Documentation — August 11, 2026
314 files changed, 354 insertions, 437 deletions — view the commit on the mirror.
Marketplace links restored on 296 data-source pages; Cloud Application Security rewritten with licensing
- 296 XSIAM data-source connector pages turned a plain-text Marketplace mention into a working link — the bulk of the day, and the only change on those pages.
- Cortex Cloud Application Security was rewritten around three use cases and now states which base licence each one needs.
- Nine Cortex XDR agent pages replaced their markdown tables with raw HTML, and several console names picked up bold.
- Outbound links in the agent guide moved from
docs-cortex.paloaltonetworks.comtoapp.gitbook.comspaces. - Nothing was added, deleted or renamed: all 316 files were modifications.
Highlights
-
Cortex Cloud Application Security now states its licence requirements
ASPM and Supply Chain Security are included with a Cloud Posture, Cloud Runtime or XSIAM Premium base licence, while Code Security requires a separate Application Security add-on purchase.
-
296 data-source pages gained a working Marketplace link
The notice that a connector is only available to tenants onboarded after July 26, 2026 now links "Marketplace" to ../../marketplace instead of naming it in plain text.
-
The agent guide's compatibility and release links now point at GitBook
Both references on the agent introduction moved from docs-cortex.paloaltonetworks.com to app.gitbook.com space URLs, and the Mac uninstall page gained a GitBook link where it previously had bare text.
-
The Azure BYOA security note was reframed from a statement of fact into a least-privilege claim
"BYOA grants the Terraform runner zero tenant-level Microsoft Graph permissions" became "BYOA mode leverages a least-privilege security model"; the mechanism described — write access through direct object ownership — is unchanged.
-
Requirements and cytool reference tables became raw HTML
Nine Cortex XDR agent pages swapped markdown pipe tables for <table> markup, which shows as a large deletion count against a single added line without any content changing.
-
The ITDR Conditional Access link was resolved out of broken-reference
It now points at the get-started-with-itdr#set-up-identity-profiles anchor, though the link text was split so only "Set up an Identity" is linked and "profile" trails outside it.
Changes
314 files listed, 15 written up and shaded below.
-
▸ ▾ Versa Networks modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/versa-networks/versa-networksRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Versa Networks# Versa Networkshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Versa Director is a virtualization and service creation platform that simplifies the design, automation, and delivery of SASE services. It provides the management, monitoring, and orchestration capabilities needed to deliver the networking and security capabilities within Versa SASE.Versa Director is a virtualization and service creation platform that simplifies the design, automation, and delivery of SASE services. It provides the management, monitoring, and orchestration capabilities needed to deliver the networking and security capabilities within Versa SASE.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Versa Networks {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Versa Director is a virtualization and service creation platform that simplifies the design, automation, and delivery of SASE services. It provides the management, monitoring, and orchestration capabilities needed to deliver the networking and security capabilities within Versa SASE. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ VMware Automation and Colection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vmware/vmware-automation-and-colectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# VMware Automation and Colection# VMware Automation and Colectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Manage VMware products: administer virtual machines and ESXi hosts through vCenter, hunt and respond to endpoint threats with Carbon Black EDR, and search and manage enrolled devices with Workspace ONE UEM (AirWatch MDM).Manage VMware products: administer virtual machines and ESXi hosts through vCenter, hunt and respond to endpoint threats with Carbon Black EDR, and search and manage enrolled devices with Workspace ONE UEM (AirWatch MDM).This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # VMware Automation and Colection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Manage VMware products: administer virtual machines and ESXi hosts through vCenter, hunt and respond to endpoint threats with Carbon Black EDR, and search and manage enrolled devices with Workspace ONE UEM (AirWatch MDM). This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ VulnDB modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vulndb/vulndbRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# VulnDB# VulnDBhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Use the VulnDB integration to get information about security vulnerabilities for various products, including operating systems and applications.Use the VulnDB integration to get information about security vulnerabilities for various products, including operating systems and applications.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # VulnDB {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Use the VulnDB integration to get information about security vulnerabilities for various products, including operating systems and applications. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ WhatsMyBrowser.org modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/whatsmybrowser.org/whatsmybrowser.orgRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# WhatsMyBrowser.org# WhatsMyBrowser.orghint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.The User Agent Parse API from WhatIsMyBrowser lets you send a User Agent String and receive a detailed response describing as much as possible about the string. WhatIsMyBrowser parses user agent strings and gives insight into known user agents, including whether a user agent string is known to be malicious.The User Agent Parse API from WhatIsMyBrowser lets you send a User Agent String and receive a detailed response describing as much as possible about the string. WhatIsMyBrowser parses user agent strings and gives insight into known user agents, including whether a user agent string is known to be malicious.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # WhatsMyBrowser.org {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. The User Agent Parse API from WhatIsMyBrowser lets you send a User Agent String and receive a detailed response describing as much as possible about the string. WhatIsMyBrowser parses user agent strings and gives insight into known user agents, including whether a user agent string is known to be malicious. