Cortex XDR: Block the Exit button with admin rights

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Cortex XDR: Block the Exit button with admin rights

L1 Bithead

Hello,

 

We have noticed that the user can simply exit the XDR on the system tray. Is there any way to block the exit button with admin rights or any way possible to avoid stopping the app?

 

 



Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.
1 REPLY 1

L5 Sessionator

Hi @Seth_Sakshi ,

 

Thank you for writing to live community!

 

Clicking on "Exit" will cause only the agent tray icon process to close and not the XDR process itself. Because it is enforced in the policy, the end user will again get the tray icon after reboot. You can try it by exiting the tray icon, but you should still be able to see the XDR agent connected on the Cortex XDR console. alternatively, you can take CLI and run "cytool runtime query" to check the agent service running status.

 

While, there is no control on XDR to not allow "Exit" button be hit, what can be alternatively done, is that we can hide the tray icon once and for all in the agent settings configuration so that end users do not see it at all. This ensures security as insiders do not know of your security solution being used(unless they get blocked and get the notification popup).Also, it solves the problem, where you do not want people to click on "Exit".  Check the screenshot for reference on how to configure the tray icon setting.

 

Please mark this response as "Accept as Solution" if it helps with your query.

 

Regards.

Screenshot 2023-01-06 at 2.23.42 PM.png

  • 1483 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!