Cortex XDR Compatibility Matrix
Tree viewThis book on one page — search it with your browser’s find (Ctrl+F / ⌘F), or jump from the tree.
Cortex XDR Compatibility Matrix
Where can I install the Cortex XDR agent?
The Cortex XDR agent is installed on supported physical and virtual endpoints.
Cortex XDR agent is a software component of the larger Cortex products. It provides both cloud workload and endpoint protection, depending on your license and deployment environment. Cortex XDR agent is installed on supported physical and virtual endpoints. As a comprehensive security solution, it secures a wide range of assets, from cloud environments (like containers and Kubernetes clusters) to traditional endpoints, and mobile devices. To ensure maximum protection of your endpoints, Palo Alto Networks recommends that you always deploy the latest maintenance version for each agent release.
Palo Alto Networks strives to support the latest major operating systems. When a new operating system is available, there may be a short delay in our support as we test interoperability.
Until a Cortex XDR agent release reaches its end-of-life status, the following support is provided:
- Microsoft operating systems are supported for three years beyond the end of Microsoft support.
- In general, other operating systems are supported until they reach end-of-life, or their extended life, as relevant.
- For Android, we support the latest Cortex XDR agent app that is available on the Google Play Store regardless of the app release date. An agent version that is no longer on Google Play will be supported for one year after the date of its release.
Note
The Cortex XDR agents for iOS, Android, 32-bit Windows, and version 7.5-CE agents, are not FedRamp compliant.
Agent releases
To ensure maximum protection of your endpoints, Palo Alto Networks recommends that you always deploy the latest maintenance version for each agent release.
Critical Environment (CE) versions must be enabled in your Cortex system before use. CE versions are designed for sensitive and highly regulated environments. These versions receive full content update coverage and contain the same feature set as the standard line it is based on. Please note, that some bug fixes, introducing higher stability risk, may not be incorporated into the maintenance releases of these lines. Support is provided for CE versions for 24 months, while support for standard versions is provided for 9 months.
See Cortex XDR Agent Releases for details and the release notes of the current agent versions. EOL versions may be shown in this document for information purposes only.
Endpoint operating systems supported
The following tables show the endpoint operating systems on which you can install each release of the Cortex XDR agent. These operating systems are also supported with supported Citrix and VMware virtual applications.
Mac
Supported Mac operating systems
The following Mac operating systems support the Cortex XDR agent.
| Cortex XDR Agent Version | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| <p>macOS 26</p><p>Tahoe</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| <p>macOS 15</p><p>Sequoia</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| <p>macOS 14</p><p>Sonoma</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| <p>macOS 13.X</p><p>Ventura</p> | — | — | ✓ | ✓ | ✓ | ✓ |
| <p>macOS 12.X</p><p>Monterey</p> | — | — | — | — | — | — |
Note
The Cortex Agent for macOS is FedRamp compliant from version 7.6.0 and later for Intel processors only.
Windows
Supported Windows operating systems
The following Windows operating systems support the Cortex XDR agent.
Note
Due to a limitation on Windows Servers, Cortex XDR agent will not register with the Microsoft Security Center.
Install the Cortex XDR agent on unsupported-ACS OS versions
Microsoft Trusted Signing (Azure Code Signing) Directive
Since March 2023, Microsoft request security vendors to sign binaries using Trusted Signing (formerly Azure Code Signing). As a result, Cortex XDR agent versions require a specific Microsoft Windows patch. Note that any machines without this Windows patch are not able to install or upgrade to newer versions of Cortex XDR agent. This mainly impacted Windows machines running Windows 10 or below; Windows 11 machines have this patch pre-installed. Windows 7 machines must have an extended support license in order to install the patch. Additional information about the security patch and the specific patch numbers required per operating system build, KB5022661/KB4474419 . In cases where the Microsoft security patch has since expired, ACS support is achieved by installing cumulative updates after the release of the initial KB patch.
Cortex XDR agent versions later than 8.3-CE will automatically detect an ACS-unsupported OS and allow the installation to complete successfully.
In agent versions 7.9.103-CE and 8.3-CE, to override the default behavior, admin must provide an MSI flag, NO_ACS_SUPPORT=1, as a parameter to the installer. This flag indicates that the installation is to be made on an ACS-unsupported operating system. A fresh installation is needed for using this flag.