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Whois modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/whois/whoisRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Whois# Whoishint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Whois is an open source tool and protocol for querying details about a domain, including the registrant that owns the domain name, the registrar who registered it, the creation date, and other domain metadata. Use the Whois integration to get enriched data for domains and IPs.Whois is an open source tool and protocol for querying details about a domain, including the registrant that owns the domain name, the registrar who registered it, the creation date, and other domain metadata. Use the Whois integration to get enriched data for domains and IPs.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Whois {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Whois is an open source tool and protocol for querying details about a domain, including the registrant that owns the domain name, the registrar who registered it, the creation date, and other domain metadata. Use the Whois integration to get enriched data for domains and IPs. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ WithSecure modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/withsecure/withsecureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# WithSecure# WithSecurehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.WithSecure Endpoint Protection is a cloud-based platform that provides effective endpoint protection against ransomware and advanced attacks.WithSecure Endpoint Protection is a cloud-based platform that provides effective endpoint protection against ransomware and advanced attacks.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # WithSecure {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. WithSecure Endpoint Protection is a cloud-based platform that provides effective endpoint protection against ransomware and advanced attacks. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Workday Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workday/workday-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Workday Automation and Collection# Workday Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintWorkday offers enterprise-level software solutions for financial management, human resources, and planning. Automate actions in Workday, fetch Workday reports to create corresponding issues as part of identity lifecycle management, and collect user activity and sign-on events from Workday.Workday offers enterprise-level software solutions for financial management, human resources, and planning. Automate actions in Workday, fetch Workday reports to create corresponding issues as part of identity lifecycle management, and collect user activity and sign-on events from Workday.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Workday: Workday offers enterprise-level software solutions for financial management, human resources, and planning. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.• Workday: Workday offers enterprise-level software solutions for financial management, human resources, and planning. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license.• Workday Event Collector: Use Workday Event Collector integration to get activity loggings from Workday. This sub-capability is available with any active Cortex XSIAM license.• Workday Event Collector: Use Workday Event Collector integration to get activity loggings from Workday. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -1,14 +1,14 @@ # Workday Automation and Collection {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Workday offers enterprise-level software solutions for financial management, human resources, and planning. Automate actions in Workday, fetch Workday reports to create corresponding issues as part of identity lifecycle management, and collect user activity and sign-on events from Workday. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Workday](https://xsoar.pan.dev/docs/reference/integrations/workday): Workday offers enterprise-level software solutions for financial management, human resources, and planning. This sub-capability is available with any active Cortex XSIAM, Cortex Cloud Posture Security, or Cortex AgentiX license. * [Workday Event Collector](https://xsoar.pan.dev/docs/reference/integrations/workday-event-collector): Use Workday Event Collector integration to get activity loggings from Workday. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ X Automation and Remediation modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/x/x-automation-and-remediationRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# X Automation and Remediation# X Automation and Remediationhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.The Twitter (X) integration enables cybersecurity researchers and SOC teams to harness Twitter to enhance their security operations, providing access to searching recent Tweets (within the last 7 days) and user information using the Twitter v2 API. Teams can automate searching to detect potential threats, gather intelligence on cyber attacks, monitor brand reputation, track threat actors, and detect fraudulent accounts impersonating their company.The Twitter (X) integration enables cybersecurity researchers and SOC teams to harness Twitter to enhance their security operations, providing access to searching recent Tweets (within the last 7 days) and user information using the Twitter v2 API. Teams can automate searching to detect potential threats, gather intelligence on cyber attacks, monitor brand reputation, track threat actors, and detect fraudulent accounts impersonating their company.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # X Automation and Remediation {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. The Twitter (X) integration enables cybersecurity researchers and SOC teams to harness Twitter to enhance their security operations, providing access to searching recent Tweets (within the last 7 days) and user information using the Twitter v2 API. Teams can automate searching to detect potential threats, gather intelligence on cyber attacks, monitor brand reputation, track threat actors, and detect fraudulent accounts impersonating their company. