<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabled Capabilities of XDR on instaallation in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/disabled-capabilities-of-xdr-on-instaallation/m-p/598310#M7201</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your reply. The ways to disable and monitor the capabilities are clear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is they were not disabled during or after the installation. "After" is confirmed once more over the Audit Logs. For "During" the customer says they have not disabled it during installation using any flags or so.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thats why I asked if anyone else has experienced sth similar.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2024 15:33:43 GMT</pubDate>
    <dc:creator>AbdBgc</dc:creator>
    <dc:date>2024-09-19T15:33:43Z</dc:date>
    <item>
      <title>Disabled Capabilities of XDR on instaallation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/disabled-capabilities-of-xdr-on-instaallation/m-p/597980#M7187</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in one of our customers with the installation of XDR agent version 8.5 the Response Capabilities (&lt;SPAN&gt;File Retrieval, Live Terminal, Script Execution&lt;/SPAN&gt;) were disabled from the very beginning on many of the endpoints. As there is no other way, the agents were uninstalled and reinstalled as a solution. But we could not identify the main reason. Eventhough they did not change anything on the installation process they dont have the problem with the new installation now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What could the reason be? Has anyone experienced sth similar?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for your answers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 07:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/disabled-capabilities-of-xdr-on-instaallation/m-p/597980#M7187</guid>
      <dc:creator>AbdBgc</dc:creator>
      <dc:date>2024-09-17T07:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Capabilities of XDR on instaallation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/disabled-capabilities-of-xdr-on-instaallation/m-p/598023#M7195</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/487095937"&gt;@AbdBgc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;There are two ways to disable these XDR capabilities. One is by setting specific flags in msiexec command line during installation. Second is from XDR tenant, by going to specific endpoint in all endpoints then right click -&amp;gt; Endpoint control -&amp;gt; Disable capabilities.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If flags were not set during installation then someone must have disabled capabilities from XDR tenant. You can monitor this activity in management audit logs with type "Response" and sub type "disable capability".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 16:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/disabled-capabilities-of-xdr-on-instaallation/m-p/598023#M7195</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2024-09-17T16:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Capabilities of XDR on instaallation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/disabled-capabilities-of-xdr-on-instaallation/m-p/598310#M7201</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your reply. The ways to disable and monitor the capabilities are clear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is they were not disabled during or after the installation. "After" is confirmed once more over the Audit Logs. For "During" the customer says they have not disabled it during installation using any flags or so.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thats why I asked if anyone else has experienced sth similar.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 15:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/disabled-capabilities-of-xdr-on-instaallation/m-p/598310#M7201</guid>
      <dc:creator>AbdBgc</dc:creator>
      <dc:date>2024-09-19T15:33:43Z</dc:date>
    </item>
  </channel>
</rss>

