Forum Discussion

kindzma's avatar
kindzma
Copper Contributor
Jul 05, 2023

no integration for 3rd party "security providers" in "security center"?

We're seeing Windows Defender and Palo Alto Cortex XDR fighting for resources on a number of our Windows Server instances...

 

("the page you are trying to access has no supported features and is not available")

 

...and noticed that "Cortex XDR" is not listed as a "provider" in Windows Security Center despite having been installed.

 

Palo Alto docs say https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-New-Agent-Settings-Profile#:~:text=The%20Cortex%20XDR%20agent%20registers,Cortex%20XDR%20agent%20is%20installed.:

 

The Cortex XDR agent registers with the Windows Security Center as an official Antivirus (AV) software product. As a result, Windows shuts down Microsoft Defender on the endpoint automatically, except for endpoints that are running Windows Server versions. To avoid performance issues, Palo Alto Networks recommends that you disable or remove Windows Defender from endpoints that are running Windows Server versions and where the Cortex XDR agent is installed.

 

Would anyone know

  1. Why I can't access "providers" under "security providers" in Windows Server 2019?

  2. Why doesn't (or can't) Palo Alto shut down or disable Windows Defender on Windows Server versions after installing Cortex XDR?

  3. What is the best way to automate the process of disabling Windows Defender on Windows Server instances where Cortex XDR is actively protecting the system?

 

Thanks!

 

P.S. Non-server Windows editions are unaffected: managing security providers is an option in "security center", for Windows Defender and Cortex XDR, with Windows Defender disabled ("passive") after Cortex XDR installation.

No RepliesBe the first to reply

Resources