> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md).

# Install the Cortex XDR Agent Using JAMF

To deploy the Cortex XDR agent to multiple endpoints, you can set up a JAMF profile. As part of your JAMF deployment you must grant full disk access, approve system extensions, content filter configuration, notifications and managed login items. Depending on your macOS version.

For a seamless configuration using JAMF that does not require creating the configuration profile manually, refer to [Install with a unified configuration profile for MDMs](/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-with-a-unified-configuration-profile-for-mdms.md).

{% hint style="warning" %}

### Caution

Following the changes Apple introduced in [macOS 11.3 for MDMs](https://support.apple.com/en-us/HT211911), when you remove an MDM configuration profile that includes permissions for system extensions (for Cortex XDR agents or Global Protect), the system extensions will be instantly unloaded from all endpoints. As a result, the Cortex XDR protection status will be disabled.
{% endhint %}

To set up a JAMF profile step-by-step, use the following workflow. The figures given here are as examples only. For additional information, refer directly to the [JAMF documentation on configuring configuration profiles](https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Computer_Configuration_Profiles.html).

1. Create a new **Computer Configuration Profile** in JAMF.

   Under General Options, assign the following:

   * Name: **`Cortex XDR Agent Unified Configuration Profile`**
   * Level: Select **Computer level**.

   ![Unified\_Config\_Profile.png](/files/sD8NYqPRjLsGnJUPaXC1)
2. Configure **System Extensions**.

   ![JAMF\_System\_Extentions\_2023.png](/files/fE7EeoyetQXdtyPjpjX7)

   1. Select**Allow users to approve system extensions**.
   2. Add an approved Team ID for Palo Alto Networks:
      * System Extension Types—**Allowed System Extensions**
      * Team Identifier—**`PXPZ95SK77`**
      * Allowed system extension bundles—**`com.paloaltonetworks.traps.securityextension`** and **`com.paloaltonetworks.traps.networkextension`**
   3. Add the allowed system extensions and save each item.
3. Configure **Content Filter**.

   1. Configure the following Content Filter in your JAMF profile:
      * Filter name: **`Cortex XDR Network Filter`**
      * Identifier: **`com.paloaltonetworks.cortex.app`**
      * Filter Order: **`Firewall`**
   2. Set the socket filter to enabled, and define the following:
      * Socket Filter Bundle Identifier: **`com.paloaltonetworks.traps.networkextension`**
      * Socket Filter Designated Requirement: **`identifier "com.paloaltonetworks.traps.networkextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = PXPZ95SK77`**
   3. The network (packet) filter is set to enabled. Cortex XDR agent disables the filter when it gets a default policy. The packet filter provider is enabled by the Cortex XDR agent when it is required.
      * Network Filter Bundle Identifier: **`com.paloaltonetworks.traps.networkextension`**
      * Network Filter Designated Requirement: **`identifier "com.paloaltonetworks.traps.networkextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = PXPZ95SK77`**

   ![JAMF\_Config\_Settings-Content\_Filter\_2023.png](/files/O4gtlKy54WJodUGk9KAl)
4. Configure **Privacy Preferences Policy Control** as described in Steps 4, 5, and 6:

   ![JAMF\_Privacy\_Preferences\_Policy\_Control\_2023.png](/files/Y2ltoulow3UhkQi2GuDj)

   1. Use the following settings to define the entity:
      * Identifier: **`com.paloaltonetworks.cortex.agent`**
      * Identifier Type: **Bundle ID**
      * Code Requirement: **`identifier "com.paloaltonetworks.cortex.agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = PXPZ95SK77`**
   2. Add and **Allow** Accessibility service.
   3. Save the app or service item.
5. Add a new **App Access** configuration to grant Full Disk Access to the Cortex XDR security extension.

   This configuration is required to enable the security extension to communicate with the OS.

   ![JAMF\_Privacy\_Preferences\_Policy\_Control\_b\_2023.png](/files/aw6c1B490ta0oFygwn7C)

   1. Use the following settings to define the following entity:
      * Identifier: **`com.paloaltonetworks.traps.securityextension`**
      * Identifier Type: **Bundle ID**
      * Code Requirement: **`identifier "com.paloaltonetworks.traps.securityextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = PXPZ95SK77`**
   2. In **App or Service**, set **SystemPolicyAllFiles** to **Allow**.
   3. **Save** the app or service item.
6. Add a new **App Access** configuration to grant Full Disk Access to Cortex XDR pmd.

