<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Feature Request: The ability to automatically quarantine hosts where the Agents are not up to a specific version (Ideally N-1,2) in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/feature-request-the-ability-to-automatically-quarantine-hosts/m-p/515645#M2865</link>
    <description>&lt;P&gt;I believe that right now, the only way to do this would be from the action center and&amp;nbsp;filter via Agent Version and manually quarantine each host that is on an EOL agent version that didnt get auto-upgraded.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cant seem to find anything on this from a policy perspective side of things unless I'm looking in the wrong spot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Sep 2022 20:39:41 GMT</pubDate>
    <dc:creator>DanCartaginese</dc:creator>
    <dc:date>2022-09-21T20:39:41Z</dc:date>
    <item>
      <title>Feature Request: The ability to automatically quarantine hosts where the Agents are not up to a specific version (Ideally N-1,2)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/feature-request-the-ability-to-automatically-quarantine-hosts/m-p/515645#M2865</link>
      <description>&lt;P&gt;I believe that right now, the only way to do this would be from the action center and&amp;nbsp;filter via Agent Version and manually quarantine each host that is on an EOL agent version that didnt get auto-upgraded.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cant seem to find anything on this from a policy perspective side of things unless I'm looking in the wrong spot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 20:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/feature-request-the-ability-to-automatically-quarantine-hosts/m-p/515645#M2865</guid>
      <dc:creator>DanCartaginese</dc:creator>
      <dc:date>2022-09-21T20:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Feature Request: The ability to automatically quarantine hosts where the Agents are not up to a specific version (Ideally N-1,2)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/feature-request-the-ability-to-automatically-quarantine-hosts/m-p/515662#M2867</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/189928"&gt;@DanCartaginese&lt;/a&gt;&amp;nbsp;there's no way to manually do that within the console as of date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What you can do using automation is:&lt;/P&gt;
&lt;P&gt;A) have the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/endpoint-management/get-all-endpoints" target="_self"&gt;Endpoints API&lt;/A&gt; retrieve the agent version for all endpoints and then isolate those specific endpoints with the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/response-actions/isolate-endpoints#id3e69cbf2-7fd9-4fd4-aa5c-9fd3813aa5e4" target="_self"&gt;Isolate API&lt;/A&gt;. You'd have to wrap it with a timer to run periodically.&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;B) have a policy that identifies endpoints that need to be upgraded (say anything &amp;lt;v7.7) and upgrade them to the latest version. This is my preferred recommendation as this ensures that the endpoints are always picked up and upgraded in case they fall through the cracks. Furthermore, use that information in a report that gets emailed on a weekly basis for any endpoints that are EOL to investigate and manually intervene, if necessary.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 07:11:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/feature-request-the-ability-to-automatically-quarantine-hosts/m-p/515662#M2867</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-09-22T07:11:00Z</dc:date>
    </item>
  </channel>
</rss>

