We use it for malicious connections from malicious websites. There might also be some payloads that might be inside the traffic. We also use it to identify malicious processes or bugs that are running on the network and any activities that tend to lead to data infiltration.
Relationship Manager at a financial services firm with 5,001-10,000 employees
Easy to use, but can have more security and integrations
Pros and Cons
- "It is easy to use."
- "We use it for malicious connections from malicious websites, to identify payloads that might be inside the traffic, to identify malicious processes or bugs that are running on the network, and any activities that tend to lead to data infiltration."
- "Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
- "Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
What is our primary use case?
What is most valuable?
It is easy to use.
What needs improvement?
Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms.
For how long have I used the solution?
I have been using this solution for about a year.
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,298 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We have maybe a thousand users of this solution because it is deployed on-prem.
How was the initial setup?
I don't think there were issues with the installation.
What's my experience with pricing, setup cost, and licensing?
It has a yearly renewal.
What other advice do I have?
I would recommend this solution. I would rate Cortex XDR a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security consultant at a computer software company with 1,001-5,000 employees
Sophisticated user interface, stable, and scalable
Pros and Cons
- "The user interface of the solution is sophisticated and straightforward."
- "The user interface of the solution is sophisticated and straightforward."
- "In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
- "In an upcoming release, the solution could improve by providing hard disk encryption."
What is our primary use case?
We use this solution to protect our computer system against threats, such as exploits and malware.
What is most valuable?
The user interface of the solution is sophisticated and straightforward.
What needs improvement?
In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution.
For how long have I used the solution?
I have been using this solution for approximately two months.
What do I think about the stability of the solution?
The solution is stable, we have not had any issues.
What do I think about the scalability of the solution?
We have over 5,000 employees and they are being managed through this solution. It is scalable.
How are customer service and technical support?
We have our own IT support teams.
Which solution did I use previously and why did I switch?
We were previously using McAfee and we switched to this solution because they failed to provide us proper protection.
How was the initial setup?
We have an IT support team in our organization and they are managing everything remotely, such as laptops.
What about the implementation team?
Our internal team did the implementation of the solution.
What other advice do I have?
I would recommend this solution to others.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,298 professionals have used our research since 2012.
Lead Security Engineer at ESKA
Scalable with excellent protection features and is very user-friendly
Pros and Cons
- "The solution doesn't need a high level of technical training."
- "Palo Alto is the best security solution in the market."
- "Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well."
- "For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible."
What is our primary use case?
Cortex XDR is used for endpoint detection and response. This is software placed into endpoints and work in this cloud. In cloud has the analytics, login, prevention models, et cetera.
What is most valuable?
If a company uses Palo Alto and supports Cortex XDR for endpoint protection it is very well protected. Palo Alto is the best security solution in the market. It's very advanced and its protection is extremely reliable.
The solution doesn't need a high level of technical training. The solution is very usable and doesn't take a lot of personnel.
The product is very scalable.
The stability is very good.
What needs improvement?
For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible.
Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well.
For how long have I used the solution?
I've been working with this security solution for ten years or so and Palo Alto Networks for two years.
What do I think about the stability of the solution?
The solution has been very stable and very reliable. There are no bugs or glitches. It doesn't crash or freeze. It's one of the best on the market.
What do I think about the scalability of the solution?
The solution is very scalable. It works well for companies that are quite sizeable. If an organization needs to expand it, it can do so easily.
We have about 50 to 55 users on the solution.
How are customer service and technical support?
I personally handle technical questions for those working with Palo Alto.
Support of Palo Alto is English, however, I work in this local technical solution, local technical and I'm working with customers with a warranty.
I've found technical support from Palo Alto to be very good. We're local and we can assist as well, however, Palo Alto is capable of handling any size of issue and they are quite helpful.
How was the initial setup?
I am not directly handling the installation. My client is.
You do need a team of people on this solution that understand the cloud and the solution itself if you have a large, complex environment. If you have a robust security team, it's good. However, if you don't have the resources, it's not an ideal product.
That said, if your company requires a small, simple setup, one person may be enough. It really depends on the size.
What about the implementation team?
My client is actually handling the installation. I often field questions from them, however, I don't participate in the installation directly.
What's my experience with pricing, setup cost, and licensing?
For basic needs, the solution isn't very expensive. However, as you grow more complex in your needs, the more you use, the more costly it can get.
