Thank you for writing to live community!
No, XDR services won't be stopped when we pause endpoint protection. Because with pause protection agent will still retain connectivity with the server to take any actions from the server, its just pausing the protection which means agent will run with all the profiles disabled.
You may refer in the documentation here for the same.
Hope this helps!
Please mark the response as "Accept as Solution" if it answers your query.
Thanks for the response Piyush.
Actually, the client asks us to disable xdr on an endpoint coz they might be doing some activity or some installations for ex and do not want XDR to block it. So what we do is , we tell them to stop the services and start post completion of the activity.(runtime stop/start)
Can we pause protection instead of that?
It is usually not a good idea to be pausing or disabling protection services unless it is to troubleshoot the agent itself. XDR should not be interfering with normal user or administrator activity and, if it is, appropriate alert tuning actions should be taken to address this. If users or administrators have the capability to disable the agent, it becomes much less likely that you will be able to identify and protect against insider threats.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!