<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting Azure Code Signing in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/troubleshooting-azure-code-signing/m-p/1246287#M9032</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/989505425"&gt;@clairehar557ris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since March 2023, Microsoft has required security vendors to sign binaries using Microsoft Trusted Signing (formerly known as Azure Code Signing or ACS). Consequently, all Cortex XDR agent versions released after this date require endpoints to have specific Microsoft Windows patches to validate these signatures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Prerequisite Details&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Required Patch:&lt;/STRONG&gt;&lt;BR /&gt;Microsoft KB5022661 or any newer cumulative update that includes its contents.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Affected Systems:&lt;/STRONG&gt;&lt;BR /&gt;This primarily impacts legacy systems including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Windows 10 (older versions)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Windows 7 SP1 (requires an extended support license to install the patch)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Windows Server 2008 R2 SP1, 2012, 2012 R2, 2016, and 2019&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;BR /&gt;Windows 11 machines have this support pre-installed and are generally unaffected.&lt;/P&gt;
&lt;H4&gt;Symptoms of Missing Prerequisite&lt;/H4&gt;
&lt;P&gt;If the required patch or cumulative update is missing, Cortex XDR agent installations or upgrades will fail with the following indicators:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Error Message:&lt;/STRONG&gt;&lt;BR /&gt;“Cortex XDR requires Azure Code Signing support. See Microsoft KB5022661 for details”&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Console Error:&lt;/STRONG&gt;&lt;BR /&gt;The upgrade status may show as &lt;STRONG&gt;Failed&lt;/STRONG&gt; with an &lt;STRONG&gt;Installer timed out&lt;/STRONG&gt; error&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;MSI Error:&lt;/STRONG&gt;&lt;BR /&gt;Log files typically record MSI error code &lt;STRONG&gt;1603&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Resolution and Workarounds:&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Apply Cumulative Updates:&lt;/STRONG&gt;&lt;BR /&gt;Ensure the endpoint is updated with the latest Microsoft security quality updates. If KB5022661 is not found individually in the Microsoft Update Catalog, it has been superseded by more recent cumulative updates.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Verify Installation:&lt;/STRONG&gt;&lt;BR /&gt;You can verify whether the patch is present by running the following command in an elevated command prompt:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;wmic qfe get hotfixid | find "KB5022661"
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass Flag (Critical Environment Agents Only):&lt;/STRONG&gt;&lt;BR /&gt;For environments where patching is not possible, Critical Environment (CE) agent versions (specifically 7.9.103-CE and 8.3-CE) allow a bypass.&lt;/P&gt;
&lt;P&gt;Perform a fresh installation using the following MSI flag:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;msiexec /i &amp;lt;installer.msi&amp;gt; NO_ACS_SUPPORT=1
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;Limitation:&lt;/STRONG&gt;&lt;BR /&gt;This flag cannot be used for upgrades; a clean reinstallation is required. Standard agent versions (for example, version 8.7) ignore this flag and will still fail if the required patch is missing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jan 2026 16:16:33 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-01-22T16:16:33Z</dc:date>
    <item>
      <title>Troubleshooting Azure Code Signing</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/troubleshooting-azure-code-signing/m-p/1245029#M9027</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With recent Cortex XDR updates, Microsoft KB5022661 is now a prerequisite for many legacy Windows systems. If your endpoints are missing this, upgrades will fail.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 06:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/troubleshooting-azure-code-signing/m-p/1245029#M9027</guid>
      <dc:creator>clairehar557ris</dc:creator>
      <dc:date>2026-01-07T06:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Azure Code Signing</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/troubleshooting-azure-code-signing/m-p/1246287#M9032</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/989505425"&gt;@clairehar557ris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since March 2023, Microsoft has required security vendors to sign binaries using Microsoft Trusted Signing (formerly known as Azure Code Signing or ACS). Consequently, all Cortex XDR agent versions released after this date require endpoints to have specific Microsoft Windows patches to validate these signatures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Prerequisite Details&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Required Patch:&lt;/STRONG&gt;&lt;BR /&gt;Microsoft KB5022661 or any newer cumulative update that includes its contents.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Affected Systems:&lt;/STRONG&gt;&lt;BR /&gt;This primarily impacts legacy systems including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Windows 10 (older versions)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Windows 7 SP1 (requires an extended support license to install the patch)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Windows Server 2008 R2 SP1, 2012, 2012 R2, 2016, and 2019&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;BR /&gt;Windows 11 machines have this support pre-installed and are generally unaffected.&lt;/P&gt;
&lt;H4&gt;Symptoms of Missing Prerequisite&lt;/H4&gt;
&lt;P&gt;If the required patch or cumulative update is missing, Cortex XDR agent installations or upgrades will fail with the following indicators:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Error Message:&lt;/STRONG&gt;&lt;BR /&gt;“Cortex XDR requires Azure Code Signing support. See Microsoft KB5022661 for details”&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Console Error:&lt;/STRONG&gt;&lt;BR /&gt;The upgrade status may show as &lt;STRONG&gt;Failed&lt;/STRONG&gt; with an &lt;STRONG&gt;Installer timed out&lt;/STRONG&gt; error&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;MSI Error:&lt;/STRONG&gt;&lt;BR /&gt;Log files typically record MSI error code &lt;STRONG&gt;1603&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Resolution and Workarounds:&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Apply Cumulative Updates:&lt;/STRONG&gt;&lt;BR /&gt;Ensure the endpoint is updated with the latest Microsoft security quality updates. If KB5022661 is not found individually in the Microsoft Update Catalog, it has been superseded by more recent cumulative updates.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Verify Installation:&lt;/STRONG&gt;&lt;BR /&gt;You can verify whether the patch is present by running the following command in an elevated command prompt:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;wmic qfe get hotfixid | find "KB5022661"
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;Bypass Flag (Critical Environment Agents Only):&lt;/STRONG&gt;&lt;BR /&gt;For environments where patching is not possible, Critical Environment (CE) agent versions (specifically 7.9.103-CE and 8.3-CE) allow a bypass.&lt;/P&gt;
&lt;P&gt;Perform a fresh installation using the following MSI flag:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;msiexec /i &amp;lt;installer.msi&amp;gt; NO_ACS_SUPPORT=1
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;Limitation:&lt;/STRONG&gt;&lt;BR /&gt;This flag cannot be used for upgrades; a clean reinstallation is required. Standard agent versions (for example, version 8.7) ignore this flag and will still fail if the required patch is missing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 16:16:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/troubleshooting-azure-code-signing/m-p/1246287#M9032</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-22T16:16:33Z</dc:date>
    </item>
  </channel>
</rss>

