- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-26-2024 09:31 PM
Hi family
How I add an exclusion based on for a specific process allow (license.exe) for specific endpoint on cortex xdr. wildfire are blocking this process many times so i want to allow for this service for specific endpoint.
thanks, and regards.
03-27-2024 06:52 AM
Hi @Prashanta, thanks for reaching us using the Live Community.
This is the overall process:
- Create a new Exceptions Security Profile: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Legac...
- Create a new legacy exception rule in Settings - Exceptions Configuration.
We recommend to select only the protection module that is blocking the process, you can see it in the Alert details.
Select the previously created Exceptions Profile.
- Now create the Policy Rule to apply the profile to the required Endpoint.
You can copy your production policy with right click - Save as New
Change the Exceptions Profile to the new created one with the exception assigned.
And then select the endpoint in the Target menu using the filters.
Please check it and let us know how it goes.
If this post answers your question, please mark it as the solution.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!