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Zendesk modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zendesk/zendeskRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Zendesk# Zendeskhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license.Integrate with Zendesk to perform operations related to users, tickets, attachments, and more. Search and query users or tickets, create and update tickets, retrieve ticket details including comments and attachments, add comments, and manage Zendesk users to streamline customer support and issue management workflows.Integrate with Zendesk to perform operations related to users, tickets, attachments, and more. Search and query users or tickets, create and update tickets, retrieve ticket details including comments and attachments, add comments, and manage Zendesk users to streamline customer support and issue management workflows.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Zendesk {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM, Cortex Cloud, Cortex Cloud Runtime Security, Cortex XDR, or Cortex AgentiX license. Integrate with Zendesk to perform operations related to users, tickets, attachments, and more. Search and query users or tickets, create and update tickets, retrieve ticket details including comments and attachments, add comments, and manage Zendesk users to streamline customer support and issue management workflows. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Zero Networks modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zero-networks/zero-networksRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Zero Networks# Zero Networkshint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM license.This sub-capability is available with any active Cortex XSIAM license.Zero Networks Segment is a security platform that automatically enforces zero trust policies across an organization's network. It dynamically segments and controls access to network resources, ensuring that only authorized users and devices can communicate, thereby reducing the attack surface and mitigating potential threats.Zero Networks Segment is a security platform that automatically enforces zero trust policies across an organization's network. It dynamically segments and controls access to network resources, ensuring that only authorized users and devices can communicate, thereby reducing the attack surface and mitigating potential threats.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Zero Networks {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM license. Zero Networks Segment is a security platform that automatically enforces zero trust policies across an organization's network. It dynamically segments and controls access to network resources, ensuring that only authorized users and devices can communicate, thereby reducing the attack surface and mitigating potential threats. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Zimperium modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zimperium/zimperiumRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Zimperium# Zimperiumhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintThis sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Zimperium is a mobile security platform that generates alerts based on anomalous or unauthorized activities detected on a user's mobile device. Fetch and investigate mobile security alerts, and query for events, devices, and users.Zimperium is a mobile security platform that generates alerts based on anomalous or unauthorized activities detected on a user's mobile device. Fetch and investigate mobile security alerts, and query for events, devices, and users.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):Show markdown source
@@ -1,14 +1,14 @@ # Zimperium {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. Zimperium is a mobile security platform that generates alerts based on anomalous or unauthorized activities detected on a user's mobile device. Fetch and investigate mobile security alerts, and query for events, devices, and users. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): -
▸ ▾ Zoom modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zoom/zoomRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Zoom# Zoomhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintZoom lets users create and join virtual meeting rooms to communicate over video and audio, share screens and files, and chat. This connector manages Zoom users and meetings, provisions users via IAM, collects operation logs and activity reports, interacts with the Zoom Mail API, and fetches Zoom endpoint IP ranges as an indicator feed.Zoom lets users create and join virtual meeting rooms to communicate over video and audio, share screens and files, and chat. This connector manages Zoom users and meetings, provisions users via IAM, collects operation logs and activity reports, interacts with the Zoom Mail API, and fetches Zoom endpoint IP ranges as an indicator feed.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• Zoom: Use the Zoom integration to manage your Zoom users and meetings. This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.• Zoom: Use the Zoom integration to manage your Zoom users and meetings. This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Zoom {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Zoom lets users create and join virtual meeting rooms to communicate over video and audio, share screens and files, and chat. This connector manages Zoom users and meetings, provisions users via IAM, collects operation logs and activity reports, interacts with the Zoom Mail API, and fetches Zoom endpoint IP ranges as an indicator feed. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [Zoom](https://xsoar.pan.dev/docs/reference/integrations/zoom): Use the Zoom integration to manage your Zoom users and meetings. This sub-capability is available with any active Cortex XSIAM, Cortex XDR, or Cortex AgentiX license. * [Zoom Feed](https://xsoar.pan.dev/docs/reference/integrations/zoom-feed): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Zscaler modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscaler/zscalerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,14 @@# Zscaler# Zscalerhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintZscaler is a cloud security solution built for performance and flexible scalability. This connector manages URL and IP address allow lists and block lists, categories, IP destination groups, and Sandbox reports, and it can also collect Zscaler Internet Access (ZIA) logs. It includes Red Canary, which collects and standardizes endpoint data to help teams detect, analyze, and respond to security issues.Zscaler is a cloud security solution built for performance and flexible scalability. This connector manages URL and IP address allow lists and block lists, categories, IP destination groups, and Sandbox reports, and it can also collect Zscaler Internet Access (ZIA) logs. It includes Red Canary, which collects and standardizes endpoint data to help teams detect, analyze, and respond to security issues.