Cortex XDR Compatibility Matrix

Tree view

This book on one page — search it with your browser’s find (Ctrl+F / ⌘F), or jump from the tree.

Cortex XDR Compatibility Matrix

Where can I install the Cortex XDR agent?

The Cortex XDR agent is installed on supported physical and virtual endpoints.

Cortex XDR agent is a software component of the larger Cortex products. It provides both cloud workload and endpoint protection, depending on your license and deployment environment. Cortex XDR agent is installed on supported physical and virtual endpoints. As a comprehensive security solution, it secures a wide range of assets, from cloud environments (like containers and Kubernetes clusters) to traditional endpoints, and mobile devices. To ensure maximum protection of your endpoints, Palo Alto Networks recommends that you always deploy the latest maintenance version for each agent release.

Palo Alto Networks strives to support the latest major operating systems. When a new operating system is available, there may be a short delay in our support as we test interoperability.

Until a Cortex XDR agent release reaches its end-of-life status, the following support is provided:

  • Microsoft operating systems are supported for three years beyond the end of Microsoft support.
  • In general, other operating systems are supported until they reach end-of-life, or their extended life, as relevant.
  • For Android, we support the latest Cortex XDR agent app that is available on the Google Play Store regardless of the app release date. An agent version that is no longer on Google Play will be supported for one year after the date of its release.

Note

The Cortex XDR agents for iOS, Android, 32-bit Windows, and version 7.5-CE agents, are not FedRamp compliant.

Agent releases

To ensure maximum protection of your endpoints, Palo Alto Networks recommends that you always deploy the latest maintenance version for each agent release.

Critical Environment (CE) versions must be enabled in your Cortex system before use. CE versions are designed for sensitive and highly regulated environments. These versions receive full content update coverage and contain the same feature set as the standard line it is based on. Please note, that some bug fixes, introducing higher stability risk, may not be incorporated into the maintenance releases of these lines. Support is provided for CE versions for 24 months, while support for standard versions is provided for 9 months.

See Cortex XDR Agent Releases for details and the release notes of the current agent versions. EOL versions may be shown in this document for information purposes only.

Endpoint operating systems supported

The following tables show the endpoint operating systems on which you can install each release of the Cortex XDR agent. These operating systems are also supported with supported Citrix and VMware virtual applications.

Mac

Supported Mac operating systems

The following Mac operating systems support the Cortex XDR agent.

  Cortex XDR Agent Version          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
<p>macOS 26</p><p>Tahoe</p>
<p>macOS 15</p><p>Sequoia</p>
<p>macOS 14</p><p>Sonoma</p>
<p>macOS 13.X</p><p>Ventura</p>
<p>macOS 12.X</p><p>Monterey</p>

Note

The Cortex Agent for macOS is FedRamp compliant from version 7.6.0 and later for Intel processors only.

Windows

Supported Windows operating systems

The following Windows operating systems support the Cortex XDR agent.

Note

Due to a limitation on Windows Servers, Cortex XDR agent will not register with the Microsoft Security Center.

Install the Cortex XDR agent on unsupported-ACS OS versions

Microsoft Trusted Signing (Azure Code Signing) Directive

Since March 2023, Microsoft request security vendors to sign binaries using Trusted Signing (formerly Azure Code Signing). As a result, Cortex XDR agent versions require a specific Microsoft Windows patch. Note that any machines without this Windows patch are not able to install or upgrade to newer versions of Cortex XDR agent. This mainly impacted Windows machines running Windows 10 or below; Windows 11 machines have this patch pre-installed. Windows 7 machines must have an extended support license in order to install the patch. Additional information about the security patch and the specific patch numbers required per operating system build, KB5022661/KB4474419 . In cases where the Microsoft security patch has since expired, ACS support is achieved by installing cumulative updates after the release of the initial KB patch.

Cortex XDR agent versions later than 8.3-CE will automatically detect an ACS-unsupported OS and allow the installation to complete successfully.

