<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Preventing CrowdStrike disaster in Cortex XDR Pro in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/595328#M7093</link>
    <description>&lt;P&gt;To prevent issues similar to CrowdStrike, we can utilize the delay auto updates configuration mechanism available on the PANW Cortex XDR platform console:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;using agent One release before the latest one. This method ensures that the auto upgrade of the PANW Cortex XDR agent version will be done to one version before the last available version (General Availability), where at least the PANW Cortex XDR agent version that will be used for auto upgrade deployment has been released about 3 months earlier. So this configuration is sufficient to prevent similar issues if the cause is due to the PANW Cortex XDR agent version upgrade.&lt;/LI&gt;
&lt;LI&gt;By default, the PANW Cortex XDR agent version auto upgrade will be done per phase rollout (not a big bang to all PANW Cortex XDR agents on laptops and PCs) where by default only up to 500 PANW Cortex XDR agent versions will be auto upgraded per phase each week according to the number entered into the Amount Of Parallel Upgrades configuration. In addition, the auto upgrade process can also be selected for a specific day and specific time range that can be selected by the customer. Suggested that the auto upgrade can be selected on a specific day and time range where it can standby at that time if there are problems caused by the PANW Cortex XDR agent version upgrade.&lt;/LI&gt;
&lt;LI&gt;By default, the content update configuration is Auto Update and Immediate. To increase the prevention of similar problems if the cause is due to the content update version, you can add a delayed configuration where the number of days of delay can be adjusted as needed. Not recommend that the content update version be delayed for a long time (for example more than 5 days), so that the PANW Cortex XDR agent version can get the new protection coverage available in the new content update version.&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Tue, 20 Aug 2024 07:26:57 GMT</pubDate>
    <dc:creator>Bisma_Verdya</dc:creator>
    <dc:date>2024-08-20T07:26:57Z</dc:date>
    <item>
      <title>Preventing CrowdStrike disaster in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592570#M6958</link>
      <description>&lt;P&gt;Hello dear community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what could we or PA setup in PA Cortex XDR to prevent us from such a disaster which happened to CrowdStrike?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any settings or recommendations which can be shared?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 16:47:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592570#M6958</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2024-07-19T16:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing CrowdStrike disaster in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592615#M6964</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;What I recommend, and what I have implemented in my XDR, is the agents only perform auto-updates after 7 days (on settings you can see agent upgrade). &lt;BR /&gt;If there is an urgent update, I go to the tenant and force all devices to upgrade.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;This way, the risk of problematic software is reduced.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 09:05:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592615#M6964</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-07-22T09:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing CrowdStrike disaster in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592621#M6965</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;In a case like CrowdStrike's last week, this approach doesn't solve the issue. The faulty update was caused by a content update and not an agent update.&amp;nbsp;However, you thankfully have the option with Cortex XDR to delay content updates through agent settings profile:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Add-a-New-Agent-Settings-Profile" target="_blank" rel="noopener"&gt;Add a New Agent Settings Profile • Cortex XDR Prevent Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We deploy content updates on 10% of the endpoints immediately and delay the remaining 90% for 2 days to make sure our business is not paralyzed by a faulty update.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 09:44:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592621#M6965</guid>
      <dc:creator>Rocky-25</dc:creator>
      <dc:date>2024-07-22T09:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing CrowdStrike disaster in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592624#M6967</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/282330491"&gt;@Rocky-25&lt;/a&gt;&amp;nbsp;, thanks&amp;nbsp;for correction.&lt;BR /&gt;I've say agent only, but our rule is apply for both options (agent and content).&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 10:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/592624#M6967</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-07-22T10:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing CrowdStrike disaster in Cortex XDR Pro</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/595328#M7093</link>
      <description>&lt;P&gt;To prevent issues similar to CrowdStrike, we can utilize the delay auto updates configuration mechanism available on the PANW Cortex XDR platform console:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;using agent One release before the latest one. This method ensures that the auto upgrade of the PANW Cortex XDR agent version will be done to one version before the last available version (General Availability), where at least the PANW Cortex XDR agent version that will be used for auto upgrade deployment has been released about 3 months earlier. So this configuration is sufficient to prevent similar issues if the cause is due to the PANW Cortex XDR agent version upgrade.&lt;/LI&gt;
&lt;LI&gt;By default, the PANW Cortex XDR agent version auto upgrade will be done per phase rollout (not a big bang to all PANW Cortex XDR agents on laptops and PCs) where by default only up to 500 PANW Cortex XDR agent versions will be auto upgraded per phase each week according to the number entered into the Amount Of Parallel Upgrades configuration. In addition, the auto upgrade process can also be selected for a specific day and specific time range that can be selected by the customer. Suggested that the auto upgrade can be selected on a specific day and time range where it can standby at that time if there are problems caused by the PANW Cortex XDR agent version upgrade.&lt;/LI&gt;
&lt;LI&gt;By default, the content update configuration is Auto Update and Immediate. To increase the prevention of similar problems if the cause is due to the content update version, you can add a delayed configuration where the number of days of delay can be adjusted as needed. Not recommend that the content update version be delayed for a long time (for example more than 5 days), so that the PANW Cortex XDR agent version can get the new protection coverage available in the new content update version.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 20 Aug 2024 07:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/preventing-crowdstrike-disaster-in-cortex-xdr-pro/m-p/595328#M7093</guid>
      <dc:creator>Bisma_Verdya</dc:creator>
      <dc:date>2024-08-20T07:26:57Z</dc:date>
    </item>
  </channel>
</rss>

