Hello @j.gamarra ,
Greetings for the day.
Before moving from Report to Block mode, review what Cortex XDR is currently detecting but not preventing.
- Check Incident Response → Alerts and filter for Detected/Reported actions and Not Blocked prevention status.
- Review the affected modules and causality chains to identify legitimate applications or scripts.
- Add exceptions for any known-good activity before enabling Block.
- Test the new Block policy on a small group of endpoints first.
- Monitor for about 7 days, then roll it out to the wider environment if there are no issues.Try with the less Group (The minimal endpoints).
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar