Install the Cortex XDR Agent for Mac

Before installing the Cortex XDR agent on a Mac endpoint, verify that the system meets the requirements described in Cortex XDR for Mac Requirements.
Install the agent using a software distribution tool of your choice (such as JAMF) or using the following workflow:
  1. Download the installation package you want to install from Cortex XDR.
  2. Copy the installation package to the endpoint on which you want to install the Cortex XDR agent software.
  3. Unzip the installation package.
  4. (
    Optional
    ) Configure a Cortex XDR agent specific proxy on the endpoint.
    If you are deploying Cortex XDR in an environment where the agents communicate with Cortex XDR through a proxy, you must assign the proxy IP address and port number during the agent installation on the endpoint.
    1. Locate the
      Config.xml
      file in the unzipped installation folder.
    2. Edit the
      <proxy_list>
      <proxyserver>:<port>
      </proxy_list>
      tag.
      • To install an agent with a Cortex XDR specific proxy, enter your proxy IP address and port number. You can assign up to five different IP addresses per agent, and the proxy for communication is selected randomly with equal probability.
        <proxy_list>10.196.20.244:8080,10.196.20.245:8080</proxy_list>
      • To install an agent communicating through the Palo Alto Networks Broker Service, you must enter the Broker VM IP address and port number 8888 only.
    3. After the initial installation, you can change the proxy settings in Cortex XDR.
  5. Install the Cortex XDR agent software.
    1. Run the
      Cortex xdr.pkg
      installation file.
      traps-mac-install-intro.png
    2. Click
      Continue
      to proceed with the installation.
    3. If prompted to confirm the destination, click
      Continue
      .
    4. Click
      Install
      to begin the installation.
    5. Enter the
      User Name
      and
      Password
      of the administrator with access to install software on the endpoint, and then click
      Install Software
      .
    6. (
      macOS 10.13 and later versions
      ) Allow Cortex XDR to install system extensions:
      1. Dismiss the
        System Extension Blocked
        warning.
      2. Go to
        System Preferences
        Security & Privacy
        General
        and select
        Allow
        .
        traps-mac-install-security-and-privacy.png
    The Cortex XDR agent logs any installation errors to
    /var/logs/installation.log
    . If installation fails for any reason, you can view this log to better understand the cause of the installation failure.
  6. After the installation completes, verify your connection.
    1. To open the Cortex XDR agent console, click the agent icon in the menu bar, and select
      Open Console
      .
    2. Click
      Check In Now
      to initiate a connection with your tenant of Cortex XDR. If successful, the
      Last Check-In
      field updates to display the recent check-in date and time.
      traps-console-mac-events.png
      If the Cortex XDR agent does not connect to Cortex XDR, verify your internet connection and perform a check-in on the endpoint. If the agent still does not connect, verify the installation package has not been removed from the Cortex XDR management console.
  7. (
    macOS 10.15 and later versions
    ) Grant full disk access.
    Due to changes in the security settings of macOS 10.15, you must allow the Cortex XDR agent full disk access on your endpoint to enable full protection. If you do not authorize the agent full disk access on your endpoint, the agent provides only partial protection of files in the
    /Applications
    directory. The first time the agent detects an attempt to run an executable file located in another protected location on the endpoint as part of the anti-malware flow, macOS will deny the Cortex XDR agent access and prompts the user to grant full disk access.
    You can grant the Cortex XDR agent full disk access manually or using a third-party tool such as JAMF.
    To grant the Cortex XDR agent full disk access locally on the endpoint:
    1. Go to
      System Preferences
      Security & Privacy
      tab, and select
      Full Disk Access
      .
    2. To make changes, click lock icon ( mac-settings-lock-icon.png ) on the bottom left, enter your credentials, and
      Unlock
      .
    3. Navigate to
      Macintosh HD
      Library
      Application Support
      PaloAltoNetworks
      Traps
      bin
      .
    4. Select
      trapsd
      ,
      authorized
      , and
      pmd
      .
      mac-full-disk-access-apps.png
    5. When you’re done, click mac-settings-unlock-icon.png to save your changes and stop editing.

Recommended For You