For the complete documentation index, see llms.txt. This page is also available as Markdown.

Understand Cortex Data Security Licenses

Cortex Data Security is licensed on a workload basis rather than per endpoint or agent. A Cortex Data Security license entitles you to a pool of Data Security Workload units, which enable the full range of capabilities within Cortex Data Security and are consumed by the data assets you protect. For details on how assets consume workload units, see License allocation.

To view the product license and add-ons associated with your tenant, go to SettingsCortex Data Security License.

Deployment and availability

Cortex Data Security can be deployed in the following ways:

  • Standalone: A dedicated Cortex tenant focused exclusively on Cortex Data Security.

  • Add-on: Integrated into an existing Cortex XDR or Cortex XSIAM tenant, providing a unified management experience for your security operations and data security posture.

Note: Cortex Data Security capabilities may be included or available based on your existing license:

  • Cortex XSIAM Premium (X5): Natively includes the full suite of Cortex Data Security capabilities (DSPM and DDR) across cloud, SaaS, and on-premises environments.

  • Cortex Cloud Runtime Security (C3): Provides comprehensive protection, detection, and response across cloud workloads and SaaS applications (such as Microsoft 365 or Slack). It includes Data Security Posture Management (DSPM) and Cloud Data Detection and Response (DDR) as core capabilities.

    To extend these data-centric protections to on-premises data stores or to provide a dedicated workspace for data security teams, you can add the Cortex Data Security license to your tenant.

Capabilities

The Cortex Data Security license includes core data security functionality and can be extended with additional capabilities as your needs grow.

Key features

Key features of the Cortex Data Security License include:

Feature
Description

Data Security Posture Management (DSPM)

Discover, classify, and assess the risk of your data assets at rest across cloud, SaaS, DBaaS, and on-premises environments.

AI Security Posture Management (AI-SPM)

Map and monitor the data that powers your AI pipelines—models, agents, endpoints, and training data—and assess their associated risk.

Data Access Governance (DAG) / Identity Security

Analyze identities and entitlements, calculate effective permissions, and govern access to sensitive data to enforce least privilege.

Data Detection and Response (DDR)

Real-time monitoring and automated response for data threats in cloud and SaaS environments. It uses machine learning and behavioral models to analyze cloud activity logs to detect and block anomalies like mass data exfiltration, unauthorized cross-region transfers, and suspicious identity behavior, while filtering out unrelated security noise.

Core Analytics

Detects anomalies and threats using machine learning and behavioral models.

Automation

Orchestrates and automates security workflows with prebuilt and customizable playbooks.

Data Ingestion

Collects and normalizes data from supported cloud and SaaS sources to create a unified foundation for data-centric analytics, investigation, and risk detection, enabling behavioral models to identify data-specific risks and prioritize security issues across the data estate.

Capacity add-ons

Use the following add-ons to expand your capacity.

Capacity add-on
Description

GB ingestion

Provides daily-ingested-GB (GB/day) capacity, which is not included in the base workload license (minimum 100 GB/day). Includes 30 days of ingested-data retention and 180 days of alerts and incidents retention.

Compute Units

Additional compute resources beyond the included allocation, to support scaling during peak workloads and cold-storage queries.

Data Retention

Extends hot, cold, per-dataset, and Case and Issue retention beyond the defaults. For details, see Data retention in Cortex Data Security and Data storage lifecycle.

GB Event Forwarding

Enables exporting parsed logs to an external SIEM for storage, so you can keep data in your own storage in addition to the Cortex Data Layer, for compliance requirements and machine learning purposes.

XDR integration for DLP

To enforce DLP policies directly on user endpoints (such as blocking unauthorized data transfers or browser-based exfiltration), you need the Cortex agent, which requires a base product like Enterprise Runtime Security (Cortex XDR) to deploy.

You must also purchase the Endpoint DLP add-on license. Once this license is applied and policies are configured in your console, the Cortex agent automatically downloads and activates the Cortex Data Loss Prevention (DLP) module to enforce your data security rules directly on the device.

Any resulting endpoint DLP incidents or sensitive asset detections are seamlessly integrated and surfaced within the Data Security Command Center.

More information

For more information about licensing, see the following topics:

Last updated

Was this helpful?