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• RedCanary: Red Canary collects endpoint data using Carbon Black Response and CrowdStrike Falcon. The collected data is standardized into a common schema which allows teams to detect, analyze and respond to security incidents. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• RedCanary: Red Canary collects endpoint data using Carbon Black Response and CrowdStrike Falcon. The collected data is standardized into a common schema which allows teams to detect, analyze and respond to security incidents. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Zscaler: Zscaler is a cloud security solution built for performance and flexible scalability. This integration enables you to manage URL and IP address allow lists and block lists, manage and update categories, get Sandbox reports, create, manage, and update IP destination groups and manually log in, log out, and activate changes in a Zscaler session. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Zscaler: Zscaler is a cloud security solution built for performance and flexible scalability. This integration enables you to manage URL and IP address allow lists and block lists, manage and update categories, get Sandbox reports, create, manage, and update IP destination groups and manually log in, log out, and activate changes in a Zscaler session. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.Show markdown source
@@ -1,14 +1,14 @@ # Zscaler {% hint style="warning" %} **Important** -This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. +This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} Zscaler is a cloud security solution built for performance and flexible scalability. This connector manages URL and IP address allow lists and block lists, categories, IP destination groups, and Sandbox reports, and it can also collect Zscaler Internet Access (ZIA) logs. It includes Red Canary, which collects and standardizes endpoint data to help teams detect, analyze, and respond to security issues. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [RedCanary](https://xsoar.pan.dev/docs/reference/integrations/red-canary): Red Canary collects endpoint data using Carbon Black Response and CrowdStrike Falcon. The collected data is standardized into a common schema which allows teams to detect, analyze and respond to security incidents. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Zscaler](https://xsoar.pan.dev/docs/reference/integrations/zscaler): Zscaler is a cloud security solution built for performance and flexible scalability. This integration enables you to manage URL and IP address allow lists and block lists, manage and update categories, get Sandbox reports, create, manage, and update IP destination groups and manually log in, log out, and activate changes in a Zscaler session. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -
▸ ▾ Enforce dynamic access control with CAP modified +1 −1 The Set up an Identity profile link resolves to the ITDR getting-started anchor instead of broken-reference.
xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/conditional-access-policyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -64,17 +64,17 @@ Conditional Access Policy follows a three-phase workflow:Access the Conditional Access Policy page under Modules → Identity Security → Conditional AccessAccess the Conditional Access Policy page under Modules → Identity Security → Conditional Access## Deploy and configure the Conditional Access Policy## Deploy and configure the Conditional Access PolicyConfigure your identity profiles, create and manage context-driven access rules, and analyze authentication results through centralized identity access logs.Configure your identity profiles, create and manage context-driven access rules, and analyze authentication results through centralized identity access logs.### Configure an Identity profile### Configure an Identity profileUse the toggle in Set up an Identity profile to enable or disable the Conditional Access policy .Use the toggle in Set up an Identity profile to enable or disable the Conditional Access policy .Important: To activate the engine, you must enable the Conditional Access Policy (CAP) feature flag and configure its specific system parameters within the Identity Profile settings. These global configurations determine how the underlying agent handles authentication interception and structural service errors across your domain.Important: To activate the engine, you must enable the Conditional Access Policy (CAP) feature flag and configure its specific system parameters within the Identity Profile settings. These global configurations determine how the underlying agent handles authentication interception and structural service errors across your domain.### Create a Conditional Access Policy rule### Create a Conditional Access Policy ruleDefine a new rule to control access based on contextual conditions. Your entire policy can contain a maximum of 20 rules.Define a new rule to control access based on contextual conditions. Your entire policy can contain a maximum of 20 rules.1. Go to Modules → Identity Security → Conditional Access → Rules.1. Go to Modules → Identity Security → Conditional Access → Rules.Show markdown source
@@ -64,17 +64,17 @@ Conditional Access Policy follows a three-phase workflow: Access the Conditional Access Policy page under **Modules** → **Identity Security** → **Conditional Access** ## **Deploy and configure the Conditional Access Policy** Configure your identity profiles, create and manage context-driven access rules, and analyze authentication results through centralized identity access logs. ### **Configure an Identity profile** -Use the toggle in [Set up an Identity profile](broken-reference) to enable or disable the Conditional Access policy . +Use the toggle in [Set up an Identity](../get-started-with-itdr#set-up-identity-profiles) profile to enable or disable the Conditional Access policy . **Important:** To activate the engine, you must enable the Conditional Access Policy (CAP) feature flag and configure its specific system parameters within the Identity Profile settings. These global configurations determine how the underlying agent handles authentication interception and structural service errors across your domain. ### **Create a Conditional Access Policy rule** Define a new rule to control access based on contextual conditions. Your entire policy can contain a maximum of 20 rules. 1. Go to **Modules** → **Identity Security** → **Conditional Access** → **Rules.**