In agent versions 7.9.103-CE and 8.3-CE, to override the default behavior, admin must provide an MSI flag, NO_ACS_SUPPORT=1, as a parameter to the installer. This flag indicates that the installation is to be made on an ACS-unsupported operating system. A fresh installation is needed for using this flag.

Note

The NO_ACS_SUPPORT flag cannot be provided as part of an existing Cortex XDR agent upgrade.

If upgrading from a 7.5-CE release line, even without explicitly providing the installer flag, the installer will detect that ACS is unsupported and will treat the installation as if the flag was given.

Windows 7

Note

Cortex XDR agent 7.9 was the last version to support Windows 7. Release 7.9.103-CE gives extended support until December 31, 2026. No new capabilities will be developed for these OS versions.

Windows 7 Operating System 8.0 and later versions 7.9.103‑CE
Windows 7 Operating System 8.0 and later versions 7.9.103‑CE
RTM
<p>Windows 7 SP1</p><p>(All editions except Home)</p>
Embedded Standard 7 SP1
<p>Embedded POSReady 7</p><p>(Based on Windows 7 SP1)</p>

Windows 8

All Windows 8 variants were supported until January 2023 (Microsoft EOL + 3 years). Release 7.9-CE, up to release 7.9.102-CE, offered support for Windows 8.1 until March 19, 2025. No new capabilities will be developed for these OS versions.

The extended-life agent 7.9.103-CE does not support Windows 8.1

Windows 10

The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
19H2, 20H1, 20H2, 21H1
Threshold LTSB, Redstone LTSB, Redstone 5 LTSB, 21H2, 22H2
<p>Windows 10 IoT Core
Windows 10 IoT Enterprise</p>

Windows 11

The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
<p>25H2
x86_64 and ARM</p>
<p>24H2
x86_64 and ARM</p>
<p>23H2
x86_64 and ARM</p>
<p>22H2
x86_64</p>

Note

Windows running on ARM is subject to certain limitations, see Known limitations in the latest Cortex XDR agent release notes.

Windows Server

The Datacenter edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.

Note

Release 7.9-CE, up to release 7.9.102-CE, was supported Windows Server until March 19, 2025.

The extended-life agent 7.9.103-CE supports Windows Server 2008 R2 SP1 until December 31, 2027.

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE7.9.103-CE
2025
2022
2019 LTSC
2019 Core
2016
2012 (Support until Oct 2027)
2012 R2 (Support until Oct 2027)
2012 Core
2008 R2 SP1
Linux

Supported Linux operating systems

The following Linux operating systems support the Cortex XDR agent.

The Cortex XDR agent protects Linux servers, there are two methods for agent protection; a Kernel module and a user-mode (eBPF-based) approach. To help you choose the best deployment for your environment, see the feature differences between these two modes in the latest Cortex XDR agent Admin guide Broken link.

For the latest Kernel modules support see here.

Note

Cortex XDR agent 9.1 was the last agent release supporting Linux kernels below 3.10. To avoid service disruption, hosts running kernels below 3.10 must not be upgraded beyond the 9.1 agent line. Disable auto-upgrades for endpoint profiles managing those machines, and prevent manual upgrades of the hosts to agent versions later than 9.1

Alibaba Cloud Linux

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Alibaba Cloud Linux 3

AlmaLinux

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
AlmaLinux 10
AlmaLinux 9
AlmaLinux 8

Amazon Linux/Amazon Linux 2/Amazon Linux 2023

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
AMI 2018.03
Amazon Linux 2 AMI
Amazon Linux 2 AMI (aarch64)
Amazon Linux 2023
Amazon Linux 2023 (aarch64)

Debian

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
Debian 13 (Trixie)
Debian 12 (Bookworm)
Debian 11 (Bullseye)
Debian 10 (Buster)
Debian 10 (Buster) aarch64
Debian 9 (Stretch)

CentOS

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
CentOS Stream 9
CentOS Stream 8
CentOS Stream 8 aarch64
CentOS 8
CentOS 8 aarch64
CentOS 7.9 aarch64

