We are still in the testing stages so there is not currently any primary use case beyond the base use of endpoint protection.
This is a recommended solution for total end-to-end protection
Pros and Cons
- "Being a cloud solution it is very flexible in serving internal and external connections and a broad range of devices."
- "The connection to the internet has not performed as expected."
What is our primary use case?
What is most valuable?
Cortex has several good features that I am interested in. There is a nice Sandbox function that is very strong, there is the Traps (endpoint protection) solution, the real-time filtering of suspect linkages is good, and the automatic blocking of suspect behavior is always active and protecting the network.
What needs improvement?
As an improvement, I would like to see enhanced connection speeds. On China's side, we need to set up a local server for the definition updates, and the performance has not been very good for the company when directly connected to the internet. We are a little disappointed with that.
For how long have I used the solution?
We have been using Cortex XDR (Extended Detection and Response) for around two months.
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is stable. From the moment we installed it has been up with no restarts of maintenance until now.
What do I think about the scalability of the solution?
I think that this product is scalable. The testing environment we use right now has around 200 users. In the future, when we deploy it to the company we will move up to around 4,000 users.
How are customer service and support?
The technical support is okay. They have already helped us to fix the installation and then we had an issue and they were available for correction of the problem. They also have made some useful suggestions. So the support team is okay in my estimation.
Which solution did I use previously and why did I switch?
We have been exploring a similar solution. Right now I am also doing testing on Sentinel at the center. This is a similar solution. But we have only just begun testing Sentinel, so we do not really have enough experience with it to comment on the product.
How was the initial setup?
As we just started with Cortex and we are using a cloud solution, I do not have the impression that it was difficult to install and begin using.
What's my experience with pricing, setup cost, and licensing?
The setup costs are a bit higher than some other solutions. Overall it is a little bit expensive, I think. If we could get it for around a 10% discount then that would be a better price point for us.
For our pricing plan, we are not on a subscription, so we do not have to pay every month. We have a yearly license for the product.
The approximate amount we pay per license is around $80 per user per year.
What other advice do I have?
My suggestion for people considering this product is that Cortex is a very good total solution on the endpoints. Because I needed Cortex to work for external and internal users and devices, it helps that it is cloud-based because it is good for working in the office or other locations. So we wanted to have the total end-to-end protection including on the mobile devices, that is what we got. This product will be a good suggestion for people who need the same capability.
On a scale from one to ten where one is the worst and ten is the best, I would rate Cortex XDR as around nine-out-of-ten. The cost is the reason it would not be higher. Nine is good but this is a very good product except for the cost.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Cyber Security Engineer at ACPL
Performs stitching between a number of security domains
Pros and Cons
- "We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action."
- "Cortex XDR should have a lightweight agent, and the agent size should not be heavy."
What is our primary use case?
Cortex XDR does the stitching between a number of security domains, like email security, API security, and web security. The solution does the stitching from different sources and makes a logical incident.
What is most valuable?
We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action. We don't need to navigate different solutions and tools or use our human intelligence to correlate all the information to make the logic. Cortex XDR entirely does it, and we can take action.
What needs improvement?
Cortex XDR should have a lightweight agent, and the agent size should not be heavy. Cortex XDR’s technical support should also be improved.
Cortex XDR should provide a feature to remove or uninstall an agent directly from the console itself without the help of an IT engineer. No one wants to do a manual installation of the agent. Everyone is looking for a solution to remove the agent from the console directly.
For how long have I used the solution?
I have been working with Cortex XDR by Palo Alto Networks for two years.
What do I think about the stability of the solution?
I rate Cortex XDR a ten out of ten for stability.
What do I think about the scalability of the solution?
I rate Cortex XDR a five out of ten for scalability.
How are customer service and support?
The technical support of Cortex XDR and other OEM products is not very good. Cortex XDR's technical support does not usually respond quickly.
How would you rate customer service and support?
Neutral
How was the initial setup?
I rate Cortex XDR’s initial setup an eight out of ten.
What's my experience with pricing, setup cost, and licensing?
Cortex XDR’s pricing is very reasonable. I rate Cortex XDR a five out of ten for pricing.
What other advice do I have?
I am using the latest version of Cortex XDR by Palo Alto Networks. Cortex XDR is usually deployed in our clients’ organization on cloud. The time it takes to deploy Cortex XDR depends totally upon the organization.
