> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task.md).

# Prepare for Installation (Administrator Task)

Prepare your organization's systems for deploying the Cortex XDR agent app on iOS devices.

<details>

<summary>Zero touch onboarding, iOS 17 or later, using an MDM</summary>

1. Perform the configurations that are required for supervised devices.
2. On the Cortex XDR or XSIAM tenant, prepare [malware](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md) and [agent settings](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md) profiles and policies for iOS endpoints.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>By default, though the Messaging &#x26; Telephony module is optional, it is set as required by the default iOS Malware policy. This module requires manual user steps to enable it, so if you want a fully Zero-Touch user experience, you must disable it in the policy (set the action as <strong>Disabled</strong> in the <strong>Call and Messages Blocking</strong> section of the Malware profile). This cannot be set remotely using an MDM, so it should be disabled if using the Network Shield feature for zero touch onboarding.</p></div>
3. On the Cortex XDR or XSIAM tenant, create the agent installation package.
   1. Select **Endpoints** → **Agent Installations**.
   2. Click **Create** to create a new installation package.
   3. Enter a unique **Name** and an optional **Description** to identify the installation package.

      The package **Name** must be no more than 100 characters and can contain letters, numbers, hyphens, underscores, commas, and spaces.
   4. For **Package Type**, select **Standalone Installers**.
   5. For **Platform**, select **iOS**, and optionally, add a **Description**.
   6. Click **Create** to create the package.
4. From **Endpoints** → **Agent Installations**, when the status of the package shows **Completed**, right-click, and click **View Installation Links**.
5. Click **Copy** to copy the link and registration code, and save it for use in the next step.
6. On your organization's MDM solution, [prepare the configuration](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md) required for pushing the Cortex XDR agent app to the iOS endpoints, and for managing them. Include the [parameters for the Network Shield xmodule](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task/configure-network-filtering-on-supervised-devices-administrator-task.md) in the payload configuration profile.
7. Use the MDM to push the Cortex XDR app to the device.

   The device runs the Cortex XDR app in the background. If, and when, the device user opens the app, inactive security modules are presented to the user, and the app asks the user to activate them.

   When organization-managed devices have an active Network Shield module configured for automatic background registration, the onboarding process is skipped entirely when the device user opens the app for the first time.

{% hint style="info" %}

### Note

When organization-managed devices have an active Network Shield module configured for automatic background registration, no onboarding process is presented when the device user opens the app for the first time.
{% endhint %}

</details>

<details>

<summary>User self-onboarding, using an MDM</summary>

1. For supervised devices, perform the required configurations.
2. On the Cortex XDR or XSIAM tenant, prepare [malware](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md) and [agent settings](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md) profiles and policies for iOS endpoints.
3. On the Cortex XDR or XSIAM tenant, create the agent installation package.
   1. Select **Endpoints** → **Agent Installations**.
   2. Click **Create** to create a new installation package.
   3. Enter a unique **Name** and an optional **Description** to identify the installation package.

      The package **Name** must be no more than 100 characters and can contain letters, numbers, hyphens, underscores, commas, and spaces.
   4. For **Package Type**, select **Standalone Installers**.
   5. For **Platform**, select **iOS**, and optionally, add a **Description**.
   6. Click **Create** to create the package.
4. From **Endpoints** → **Agent Installations**, when the status of the package shows **Completed**, right-click, and click **View Installation Links**.
5. Click **Copy** to copy the link and registration code, and save it for use in the next step.
6. On your organization's MDM solution, [prepare the configuration](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task.md) required for pushing the Cortex XDR agent app to the iOS endpoints, and for managing them. Optionally, include the [parameters for the Network Shield module](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/configuration-for-installation-by-mdm-administrator-task/configure-network-filtering-on-supervised-devices-administrator-task.md) in the payload configuration profile.
7. Send onboarding instructions to the device user. The user must open the app, and follow the on-screen instructions. Inactive security modules are presented to the user, and the app asks the user to activate them.

</details>

<details>

<summary>User self-onboarding, no MDM</summary>

The Cortex XDR or Cortex XSIAM administrator prepares the installation package, and then sends a link with installation instructions to the endpoint iOS device user.

1. On the Cortex XDR or XSIAM tenant, prepare [malware](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-a-malware-prevention-profile-administrator-task.md) and [agent settings](/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task/add-an-agent-settings-prevention-profile-administrator-task.md) profiles and policies for iOS endpoints.
2. Create the agent installation package.

   1. Select **Endpoints** → **Agent Installations**.
   2. Click **Create** to create a new installation package.
   3. Enter a unique **Name** and an optional **Description** to identify the installation package.

      The package **Name** must be no more than 100 characters and can contain letters, numbers, hyphens, underscores, commas, and spaces.
   4. For **Package Type**, select **Standalone Installers**.
   5. For **Platform**, select **iOS**, and optionally, add a **Description**.
   6. Click **Create** to create the package.

   Cortex XDR or Cortex XSIAM prepares the installation package, and makes it available on the **Agent Installations** page.
3. Prepare the information for the endpoint user.
   1. Prepare an email or text message for the endpoint user.
   2. From **Endpoints** → **Agent Installations**, when the status of the package shows **Completed**, right-click, and click **View Installation Links**.
   3. Click **Copy** to copy the link and registration code and paste it in the email message.

      For example:

      App Store download link: `https://apps.apple.com/app/cortex-xdr/idXXXXXXXXXX`

      Activation link:

      `https://distributions.traps.palotaltonetworks.com/operations/provision/ios/?distributionId=f91dd2af13894a57b1dbda8528XXXXXX`

      Registration code:

      f91dd2af13894a57b1dbda8528XXXXXX
4. Copy the following instructions to the email message, and send the email to the endpoint user.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>These are generic instructions. Only the onboarding phases that are relevant to the device (and the defined security policy) are presented during the onboarding process.</p></div>

   1. On your iOS device, open the download link for the Cortex XDR Agent app.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>This link accesses the Cortex XDR Agent app in the App Store.</p></div>
   2. **Install** the app.
   3. Enter the Distribution ID if it has not been prefilled, and enter your username.
   4. Select **Register Agent** to continue.
   5. Follow the onboarding wizard instructions to confirm permissions and enable modules.
   6. For iPhones, configure the following:
      1. From **Settings**, select **Phone** → **Call Blocking & Identification**.
      2. Return to the **Phone** options, and select **SMS/Call Reporting**.
      3. Return to **Settings**, and select **Messages** → **Unknown & Spam**.
      4. For **Message Filtering**, enable **Filter Unknown Senders**.
      5. For **SMS Filtering**, select **Cortex XDR**, and then tap **Enable**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Manual startup of the Cortex XDR Agent app is required after every restart of the iOS device.</p></div>

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-ios-guide/9.2/administrator-tasks/prepare-for-installation-administrator-task.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