The licensing is typically for one year. There's a one-time installation. If you would like to continue with the service, you can continue. There's no need to install and reinstall.
What other advice do I have?
Cortex XDR is a threat analytics security manager that allows users to see what threats are going to endpoints. It's a very high-security solution.
The next step up from Cortex XDR is Cortex XSOAR. XSOAR is an automated threat solution. It's a security solution from Palo Alto.
I'd recommend the solution to others. I'd rate it at a nine out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Sales Engineer at a security firm with 51-200 employees
Reliable with good support, but the installation should be simplified
Pros and Cons
- "Stability is one of the features we like the most."
- "Stability is one of the features we like the most."
- "The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
- "The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
What is our primary use case?
We use this solution to secure endpoints and to have more visibility on what is happening on the endpoints.
We have two customers who are using this solution currently.
What needs improvement?
The installation should be easier and the Palo Alto pre-sales and sales should teams have more information on the product because they don't know what they are selling.
They don't know the features of the products they sell.
For example, Cortex XDR includes Cortex XDR Prevent, Cortex XDR Pro, and Cortex XDR Pro per TB. They don't know the real differences between Cortex XDR Pro and Cortex XDR Pro per TB.
Sometimes, they will tell you about features for one edition that belong to another edition. They don't seem to know what features belong to what edition.
For how long have I used the solution?
I have been working with this solution for one month.
We are familiar with Cortex XDR Prevent and Cortex XDR Pro.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's a scalable solution.
How are customer service and technical support?
Technical support is okay.
How was the initial setup?
The initial setup is complex. It is not easy to install.
We have been deploying this solution for a month, but we are not finished yet.
We only need one engineer for the deployment and maintenance.
What other advice do I have?
I would recommend this solution to anyone who is interested in using it.
I would rate Cortex XDR a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Director of Cloud Security at a comms service provider with 51-200 employees
Solid solution
Pros and Cons
- "The dashboard is customizable."
- "The dashboard is customizable."
- "The dashboard could use some significant improvement, just making it more useful with more information. It has a limited amount of information right now. It is customizable, but I'd love to see a better out-of-box dashboard."
- "The dashboard could use some significant improvement, just making it more useful with more information."
What needs improvement?
In terms of what could be improved in Cortex XDR, definitely the host insights module. The ability to kind of take a look at what applications are running on the endpoint is a new feature, but there is a lot of room for improvement there in terms of versioning and so forth.
Additionally, the dashboard could use some significant improvement, just making it more useful with more information. It has a limited amount of information right now. It is customizable, but I'd love to see a better out-of-box dashboard.
For how long have I used the solution?
I have been working with Cortex XDR over the last year, at least.
What other advice do I have?
On a scale of one to ten, I would give Cortex XDR by Palo Alto Networks an eight.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Ingeniero de Soporte at a tech services company with 11-50 employees
Stable, flexible, and easy to deploy
Pros and Cons
- "They did what they said. This solution could apply to any scenario."
- "They did what they said, and this solution could apply to any scenario."
- "I would like to see better protection, specifically to protect email applications."
- "The configuration could be simplified. I would like to see better protection, specifically to protect email applications."
What is our primary use case?
We deploy this solution in Universities and banks because it's private. Our company is a private company.
What is most valuable?
They did what they said. This solution could apply to any scenario.
What needs improvement?
The configuration could be simplified.
I would like to see better protection, specifically to protect email applications.
What do I think about the stability of the solution?
This solution is stable.
How was the initial setup?
It's easy to deploy
You need the experience to configure the equipment, but the configuration is easy to deploy.
What's my experience with pricing, setup cost, and licensing?
The price could be improved. Our customers have expressed that the price is high. When compared with other services, it's more expensive, but it's not too high.
What other advice do I have?
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Consultant at a tech services company with 201-500 employees
Automated, with well defined policies, but privacy is a concern
Pros and Cons
- "The most valuable feature is that you can select remote access of any machine for sandboxing."
- "The product is mostly automated, and we do not have to make decisions, because all the decisions are made by the product itself and we are not required to create any custom policies since the policies that are created are well defined in the product itself."
- "Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access."
- "Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access."
What is our primary use case?
We use this solution specifically in endpoint response, endpoint detection, endpoint sandboxing, and as a firewall.
How has it helped my organization?
The product is mostly automated, and we do not have to make decisions. All the decisions are made by the product itself.
