **Agent Settings** as the profile type.
   3. Click **Next**.
   4. For **Profile Name**, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
   5. For **Description**, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include a case identification number or a link to a help desk ticket.
2. Configure the following notifications that can be pushed to the iOS device.

   | Item                         | Options                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                           |
   | ---------------------------- | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | App Notifications            | <ul><li>Enabled</li><li>Disabled</li></ul> | Select whether to enable or disable notifications from the app on the iOS device.                                                                                                                                                                                                                                                                                                                                                                      |
   | Jailbreak Detection          | <ul><li>Enabled</li><li>Disabled</li></ul> | Select whether to enable or disable Jailbreak Detection notification to the device.                                                                                                                                                                                                                                                                                                                                                                    |
   | Restart Recommendation       | <ul><li>Enabled</li><li>Disabled</li></ul> | Select whether to enable or disable a reboot notification to the device. An option can be set for a reminder every number of days. The default is 15 days.                                                                                                                                                                                                                                                                                             |
   | Stationary Device Indicators | <ul><li>Enabled</li><li>Disabled</li></ul> | <p>Select whether to enable or disable notifications for stationary iOS devices, such as iPads that are expected to remain in a fixed location. Options include:</p><ul><li>Significant location change</li><li>Unplugged from power</li><li>Low battery. You can configure a threshold for the device's remaining charge level (10% - 90%).</li><li>Significant network change</li><li>Show Stationary Device indication on its home screen</li></ul> |
3. To save the profile, click **Create**.

What to do next

If you are ready to apply your new profile to endpoints, you do this by adding it to a policy rule. If you still need to define other profiles, you can do this later. During policy rule creation or editing, you select the endpoints to which to assign the policy. There are different ways of doing this, such as:

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