   This configuration allows the daemon access to analyze processes, files, disk access, utilities and more.

   ![JAMF\_Privacy\_Preferences\_Policy\_Control\_c\_2023.png](/files/6N83nyTu6ObmpzmQMgn8)

   1. Use the following settings to define the entity:
      * Identifier: **`/Library/Application Support/PaloAltoNetworks/Traps/bin/pmd`**
      * Identifier Type: **Path**
      * Code Requirement: **`identifier pmd and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = PXPZ95SK77`**
   2. In **App or Service**, set **SystemPolicyAllFiles** to **Allow**.
   3. **Save** the app or service item.
7. Configure **Notifications**.

   Configure the following Notifications payload in your JAMF profile:

   * Bundle ID for agent 8.2 and earlier: **`com.paloaltonetworks.traps-agent`**

     Bundle ID for agent 8.3 and later: **`com.paloaltonetworks.cortex.agent`**
   * Critical alerts: **`Enable and include`**.
   * Notifications: **`Enable and include`**.
   * Banner alert type: **`Temporary and include`**.
   * Notifications on Lock Screen: **`Display and include`**.
   * Notifications on Notification Center: **`Display and include`**.
   * Badge app icon: **`Display and include`**.
   * Play sound for notifications: **`Enable`**.

   ![JAMF\_Notifications\_2023.png](/files/f4dTnt9NUL6TvrnlW9S7)
8. Configure Managed Login Items.

   * Rule type: **`Label prefix`**
   * Rule value: **`com.paloaltonetworks.cortex`**
   * Team identifier: **`PXPZ95SK77`**
   * Rule comment: **`Allows Cortex XDR launch daemons and launch agents`**

   ![Configuration\_profile\_Notifications\_2.png](/files/wbJbUAB5X8Hm72wPTPJA)
9. Configure **Application & Custom Settings** and click **Upload**.
   1. Select **+Add** to add the configuration details for each web browser:

      **Chrome**:

      * Preference Domain: `com.google.Chrome`
      * Property List:

        ```programlisting
        <?xml version="1.0" encoding="UTF-8"?>
        <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
        <plist version="1.0">
          <dict>
            <key>ExtensionSettings</key>
            <dict>
              <key>aalncdhjokfcbldaemnehledpfpibopi</key>
              <dict>
                <key>installation_mode</key>
                <string>force_installed</string>
                <key>toolbar_pin</key>
                <string>force_pinned</string>
                <key>update_url</key>
                <string>file:///Library/Application Support/PaloAltoNetworks/Traps/cdsx/extension.xml</string>
              </dict>
            </dict>
          </dict>
        </plist>
        ```

        ![CdsxMdmChrome.png](/files/wiR1dzJldPNaQwDlpKCU)

      **Edge**

      * Preference Domain: `com.microsoft.Edge`
      * Property List:

        ```programlisting
        <?xml version="1.0" encoding="UTF-8"?>
        <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
        <plist version="1.0">
          <dict>
            <key>ExtensionSettings</key>
            <dict>
              <key>aalncdhjokfcbldaemnehledpfpibopi</key>
              <dict>
                <key>installation_mode</key>
                <string>force_installed</string>
                <key>toolbar_state</key>
                <string>force_shown</string>
                <key>update_url</key>
                <string>file:///Library/Application Support/PaloAltoNetworks/Traps/cdsx/extension.xml</string>
              </dict>
            </dict>
          </dict>
        </plist>
        ```

        ![CdsxMdmEdge.png](/files/i3fyeD9IeY8HlTCNpMaJ)
10. **Save** the configuration profile.
11. After you set up your computer configuration profiles, create a new agent installation package in the Cortex XDR management console, upload the ZIP package you downloaded from Cortex XDR to your MDM (do not extract it), and then add it to a distribution point.

    For instructions, see the following documentation resource from JAMF: [Manually Adding a Package to a Distribution Point and Jamf Pro](https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Package_Management.html).
12. Create a new policy and install the package.
    * JAMF [Package Deployment](https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Package_Deployment.html) instructions.
    * JAMF [Policy Management](https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Policy_Management.html) instructions.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-using-jamf.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
