For the complete documentation index, see llms.txt. This page is also available as Markdown.

Add an Agent Settings Prevention Profile (Administrator Task)

You can use Agent Settings prevention profiles to customize Cortex XDR agent settings for different platforms and groups of users.

You can use Agent Settings prevention profiles to customize the Cortex XDR agent settings for different platforms and groups of users. Configure an Agent Settings profile on the Cortex XDR or XSIAM tenant.

  1. Add a new profile and define basic settings.

    1. Select EndpointsPolicy ManagementPreventionProfiles. Click +Add Profile, and select whether to create a new profile or import a profile from a file.

      Note

      New profiles based on imported profiles are added, and do not replace existing ones.

    2. Select the iOS platform, and Agent Settings as the profile type.

    3. Click Next.

    4. For Profile Name, enter a unique name for the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.

    5. For Description, to provide additional context for the purpose or business reason for creating the profile, enter a profile description. For example, you might include an incident identification number or a link to a help desk ticket.

  2. Configure the following notifications that can be pushed to the iOS device.

    Item

    Options

    More details

    App Notifications

    • Enabled

    • Disabled

    Select whether to enable or disable notifications from the app on the iOS device.

    Jailbreak Detection

    • Enabled

    • Disabled

    Select whether to enable or disable Jailbreak Detection notification to the device.

    Restart Recommendation

    • Enabled

    • Disabled

    Select whether to enable or disable a reboot notification to the device. An option can be set for a reminder every number of days. The default is 15 days.

    Stationary Device Indicators

    • Enabled

    • Disabled

    Select whether to enable or disable notifications for stationary iOS devices, such as iPads that are expected to remain in a fixed location. Options include:

    • Significant location change

    • Unplugged from power

    • Low battery. You can configure a threshold for the device's remaining charge level (10% - 90%).

    • Significant network change

    • Show Stationary Device indication on its home screen

  3. To save the profile, click Create.

Assign the profile to a prevention policy rule

  1. Select Endpoints → Policy Management → Prevention → Policy Rules.

  2. Do one of the following:

    • To create a new policy or import a policy, click +Add Policy and select whether to Create New or Import from File. Enter a meaningful Policy Name and Description.

    • Edit an existing policy rule.

    Note

    New imported policies are added, not replaced.

  3. For Platform, select iOS, and then for Agent Settings, select the profile that you created.

  4. Click Next.

  5. Select the iOS devices to which you want to assign the policy.

  6. Click Done.

Last updated

Was this helpful?