<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Full disk access requirement on macos agent in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/full-disk-access-requirement-on-macos-agent/m-p/1233066#M8514</link>
    <description>&lt;P&gt;Hi Luis - thanks for your reply. I'll need to get more info from the user to understand more on what was going on here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another question for (2). As you mention, the cytool output (while read confusing to me) seemed like it indicated that full disk access wasn't granted. However on the web console, that endpoint showed up as being fully protected though. So which one is to be believed?&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jul 2025 22:49:21 GMT</pubDate>
    <dc:creator>tmeksik</dc:creator>
    <dc:date>2025-07-02T22:49:21Z</dc:date>
    <item>
      <title>Full disk access requirement on macos agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/full-disk-access-requirement-on-macos-agent/m-p/1232995#M8507</link>
      <description>&lt;P&gt;Hi team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A couple of questions here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Is full disk access required for agents running on macOS Sonoma and Sequoia?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) What is the meaning of "Requires full disk access: False" in the "cytool status" output? (screenshot attached)&lt;BR /&gt;The endpoint we ran this command on showed as "Fully protected" through the console. It is running&amp;nbsp;8.7.1.2855 on MacOS Sonoma.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Tum&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 04:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/full-disk-access-requirement-on-macos-agent/m-p/1232995#M8507</guid>
      <dc:creator>tmeksik</dc:creator>
      <dc:date>2025-07-02T04:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Full disk access requirement on macos agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/full-disk-access-requirement-on-macos-agent/m-p/1233019#M8509</link>
      <description>&lt;P&gt;Hi Tmeksik,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Full disk access on mac is required to give full protection against malicious activities in your endpoint as you can see in the documentation below at step 9. To provide full protection from antimalware flow full disk access is required:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/8.3/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-Manually" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/8.3/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-Manually&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;I see that MacOs Somoa and Sequoia are versions 14 and 15 respectively. The full disk access is required since version MacOs v10.15 as the documentation says. The output of cytool seems to say that the agent does not have full access to the disk. Could you please double check on your mac configurations ? I dont have a Mac with me now, I believe it is under the Privacy &amp;amp; Security menu of your Mac. Please make sure that you have granted full access to the XDR agent over the disk in your Mac endpoint.&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;I have checked too that XDR Agent 8.7.1.2855 is compatible with MacOs Sequoia and Sonoma:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Mac" target="_blank" rel="noopener"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Compatibility-Matrix/Mac&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 08:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/full-disk-access-requirement-on-macos-agent/m-p/1233019#M8509</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-07-02T08:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Full disk access requirement on macos agent</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/full-disk-access-requirement-on-macos-agent/m-p/1233066#M8514</link>
      <description>&lt;P&gt;Hi Luis - thanks for your reply. I'll need to get more info from the user to understand more on what was going on here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another question for (2). As you mention, the cytool output (while read confusing to me) seemed like it indicated that full disk access wasn't granted. However on the web console, that endpoint showed up as being fully protected though. So which one is to be believed?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 22:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/full-disk-access-requirement-on-macos-agent/m-p/1233066#M8514</guid>
      <dc:creator>tmeksik</dc:creator>
      <dc:date>2025-07-02T22:49:21Z</dc:date>
    </item>
  </channel>
</rss>