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

CentOS 7
CentOS 6
(6.7 and above)
Async mode onlyAsync mode only

Fedora Server

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Fedora Server (USM only)

openSUSE

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
openSUSE Leap 16.0 (UM only) <p>✓</p><p>From content release 2280-36261</p> <p>✓</p><p>From content release 2280-36261</p>
openSUSE Leap 15.6 (UM only) <p>✓</p><p>From content release 2160-30885</p> <p>✓</p><p>From content release 2160-30885</p> <p>✓</p><p>From content release 2160-30885</p> <p>✓</p><p>From content release 2160-30885</p>
openSUSE Leap 15.3
openSUSE Leap 15.2
openSUSE Leap 15.1

Oracle Linux

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
Oracle 10 x86_64

From content release 1940-22526

Oracle 10 aarch64

From content release 1940-22526

Oracle 9 x86_64 — Release 9.4 and later
Oracle 9 x86_64 — Release 9.3*
Oracle 9 aarch64
Oracle 8
Oracle 8 aarch64
Oracle 7


Oracle Linux 6 (6.7 and above)

  • RHCK (kernel 2.6.32)
  • UEK Release 2 (kernel 2.6.39)
  • UEK Release 3 (kernel 3.8.13)
Async mode onlyAsync mode only

*Oracle Linux 9.3 x86_64 notes:

Kernel Support Minimum agent version
RHCK User mode only 8.2
UEK Supported 7.9-CE

Red Hat Enterprise Linux

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
RHEL 10 x86_64
RHEL 10 aarch64
RHEL 9* x86_64
RHEL 9* aarch64
RHEL 8 x86_64
RHEL 8 aarch64

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

RHEL 7
RHEL 6 (supports 6.7 and above)Async mode onlyAsync mode only

*RHEL 9 requirement

RHEL 9.3 and later requires Cortex XDR agent version 8.2 or later.

Rocky Linux

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Rocky Linux 10 x86_64
Rocky Linux 9 x86_64
Rocky Linux 9 aarch64
Rocky Linux 8 x86_64

SUSE Linux Enterprise Server

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Server 16.0 <p>✓</p><p>From content release 2280-36261</p> <p>✓</p><p>From content release 2280-36261</p>
Server 15 SP7 <p>✓</p><p>From content release 1940-22526</p>
Server 15 SP0-SP6
Server 12 SP4-SP5
Server 11 SP4 Async mode only Async mode only

Ubuntu

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
26.04 LTS x86_64
26.04 LTS aarch64
24.04 LTS x86_64
24.04 LTS aarch64
22.04 LTS x86_64
22.04 LTS aarch64
20.04 LTS
20.04 LTS aarch64
18.04 LTS
18.04 LTS aarch64
16.04 LTS
14.04 LTSAsync mode onlyAsync mode only
12.04 LTSAsync mode onlyAsync mode only

Cloud platforms supported with Cortex XDR agent

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
Alibaba Cloud
Amazon Web Services (AWS)
Google Cloud Platform
IBM Cloud
Microsoft Azure
Oracle Cloud Infrastructure (OCI)

Kubernetes platforms supported

View the Kubernetes platforms that are supported with Cortex XDR agents.

This table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version tested for compatibility are supported.

For installation instructions refer to Cortex XDR Agent for Linux → Install the Cortex XDR Agent for Kubernetes Hosts in the latest Cortex XDR agent admin guide.

Linux Kubernetes PlatformVersion
Unmanaged Kubernetes (k8s)1.30

Amazon Elastic Kubernetes Service (EKS)

  • BottleRocket OS x86_64
    User mode agent only
  • BottleRocket OS aarch64
    User mode agent only
1.36

Microsoft Azure Kubernetes Service (AKS)

  • CBL-mariner 2 x86_64
1.36

Google Kubernetes Engine (GKE)

  • Google Container-Optimized OS (COS)* x86_64
    User mode agent only
  • Google Kubernetes Engine (GKE) Autopilot
1.36
Oracle Kubernetes Engine (OKE)1.33

Red Hat Openshift Container Platform (OCP)

  • RHCOS* x86_64
    User mode agent only

4.18

4.19 in agent versions 9.1.1 and later

4.20 in agent versions 9.1.1 and later

SUSE Rancher Kubernetes Engine 2 (RKE2)1.28
Talos1.8.3

Notes

In Google Container-Optimized OS release 100 and earlier, where the FANOTIFY EXEC flag is not supported, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.