The biggest drawback of Cortex XDR is that it has a heavyweight agent. Cortex XDR would be a good product if this issue could be resolved.
Overall, I rate Cortex XDR an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Servicio Posventa at a security firm with 11-50 employees
A pinpoint evasive threats with patented behavioral analytics solution with a useful policy extension feature
Pros and Cons
- "One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
- "I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs."
What is our primary use case?
Our clients want to correlate information they have in their network. Many engineers or companies have different tools like CMs, firewalls, VPNs, and some other things related to networks. They mentioned that after they acquired the Cortex XDR solution they have all of the information in one place. That is important because they improved the time to solve security issues.
What is most valuable?
One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers.
Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network.
What needs improvement?
I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs.
For how long have I used the solution?
I have worked with Cortex XDR by Palo Alto Network for about four years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Network is a stable solution. I have been working with it for years, and it only went down once.
On a scale from one to ten, I would give stability a nine.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Network is a scalable solution.
How are customer service and support?
Technical support is okay.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward and not very complicated. I think it takes about two hours to deploy this solution. The number of personnel needed depends on the company. For example, banks usually have five cybersecurity engineers installing and maintaining this solution.
On a scale from one to ten, I would give the initial setup a seven.
What's my experience with pricing, setup cost, and licensing?
I don't like that they have different types of licenses.
On a scale from one to nine, I would give licensing costs a seven.
What other advice do I have?
I consider Cortex XDR by Palo Alto Network a good solution. They have good support, and they listen to customer feedback.
On a scale from one to nine, I would give Cortex XDR by Palo Alto Network a nine.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Specialist at Eazzy Solutions
Scalable and high availability
Pros and Cons
- "Cortex XDR by Palo Alto Networks should be a stable solution."
- "Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console."
What is our primary use case?
Cortex XDR by Palo Alto Networks is a network management solution.
What needs improvement?
Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console.
For how long have I used the solution?
I have sold Cortex XDR by Palo Alto Networks within the last 12 months.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks should be a stable solution.
What do I think about the scalability of the solution?
The scalability of Cortex XDR by Palo Alto Networks is very good.
What's my experience with pricing, setup cost, and licensing?
The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month.
What other advice do I have?
I would recommend this solution to others.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Presales Manager at a tech services company with 51-200 employees
Easy to set up with great policy configuration and is an excellent addition to the Palo Alto ecosystem
Pros and Cons
- "It has pretty much everything we need and works well within the Palo Alto ecosystem."
- "The GUI could be improved."
What is our primary use case?
The main use case was the integration with their Palo Alto firewall and Panorama. Apart from that, they also had integration with the FIM solution that they had. Overall, having it at the endpoint and having network integration for the overall threat scenario has been where we use it.
What is most valuable?
The policy configuration is great. The granularity of policies that are available is very helpful.
It is straightforward to set up.
It has pretty much everything we need and works well within the Palo Alto ecosystem.
What needs improvement?
The GUI could be improved. It's a little bit cumbersome. It could be more user-friendly.
For how long have I used the solution?
I've been using the solution for around two years.
What do I think about the stability of the solution?
The solution is quite stable. The only hiccup we had experienced was related to some false alerts where there was no detection, yet still the product showed that it detected something. There were a few false positives. Apart from that, it is quite stable.
What do I think about the scalability of the solution?
For cloud purposes, scaling is not an issue. Even with the on-premises deployments, we have not faced any scaling issues.
How are customer service and support?
Technical support is great. We haven't had any problems with them.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution is very simple and very straightforward to set up. It's not overly difficult or complex.
I'd rate it four out of five in terms of ease of setup.
What's my experience with pricing, setup cost, and licensing?
I do not deal with licensing costs. That is taken care of by our sales team.
What other advice do I have?
We do hybrid deployments. For some customers, it was on the cloud and for some, it was on-prem.
It's a good solution to go with. If you are dealing with the ecosystem of Palo Alto, like Palo Alto firewall, Palo Alto Prisma Access, and Palo Alto XDR, if you have a Palo Alto ecosystem, it's a must to have Cortex XDR. Individually, it also works well. However, having Palo Alto everywhere will be a better scenario or a better fit if you want to deploy Cortex.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Administrator at a tech services company with 1-10 employees
Provides more visibility than expected and lets us know if anything unusual happens on our network
Pros and Cons
- "Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
- "They've been having some issues with updating their endpoint agents, and it has been quite frustrating."
What is our primary use case?
