<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question regarding random Decryption when using Cortex XDR in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-regarding-random-decryption-when-using-cortex-xdr/m-p/567181#M5627</link>
    <description>&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;Wanted to ask if any of you had something similar happening around.&lt;BR /&gt;&lt;BR /&gt;Scenario :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;2 systems (just as an example, as they are more) - 1 of the systems gets decrypted after a system update was done (BIOS, driver updates etc.) , the other system does not get decrypted for the same updates, instead the BitLocker suspends itself and after the upgrade is done, it 'resumes' itself (which in my opinion is the correct expectation). This information I get from Event Viewer (sadly I can't see what the decryption issue is there, neither can I see it in the traps logs).&lt;BR /&gt;&lt;BR /&gt;Both of the systems are using the same encryption profile from Cortex, both of the systems are using the same GPO configuration that pushes Cortex BitLocker encryption.&lt;BR /&gt;&lt;BR /&gt;At first I though it might be related to no AD connectivity prior to the upgrade initiation, but this was false, I checked if Secure boot might cause it, but this was also false. Both of the systems are using UEFI.&lt;BR /&gt;&lt;BR /&gt;Anybody got any idea what specs/configs I need to check/compare for those systems that decrypt and those that do not?&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 10:33:09 GMT</pubDate>
    <dc:creator>milen.slavov</dc:creator>
    <dc:date>2023-11-27T10:33:09Z</dc:date>
    <item>
      <title>Question regarding random Decryption when using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-regarding-random-decryption-when-using-cortex-xdr/m-p/567181#M5627</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;&lt;BR /&gt;Wanted to ask if any of you had something similar happening around.&lt;BR /&gt;&lt;BR /&gt;Scenario :&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;2 systems (just as an example, as they are more) - 1 of the systems gets decrypted after a system update was done (BIOS, driver updates etc.) , the other system does not get decrypted for the same updates, instead the BitLocker suspends itself and after the upgrade is done, it 'resumes' itself (which in my opinion is the correct expectation). This information I get from Event Viewer (sadly I can't see what the decryption issue is there, neither can I see it in the traps logs).&lt;BR /&gt;&lt;BR /&gt;Both of the systems are using the same encryption profile from Cortex, both of the systems are using the same GPO configuration that pushes Cortex BitLocker encryption.&lt;BR /&gt;&lt;BR /&gt;At first I though it might be related to no AD connectivity prior to the upgrade initiation, but this was false, I checked if Secure boot might cause it, but this was also false. Both of the systems are using UEFI.&lt;BR /&gt;&lt;BR /&gt;Anybody got any idea what specs/configs I need to check/compare for those systems that decrypt and those that do not?&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 10:33:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-regarding-random-decryption-when-using-cortex-xdr/m-p/567181#M5627</guid>
      <dc:creator>milen.slavov</dc:creator>
      <dc:date>2023-11-27T10:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding random Decryption when using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-regarding-random-decryption-when-using-cortex-xdr/m-p/567796#M5640</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280873"&gt;@milen.slavov&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out through LIVEcommunity!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After reading your issues I'd highly suggest creating a support ticket and having our TAC engineers take a look into this issue.&amp;nbsp; Digging deeper into this issue to provide you with useful information is going to require you to upload some logs in order to gather more information.&amp;nbsp;&amp;nbsp;A support case can be created &lt;A href="https://support.paloaltonetworks.com/Support/Index" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you find this information helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 15:28:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-regarding-random-decryption-when-using-cortex-xdr/m-p/567796#M5640</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-11-30T15:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding random Decryption when using Cortex XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-regarding-random-decryption-when-using-cortex-xdr/m-p/567797#M5641</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Milen.Slavov,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please ensure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;the endpoint is AD connected and that an AD DS role is installed on the endpoint.&lt;/LI&gt;
&lt;LI&gt;Cortex XDR disk encryption policy does not conflict with the GPO configuration to Choose drive encryption method and cipher strength. Reference&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Disk-Encryption" target="_blank"&gt;Disk Encryption • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please open a &lt;A href="https://live.paloaltonetworks.com/t5/community-blogs/opening-a-new-support-case-in-the-customer-support-portal-csp/ba-p/284277" target="_self"&gt;support case&lt;/A&gt; for analysis.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 15:35:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/question-regarding-random-decryption-when-using-cortex-xdr/m-p/567797#M5641</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2023-11-30T15:35:00Z</dc:date>
    </item>
  </channel>
</rss>

