<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XDR Capabilities in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-capabilities/m-p/566615#M5589</link>
    <description>&lt;P&gt;Does XDR has the capability to identify and block admin access on end user workstation?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2023 05:21:01 GMT</pubDate>
    <dc:creator>RamyashreeMada</dc:creator>
    <dc:date>2023-11-22T05:21:01Z</dc:date>
    <item>
      <title>XDR Capabilities</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-capabilities/m-p/566615#M5589</link>
      <description>&lt;P&gt;Does XDR has the capability to identify and block admin access on end user workstation?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 05:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-capabilities/m-p/566615#M5589</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-11-22T05:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Capabilities</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-capabilities/m-p/566906#M5598</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on Live Community!&lt;/P&gt;
&lt;P&gt;Unfortunately XDR do not control the access for endpoint users. It can prevent malicious activity but cannot control user's access directly. You can use "User risk view" to investigate and assess user behaviour.&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN&gt;With the&amp;nbsp;&lt;SPAN class="proto-highlight"&gt;User&lt;/SPAN&gt;&amp;nbsp;Risk view, you can do the following.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="itemizedlist"&gt;
&lt;UL class="itemizedlist"&gt;
&lt;LI class="listitem"&gt;
&lt;P class=""&gt;&lt;SPAN&gt;Assess the&amp;nbsp;&lt;SPAN class="proto-highlight"&gt;user&lt;/SPAN&gt;'s behavior and score.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P class=""&gt;&lt;SPAN&gt;Review the&amp;nbsp;&lt;SPAN class="proto-highlight"&gt;user&lt;/SPAN&gt;'s working hours and past alerts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P class=""&gt;&lt;SPAN&gt;Analyze the&amp;nbsp;&lt;SPAN class="proto-highlight"&gt;user&lt;/SPAN&gt;'s behavior over time and compare to their peers with the same asset role.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listitem"&gt;
&lt;P class=""&gt;&lt;SPAN&gt;Star the&amp;nbsp;&lt;SPAN class="proto-highlight"&gt;user&lt;/SPAN&gt;&amp;nbsp;to be included in the watchlist.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Please follow below guide to learn more about investigating a user.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Investigate-a-User" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Investigate-a-User&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 23 Nov 2023 16:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-capabilities/m-p/566906#M5598</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-11-23T16:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: XDR Capabilities</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-capabilities/m-p/567221#M5608</link>
      <description>&lt;P&gt;There are a bunch of solutions that "block" admin access on endpoints. Most of them overtakes the normal Admin account and then provides granular access to all other accounts stripping them for any admin rights and then you can make an approval workflow on a per app basis or for a limited time. There will be a lot of functionality that comes along with those solutions. Often software/inventory management and 3rd party application updates are some of them.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:28:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-capabilities/m-p/567221#M5608</guid>
      <dc:creator>Clausj</dc:creator>
      <dc:date>2023-11-27T14:28:13Z</dc:date>
    </item>
  </channel>
</rss>

