Cortex XDR Agents Deployed in Advertise Mode
Depending on your Cortex XDR agent release, you can install or upgrade the agent in Advertise mode.
Advertise mode is an msi property you can set manually through the msi execution command line or through a deployment profile in a third-party deployment tool such as Microsoft System Center Configuration Manager (SCCM), allowing the Windows Installer to advertise the availability of an application to users or other applications without actually installing the application. For more information on advertise mode, refer to the Microsoft Windows official documentation.
Caution
When you want to install or upgrade a Cortex XDR agent on an endpoint where a Cortex XDR agent release prior to 7.0.3 was installed in Advertise mode, whether the agent is still running or was removed from the endpoint, you must first clean the endpoint from the remains of the previous installation in Advertise mode. Otherwise, if you don’t clean the endpoint, the installation/upgrade of the Cortex XDR agent will fail.
The following table summarizes the different scenarios of upgrade paths and the recommended workaround according to the different Cortex XDR agent releases:
Agent release 5.0.0 or later that was installed in Advertise mode
Not supported, leads to undefined behavior.
Contact Palo Alto Networks Support for assistance before you can re-install the agent.
Not supported, you will receive an error in the agent installation log.
Contact Palo Alto Networks Support for assistance before you can re-install the agent.
You will receive an error in the agent installation log.
Add the CLEAN_AGGRESIVLY=1 msi property to you command line and proceed to install the agent.
Agent release 7.0.3 or later that was installed in Advertise mode
N/A
Seamless
Seamless
Last updated
Was this helpful?
