Cortex XDR supervisor password

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Cortex XDR supervisor password

L2 Linker

Hi Team,

 

Some cytool commands were asking to enter supervisor password to proceed, Is this the uninstall password had to set while creating the package? or the Login account password?

 

 

1 accepted solution

Accepted Solutions

One more thing to confirm -- did you run cmd.exe as administrator?


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

View solution in original post

12 REPLIES 12

L4 Transporter

HI @Marsooq_A -

 

Yes, this is the uninstall password.  If you need to change the password, this can be done within the agent profile.

 


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

well , It didn't work for me, even I created a dedicated policy for an endpoint with customized agent profile with a known uninstall password to test this. But did not work

 

cytool2.jpg

Hi @Marsooq_A-

 

When you go to to your list of endpoints, can you right-click on the machine in question then select Endpoint Data > View Endpoint Policy.

 

dfalcon_0-1590669829933.png

 

From there, can you please confirm that the machine received the correct profile?

 

dfalcon_1-1590669947077.png

 

 


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

@dfalcon , Yes the endpoint is configured with right policy.

One more thing to confirm -- did you run cmd.exe as administrator?


David Falcon 
Senior Solutions Architect, Cortex
Palo Alto Networks® 

@dfalcon 

Thanks for the suggestion, its working with cmd with admin privilege

 

Same issue even if i am working with cmd with admin privileges,

 

but got resolved once I set new uninstall password as specified above.

 

Thanks Dfalcon

Hi @vigneshmohan ,

Could you share the steps to change uninstall password? did you perform that using Cytool or other tools?

 

Thanks

Hi @dfalcon ,

I tried running the "Cytool protect disable" command in cmd - admin window. Still it requested for password, I gave the user password with which I was logged in to the system. It is part of admin group. But the 'protect disable' command gave 'Access denied' response.

 

Regards

Please access to Management Console >>> Go to your Cortex XDR instance where u have your endpoint XDR Agent is binded  >>> Go to Endpoint Tab >>> Policy Management>>> Profiles>>> Agent settings profile ( the Agent settings profile that you added to your policy that has your endpoint as its target) >>> Uninstall Password >>> Change the uninstall password to your own local password,

make sure to Check-in ( perform heart beat),

 

Now what you had done is replaced either the global settings/ Agent Settings uninstall password

 

hope it helps

L1 Bithead

Supervisor password is also called as Uninstall Password

to change it >> go and change the agent settings profile uninstall password. This must be done on your Cortex XDR Instance.

 

Steps

Please access to Management Console >>> Go to your Cortex XDR instance where u have your endpoint XDR Agent is binded >>> Go to Endpoint Tab >>> Policy Management>>> Profiles>>> Agent settings profile ( the Agent settings profile that you added to your policy that has your endpoint as its target) >>> Uninstall Password >>> Change the uninstall password to your own local password,

make sure to Check-in ( perform heart beat),

 

Now what you had done is replaced either the global settings/ Agent Settings uninstall password

  • 1 accepted solution
  • 28674 Views
  • 12 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!