Note
The NO_ACS_SUPPORT flag cannot be provided as part of an existing Cortex XDR agent upgrade.
If upgrading from a 7.5-CE release line, even without explicitly providing the installer flag, the installer will detect that ACS is unsupported and will treat the installation as if the flag was given.
Windows 7
Note
Cortex XDR agent 7.9 was the last version to support Windows 7. Release 7.9.103-CE gives extended support until December 31, 2026. No new capabilities will be developed for these OS versions.
| Windows 7 Operating System | 8.0 and later versions | 7.9.103‑CE |
|---|---|---|
| Windows 7 Operating System | 8.0 and later versions | 7.9.103‑CE |
| RTM | — | — |
| <p>Windows 7 SP1</p><p>(All editions except Home)</p> | — | ✓ |
| Embedded Standard 7 SP1 | — | ✓ |
| <p>Embedded POSReady 7</p><p>(Based on Windows 7 SP1)</p> | — | ✓ |
Windows 8
All Windows 8 variants were supported until January 2023 (Microsoft EOL + 3 years). Release 7.9-CE, up to release 7.9.102-CE, offered support for Windows 8.1 until March 19, 2025. No new capabilities will be developed for these OS versions.
The extended-life agent 7.9.103-CE does not support Windows 8.1
Windows 10
The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| 19H2, 20H1, 20H2, 21H1 | — | — | — | — | — | ✓ |
| Threshold LTSB, Redstone LTSB, Redstone 5 LTSB, 21H2, 22H2 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| <p>Windows 10 IoT Core Windows 10 IoT Enterprise</p> |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Windows 11
The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| <p>25H2 x86_64 and ARM</p> |
✓ | ✓ | ✓ | ✓ | ✓ | — |
| <p>24H2 x86_64 and ARM</p> |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| <p>23H2 x86_64 and ARM</p> |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| <p>22H2 x86_64</p> |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Note
Windows running on ARM is subject to certain limitations, see Known limitations in the latest Cortex XDR agent release notes.
Windows Server
The Datacenter edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.
Note
Release 7.9-CE, up to release 7.9.102-CE, was supported Windows Server until March 19, 2025.
The extended-life agent 7.9.103-CE supports Windows Server 2008 R2 SP1 until December 31, 2027.
| Cortex XDR agent | |||||||
|---|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | 7.9.103-CE | |
| 2025 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| 2022 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| 2019 LTSC 2019 Core | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| 2016 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| 2012 (Support until Oct 2027) 2012 R2 (Support until Oct 2027) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| 2012 Core | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| 2008 R2 SP1 | — | — | — | — | — | — | ✓ |
Linux
Supported Linux operating systems
The following Linux operating systems support the Cortex XDR agent.
The Cortex XDR agent protects Linux servers, there are two methods for agent protection; a Kernel module and a user-mode (eBPF-based) approach. To help you choose the best deployment for your environment, see the feature differences between these two modes in the latest Cortex XDR agent Admin guide Broken link.
For the latest Kernel modules support see here.
