<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR along with Defender for endpoint Compatibility in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-with-defender-for-endpoint-compatibility/m-p/1225482#M8173</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Does anyone have a list of guidelines to follow when running cortex xdr (Report mode) in parallel with defender (active mode) for workstations as well as servers? Do i need to do any exclusions/whitelisting? Do I need to disable any features in XDR to prevent issues?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In xdr compatibility matrix&amp;nbsp;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Cortex-XDR-agent-compatibility-with-third-party-security-products" target="_blank" rel="noopener nofollow ugc"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Cortex-XDR-agent-compatibility-with-third-party-security-products&lt;/A&gt;&amp;nbsp;you can see it mentions defender and emet separately but if emet like features are present in defender (exploit protection features), running exploit protection in both xdr and defender for endpoint should not work as well correct?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2025 17:49:43 GMT</pubDate>
    <dc:creator>bridgetlitt</dc:creator>
    <dc:date>2025-04-02T17:49:43Z</dc:date>
    <item>
      <title>Cortex XDR along with Defender for endpoint Compatibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-with-defender-for-endpoint-compatibility/m-p/1225482#M8173</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Does anyone have a list of guidelines to follow when running cortex xdr (Report mode) in parallel with defender (active mode) for workstations as well as servers? Do i need to do any exclusions/whitelisting? Do I need to disable any features in XDR to prevent issues?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In xdr compatibility matrix&amp;nbsp;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Cortex-XDR-agent-compatibility-with-third-party-security-products" target="_blank" rel="noopener nofollow ugc"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Cortex-XDR-agent-compatibility-with-third-party-security-products&lt;/A&gt;&amp;nbsp;you can see it mentions defender and emet separately but if emet like features are present in defender (exploit protection features), running exploit protection in both xdr and defender for endpoint should not work as well correct?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 17:49:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-with-defender-for-endpoint-compatibility/m-p/1225482#M8173</guid>
      <dc:creator>bridgetlitt</dc:creator>
      <dc:date>2025-04-02T17:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR along with Defender for endpoint Compatibility</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-with-defender-for-endpoint-compatibility/m-p/1225610#M8181</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/710084109"&gt;@bridgetlitt&lt;/a&gt;, usually when running two security products in the same endpoint you need to disable the exploit prevention in one of them. In this case, as the XDR is the "passive" product, should be done with the Cortex console.&lt;/P&gt;
&lt;P&gt;There is no official support for XDR in report mode and Defender in active mode, the only supported mode is stated in the URL that you shared in the post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 16:56:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-along-with-defender-for-endpoint-compatibility/m-p/1225610#M8181</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2025-04-03T16:56:46Z</dc:date>
    </item>
  </channel>
</rss>