We are not required to create any custom policies.
The policies that are created are well defined in the product itself.
What is most valuable?
The most valuable feature is that you can select remote access of any machine for sandboxing.
Irrespective of whether you have the rights or not, you can still access it from the cloud.
What needs improvement?
I would like to see some sort of attachment scanning included.
Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access.
I want a plugin for email attachment scanning and email body scanning.
For how long have I used the solution?
I have been using this solution for two years.
We are using version seven.
What do I think about the scalability of the solution?
Scalability is not a problem with this solution.
It's a cloud setup. You can scale in and you can scale out as per the cloud.
We have close to 500 users in our company.
How are customer service and technical support?
Technical support is very good, but it can be a problem, especially in the Gulf region.
If you do not take direct support, you have to wait for 72 hours.
Also, direct support is a little bit costly.
Which solution did I use previously and why did I switch?
We used McAfee previously. We switched because the solution is pretty automated. You don't have to manually decide on the policy.
How was the initial setup?
The initial setup is pretty straightforward.
In one hour, you can deploy the entire setup and get started.
After the setup, deployment can take up to three to four days.
We had one admin test the solution and maintain it for us.
What about the implementation team?
We did not use an integrator or vendor team.
What's my experience with pricing, setup cost, and licensing?
The pricing is okay, although direct support can be expensive.
What other advice do I have?
It is a very straightforward product with minimum administer interference, once it is deployed.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network and Cybersecurity Consultant at a tech services company with 11-50 employees
A stable detection and response app with a good policy management feature
Pros and Cons
- "Stability is a primary factor, and then there's the ease of distribution and policy management."
- "Stability is a primary factor, and then there's the ease of distribution and policy management; Cortex XDR by Palo Alto Networks is very easy to work with, and we're quite happy with them."
- "It would be good to have a better way to search for a file within the UI."
- "It would be good to have a better way to search for a file within the UI."
What is our primary use case?
We're primarily a Palo Alto shop, and we integrate solutions in the Palo Alto ecosystem. But for firewalls and threat hunting, it's all through Cortex XDR. We also compliment the Cortex XDR product with other endpoint protection solutions, like Windows Defender, or whatever the customer is using,
What is most valuable?
Stability is a primary factor, and then there's the ease of distribution and policy management. Cortex XDR by Palo Alto Networks is very easy to work with, and we're quite happy with them.
What needs improvement?
It would be good to have a better way to search for a file within the UI. Like in SentinelOne, you can search for an arbitrary file, and in Cortex XDR, you can't. You can do it with an addendum license, but I think we could all benefit from getting it with the standard license. Because if you want to do threat hunting with this product, you have to search for files now and not wait to get a license.
For how long have I used the solution?
I've been using Cortex XDR by Palo Alto Networks for about two years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is a stable solution.
How are customer service and technical support?
We used to talk to Palo Alto support extensively, and we always had a pleasant experience and never had a problem with them.
How was the initial setup?
Cortex XDR is quite easy to install. The time it takes to deploy depends on the infrastructure. We have had cases that lasted a few days and other cases where it took two to four months for a proof of concept.
What's my experience with pricing, setup cost, and licensing?
Every customer has to pay for a license because it doesn't work with what you get from a managed services provider. It's quite expensive, and they can't sell it for less than 200 euros a license. It's the lowest license price we can get from them.
What other advice do I have?
I would recommend Cortex XDR by Palo Alto Networks to potential users.
On a scale from one to ten, I would give Cortex XDR by Palo Alto Networks a nine.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Extended Detection and Response (XDR) Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
IBM Security QRadar
Microsoft Sentinel
Varonis Platform
Elastic Security
Huntress Managed EDR
HP Wolf Security
Trellix Endpoint Security Platform
TrendAI Vision One
WatchGuard Firebox
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?

















Hi There, We have a customer who wants to have Cortex & Microsoft solutions on all their Windows 10 endpoints. So here is my query - Can Cortex XDR co-exist with Microsoft Defender for Endpoint on same endpoints and both operate optimally and independently of each other? Thanks in advance! Dr. Praveen Talwar (Praveen.Talwar@Spark.co.nz)
Hello @Praveen Talwar, please note that you can also create a new question from your Home feed: https://www.itcentralstation.c... . This way, it will get higher visibility (it just should not include any marketing or sales content). I hope this is helpful.