Note
Cortex XDR agent 9.1 was the last agent release supporting Linux kernels below 3.10. To avoid service disruption, hosts running kernels below 3.10 must not be upgraded beyond the 9.1 agent line. Disable auto-upgrades for endpoint profiles managing those machines, and prevent manual upgrades of the hosts to agent versions later than 9.1
Alibaba Cloud Linux
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| Alibaba Cloud Linux 3 | ✓ | ✓ | ✓ | ✓ | — | — |
AlmaLinux
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| AlmaLinux 10 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| AlmaLinux 9 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| AlmaLinux 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Amazon Linux/Amazon Linux 2/Amazon Linux 2023
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| AMI 2018.03 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Amazon Linux 2 AMI | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Amazon Linux 2 AMI (aarch64) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Amazon Linux 2023 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Amazon Linux 2023 (aarch64) | ✓ | ✓ | ✓ | ✓ | ✓ | — |
Debian
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| Debian 13 (Trixie) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Debian 12 (Bookworm) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Debian 11 (Bullseye) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Debian 10 (Buster) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Debian 10 (Buster) aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Debian 9 (Stretch) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
CentOS
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| CentOS Stream 9 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| CentOS Stream 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| CentOS Stream 8 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| CentOS 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| CentOS 8 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| CentOS 7.9 aarch64 | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported |
| CentOS 7 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| CentOS 6 (6.7 and above) | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ |
Fedora Server
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| Fedora Server (USM only) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
openSUSE
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| openSUSE Leap 16.0 (UM only) | ✓ | ✓ | <p>✓</p><p>From content release 2280-36261</p> | <p>✓</p><p>From content release 2280-36261</p> | — | — |
| openSUSE Leap 15.6 (UM only) | ✓ | ✓ | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> |
| openSUSE Leap 15.3 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| openSUSE Leap 15.2 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| openSUSE Leap 15.1 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Oracle Linux
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| Oracle 10 x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ From content release 1940-22526 |
| Oracle 10 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ From content release 1940-22526 |
| Oracle 9 x86_64 — Release 9.4 and later | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Oracle 9 x86_64 — Release 9.3* | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Oracle 9 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Oracle 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Oracle 8 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Oracle 7 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ |
*Oracle Linux 9.3 x86_64 notes:
| Kernel | Support | Minimum agent version |
|---|---|---|
| RHCK | User mode only | 8.2 |
| UEK | Supported | 7.9-CE |
Red Hat Enterprise Linux
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| RHEL 10 x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| RHEL 10 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| RHEL 9* x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| RHEL 9* aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| RHEL 8 x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| RHEL 8 aarch64 | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported | ✓ User mode agent not supported |
| RHEL 7 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| RHEL 6 (supports 6.7 and above) | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ |
*RHEL 9 requirement
RHEL 9.3 and later requires Cortex XDR agent version 8.2 or later.
Rocky Linux
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| Rocky Linux 10 x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Rocky Linux 9 x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Rocky Linux 9 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Rocky Linux 8 x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
SUSE Linux Enterprise Server
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| Server 16.0 | ✓ | ✓ | <p>✓</p><p>From content release 2280-36261</p> | <p>✓</p><p>From content release 2280-36261</p> | — | — |
| Server 15 SP7 | ✓ | ✓ | ✓ | ✓ | ✓ | <p>✓</p><p>From content release 1940-22526</p> |
| Server 15 SP0-SP6 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Server 12 SP4-SP5 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Server 11 SP4 | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ |
Ubuntu
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| 26.04 LTS x86_64 | ✓ | ✓ | ✓ | ✓ | — | — |
| 26.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | — | — |
| 24.04 LTS x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 24.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 22.04 LTS x86_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 22.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 20.04 LTS | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 20.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 18.04 LTS | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 18.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 16.04 LTS | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 14.04 LTS | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ |
| 12.04 LTS | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ |
Cloud platforms supported with Cortex XDR agent
| Cortex XDR agent | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | |
| Alibaba Cloud | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Amazon Web Services (AWS) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Google Cloud Platform | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| IBM Cloud | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Microsoft Azure | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Oracle Cloud Infrastructure (OCI) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Kubernetes platforms supported
View the Kubernetes platforms that are supported with Cortex XDR agents.
This table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version tested for compatibility are supported.
For installation instructions refer to Cortex XDR Agent for Linux → Install the Cortex XDR Agent for Kubernetes Hosts in the latest Cortex XDR agent admin guide.
| Linux Kubernetes Platform | Version |
|---|---|
| Unmanaged Kubernetes (k8s) | 1.30 |
Amazon Elastic Kubernetes Service (EKS)
| 1.36 |
Microsoft Azure Kubernetes Service (AKS)
| 1.36 |
Google Kubernetes Engine (GKE)
| 1.36 |
| Oracle Kubernetes Engine (OKE) | 1.33 |
Red Hat Openshift Container Platform (OCP)
| 4.18 4.19 in agent versions 9.1.1 and later 4.20 in agent versions 9.1.1 and later |
| SUSE Rancher Kubernetes Engine 2 (RKE2) | 1.28 |
| Talos | 1.8.3 |
Notes
In Google Container-Optimized OS release 100 and earlier, where the FANOTIFY EXEC flag is not supported, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.
In RHCOS version 4.12 and earlier, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.
