- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-02-2024 07:30 AM
Hi, I need help, I have Cortex XDR policy to allow scans on the endpoint, however users are unable to start the scans, the option does not appear
I can only scan, with cmd as administrator (cytool scan start) , in the GUI I can't even do it as administrator:
my configuration:
02-03-2024 08:09 AM
Dear @tlmarques ,
Hope you are doing well, and thank you for reaching out to our Live Community. From the above query I believe that you are trying to see how to configure the end users to initiate a full scan from the Cortex XDR interface locally on endpoint.
Please note that a full scan can only be initiated from Cortex XDR portal by navigating to Incident Response → Response → Action Center
Please find the document provided below for further details, thank you:
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Scan-an...
And for the configuration you have provided in the second screenshot, this configuration is used to allow the end user to initiate a right click scan on a file or folder as seen in the screenshot provided below, thank you:
If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.
02-12-2024 11:58 AM
we've that configuration enabled....the problem is the agent...i open a case with support and we found the problem.
For future, if someone have the same problem, check that:
OS version:
In the case of Windows 11, it will show clicking the “Show More Options” in the context menu.
Registry:
This is a registry key related to “Show More Options” in the context menu.
Please check if they are in the registry key.
- HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Cortex.XDR.Scan
- HKEY_CLASSES_ROOT\CLSID\{44303AF8-6F09-4803-8639-9247339BE42D}
- HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\Cortex.XDR.Scan
- HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\Cortex.XDR.Scan
If registry keys are missing, please re-install the agent.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!