In RHCOS version 4.12 and earlier, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.

Virtual applications supported

The following describes the supported software vendors you can use to deploy virtual applications and the minimum software version supported with each release of the Cortex XDR agent.

Citrix

  • Citrix Virtual Apps and Desktops (previously XenApp and XenDesktop)—7.xx and later on all Cortex XDR agents.
  • Citrix App Layering according to the installation process detailed in the Cortex XDR agent admin guide. Installation on the OS layer: Citrix App 4 and later on all Cortex XDR agents Installation on the Platform layer: Supported from Cortex XDR agent 9.2 and later

VMware

  • VMware AppVolumes—2.13.1 & later on all Cortex XDR agents according to the installation process detailed.
  • VMware Horizon View—7.8 & later for all Cortex XDR agents.
  • VMware ThinApp—5.2.2 & later for all Cortex XDR agents.

Windows

  • Windows Virtual PC—Azure Virtual Desktop (WVD or AVD) supported from Cortex XDR agent 7.5 and later.

Mobile operating systems supported with Cortex XDR

The following tables show the mobile operating systems on which you can install each release of the agent. You can install the Cortex XDR agent on Android and iOS, mobile phones and tablets.

Android

Cortex XDR agent for Android
9.39.29.19.08.98.8
26
16
15
14
13
12
11
10
9
8

iOS/iPadOS

Note

The SMS filtering and call blocking features offered by Cortex XDR are available only in iPhones. iPads do not support SMS messaging or cellular-based telephony, even when fitted with a SIM card.

  Cortex XDR agent for iOS          
  9.3 9.2 9.1 9.0 8.9 8.8
26
16.0 and later
15.0 and later

Cortex XDR agent compatibility with third-party security products

Review the considerations related to third-party security software integration with Cortex XDR agent software.

This information outlines important considerations regarding the integration of third-party security software with Cortex XDR agent software. The following tables detail the supported security products that can run alongside Cortex XDR, along with their known limitations or the required additional actions to ensure proper integration with Cortex XDR agents.

It is important to note that while other third-party applications may be compatible with Cortex XDR agents, Palo Alto Networks has not conducted compatibility testing on these products. Customers who intend to install such applications alongside Cortex XDR agents are advised to perform thorough internal testing to ensure there are no conflicts or performance issues.

Should you encounter any problems during the integration process with the following third-party security software, please contact your support team for assistance.

Third-party Windows security applications

Application Name Limitations
CrowdStrike Falcon Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously.
Microsoft Defender If a Cortex XDR agent is running alongside Microsoft Defender on endpoints running Windows Server editions, we recommend setting Defender to Passive mode. Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously.
Trellix McAfee Solidcore/Solidifier Running exploit protection and Solidcore/Solidifier in parallel is not supported. All other malware protection functionality—such as local analysis, WildFire analysis, and restriction rules—works as expected. Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously.
SentinelOne Singularity XDR Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously.

Third-party Mac security applications

Application Name Limitations
Symantec Endpoint Protection (SEP) Uninstalling or upgrading Cortex XDR agent on Mac endpoints with SEP installed is not supported.

Third-party Linux security applications

Application Name Limitations
SELinux Because SELinux collides with the agent injection mechanism, injection-based security modules (ROP Mitigation and Brute Force Protection) are disabled when SELinux is enabled. All other exploit and malware protection functionality works as expected. No user action is required.
Symantec Running Symantec Kernel Module on Linux machines side by side with Cortex XDR is not supported.
McAfee Running McAfee Kernel Module on Linux machines side by side with Cortex XDR will lead to the Cortex XDR agent running without the Kernel Module and be partially protected. It is recommended to have the McAfee KM disabled.