Virtual applications supported
The following describes the supported software vendors you can use to deploy virtual applications and the minimum software version supported with each release of the Cortex XDR agent.
Citrix
- Citrix Virtual Apps and Desktops (previously XenApp and XenDesktop)—7.xx and later on all Cortex XDR agents.
- Citrix App Layering according to the installation process detailed in the Cortex XDR agent admin guide. Installation on the OS layer: Citrix App 4 and later on all Cortex XDR agents Installation on the Platform layer: Supported from Cortex XDR agent 9.2 and later
VMware
- VMware AppVolumes—2.13.1 & later on all Cortex XDR agents according to the installation process detailed.
- VMware Horizon View—7.8 & later for all Cortex XDR agents.
- VMware ThinApp—5.2.2 & later for all Cortex XDR agents.
Windows
- Windows Virtual PC—Azure Virtual Desktop (WVD or AVD) supported from Cortex XDR agent 7.5 and later.
Mobile operating systems supported with Cortex XDR
The following tables show the mobile operating systems on which you can install each release of the agent. You can install the Cortex XDR agent on Android and iOS, mobile phones and tablets.
Android
| Cortex XDR agent for Android | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1 | 9.0 | 8.9 | 8.8 | |
| 26 | ✓ | ✓ | ✓ | ✓ | — | — |
| 16 | ✓ | ✓ | ✓ | ✓ | — | — |
| 15 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 14 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 13 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 12 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 11 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 10 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 9 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
iOS/iPadOS
Note
The SMS filtering and call blocking features offered by Cortex XDR are available only in iPhones. iPads do not support SMS messaging or cellular-based telephony, even when fitted with a SIM card.
| Cortex XDR agent for iOS | ||||||
|---|---|---|---|---|---|---|
| 9.3 | 9.2 | 9.1 | 9.0 | 8.9 | 8.8 | |
| 26 | ✓ | ✓ | ✓ | ✓ | — | — |
| 16.0 and later | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| 15.0 and later | — | — | — | — | — | — |
Cortex XDR agent compatibility with third-party security products
Review the considerations related to third-party security software integration with Cortex XDR agent software.
This information outlines important considerations regarding the integration of third-party security software with Cortex XDR agent software. The following tables detail the supported security products that can run alongside Cortex XDR, along with their known limitations or the required additional actions to ensure proper integration with Cortex XDR agents.
It is important to note that while other third-party applications may be compatible with Cortex XDR agents, Palo Alto Networks has not conducted compatibility testing on these products. Customers who intend to install such applications alongside Cortex XDR agents are advised to perform thorough internal testing to ensure there are no conflicts or performance issues.
Should you encounter any problems during the integration process with the following third-party security software, please contact your support team for assistance.
Third-party Windows security applications
| Application Name | Limitations |
|---|---|
| CrowdStrike Falcon | Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously. |
| Microsoft Defender | If a Cortex XDR agent is running alongside Microsoft Defender on endpoints running Windows Server editions, we recommend setting Defender to Passive mode. Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously. |
| Trellix McAfee Solidcore/Solidifier | Running exploit protection and Solidcore/Solidifier in parallel is not supported. All other malware protection functionality—such as local analysis, WildFire analysis, and restriction rules—works as expected. Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously. |
| SentinelOne Singularity XDR | Note that there may be performance implications that cannot be predicted due to usage of multiple applications simultaneously. |
Third-party Mac security applications
| Application Name | Limitations |
|---|---|
| Symantec Endpoint Protection (SEP) | Uninstalling or upgrading Cortex XDR agent on Mac endpoints with SEP installed is not supported. |
Third-party Linux security applications
| Application Name | Limitations |
|---|---|
| SELinux | Because SELinux collides with the agent injection mechanism, injection-based security modules (ROP Mitigation and Brute Force Protection) are disabled when SELinux is enabled. All other exploit and malware protection functionality works as expected. No user action is required. |
| Symantec | Running Symantec Kernel Module on Linux machines side by side with Cortex XDR is not supported. |
| McAfee | Running McAfee Kernel Module on Linux machines side by side with Cortex XDR will lead to the Cortex XDR agent running without the Kernel Module and be partially protected. It is recommended to have the McAfee KM disabled. |