- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-13-2026 10:44 AM
I am looking for detailed information regarding the backup and recovery lifecycle for a Cortex XDR tenant. Specifically, I have the following questions:
Automated Backups: Does Palo Alto Networks perform regular backups of tenant-specific configurations (Security Policies, Profiles, XQL queries, etc.)? If so, what is the standard frequency?
Restoration Requests: In the event of an accidental configuration loss, is it possible to request a restoration of a previous backup through support? What is the standard procedure and the expected Lead Time for such a request?
Self-Service Rollback: Does the platform currently offer any "Undo" or "Rollback" features for administrative changes, or are we reliant on manual reconstruction via Audit Logs?
Thank you in advance for your insights!
02-16-2026 10:02 AM
Hello @R.Abdeen ,
Greetings for the day.
The Cortex XDR platform is a fully managed cloud Software-as-a-Service (SaaS) solution. Consequently, Palo Alto Networks manages the backend infrastructure, including regular system backups and disaster recovery procedures.
Palo Alto Networks performs regular internal snapshots and system-level backups to ensure platform resilience and data integrity.
While the internal snapshot interval is not publicly defined as a specific hourly or daily schedule in technical documentation, the system adheres to strict recovery metrics:
Recovery Point Objective (RPO): 4 hours
Recovery Time Objective (RTO): 4 hours
Service Availability: 99.9% monthly uptime objective
The platform does not provide a customer-facing "point-in-time" restoration tool for reverting an entire tenant configuration due to administrative errors.
If specific critical components like Indicators of Compromise (IOCs) or BIOC rules are accidentally deleted, a limited restoration may be possible through a support request.
The customer must provide the exact date and time of the deletion and the specific restoration point.
TAC engineers will open a JIRA ticket to the Engineering/DevOps team to request a data merge from database backups.
These manual data merges are typically performed during the next available maintenance window, commonly Sunday evening.
There is currently no native "Undo," "Checkpoint," or "Recycle Bin" feature for administrative configuration changes within the console.
Administrators must rely on Management Audit Logs to track modifications. These logs record:
What configuration was modified or deleted
The timestamp of the change
The user attribution for the action
To mitigate accidental losses, Palo Alto Networks recommends a proactive manual backup strategy for security policies and profiles.
Periodically export Prevention Profiles and Policy Rules from the console:
Navigate to:
Endpoints → Policy Management → Prevention → Profiles (or Policy Rules)
Right-click the desired items and select Export Profile or Export Policy
Re-import these Base64-encoded files to manually revert settings if needed:
Navigate to:
Endpoints → Policy Management → Prevention → Policy Rules
Select Import from File
There is currently no documented native API-based method for automated configuration backups or versioning.
While APIs can be used to extract alerts and incidents, configuration objects such as security profiles are not currently supported for automated backup via public API endpoints.
A feature request (CXDR-I-1916) exists for a comprehensive backup utility.
For formal documentation regarding disaster recovery plans or contractual SLAs, please contact your Palo Alto Networks Account Team.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