We have Cortex XDR on our endpoints, and we have managed threat hunting. We are using it for everything related to security. If we have a device we believe is compromised, we can do a scan of the device to check for malware. We look for indicators of compromise in our network. We also look for behavioral things, such as if people are, for some reason, sending a bunch of information out. We also monitor USB file copies to make sure sensitive data isn't leaving our systems. It is also for any kind of denial of service attack.
We are using its latest version. It is deployed on-prem. We have agent software on all our endpoints, and then we have on-prem devices managed through Panorama.
How has it helped my organization?
It has quite a bit of functionality. So, if anything weird happens on our network, Cortex normally lets us know.
What is most valuable?
Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful.
What needs improvement?
They've been having some issues with updating their endpoint agents, and it has been quite frustrating.
For how long have I used the solution?
I have been using this solution for about a year.
What do I think about the stability of the solution?
It's incredibly stable. It's Palo Alto; it's top of the line.
What do I think about the scalability of the solution?
It's enterprise-grade. They cover everybody from the federal government to large corporations. We're probably a pretty small network for them. We have about 2,000 endpoints.
How are customer service and support?
I have used their support. I would rate them a four out of five.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used to have Check Point. We switched because there were a lot of added features with Palo Alto that Check Point didn't have. It was an upgrade for us.
How was the initial setup?
It is incredibly complex. It has a lot of parts. Its implementation took six months.
What about the implementation team?
We worked with Palo Alto directly to look at our old firewalls and translate their configuration to Palo Alto.
There are three of us for deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff.
What other advice do I have?
You get out what you put in. So, the more you work with it, customize it, monitor it, and manage it, the more you'll get out of it.
I would rate it an eight out of ten. There are some bug updates that they were having issues with. Everything else has been pretty great. There is a lot more visibility than I expected.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Specialist at a manufacturing company with 1,001-5,000 employees
Useful for monitoring, but its implementation is quite complex
Pros and Cons
- "Monitoring is most valuable."
- "In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex."
What is our primary use case?
It has just been about a month.
How has it helped my organization?
It is mainly for monitoring and/or logging. We look at it to see if there are any log incidents.
We are using its latest version. It is deployed as a hybrid.
What is most valuable?
Monitoring is most valuable.
What needs improvement?
In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex.
In terms of new features, we don't have any functions or features that we would like to add at the moment.
What do I think about the scalability of the solution?
It is looking promising in terms of scalability, but we have not looked into it further because we are still in the process of learning and getting some experience.
Currently, there are just two users of this solution. They are IT specialists.
How was the initial setup?
Its initial setup is quite complex. In terms of complexity, I would rate it a four and a half out of five.
What's my experience with pricing, setup cost, and licensing?
I am using the Community edition.
What other advice do I have?
My advice for people who are looking into implementing this system is that they should be aware of the complexity of the installation and the management of the system. I would preferably buy this from a partner.
We have not yet completed our review of the product. At this time, I would rate it a five out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Consultant at Trillennium (Pvt) Ltd
Excellent technical support, straightforward implementation, and cutting-edge technology
Pros and Cons
- "When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
- "In general, the price could be more competitive."
What is our primary use case?
We are not using it for our purposes because we are a Palo Alto partner. We propose it for our customers based on their requirements.
We are both a service provider and a reseller.
When the pandemic first began, the use cases were mostly for remote users. We deployed this for the majority of remote users.
What is most valuable?
When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud. We have a lot of advantages as a result.
It's a very simple implementation, and I have direct Palo Alto implementation available as well. So it's very simple. We haven't found any issues, so far the implementation is going well, I don't see any gaps.
What needs improvement?
In general, the price could be more competitive.
For how long have I used the solution?
In Palo Alto, we also work with all product lines, including Prisma and other product lines as required. Is a mix, it's a subproduct, we work with the mix of products.
We have been working with Cortex XDR by Palo Alto Networks for two to three years.
We get updates from Palo Alto directly.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is a stable product.
What do I think about the scalability of the solution?
It's a scalable solution, we have not had any challenges with the scalability of Cortex XDR by Palo Alto Networks.
Our customers range from medium to large enterprise companies. The adoption rate in small businesses is much less, but the majority of our requirements come from mid-to enterprise-sized businesses.
How are customer service and support?
Technical support is the best in class, in my opinion, because they have invested heavily in research and development. In terms of comparison and today's challenges, such as security and layers, Palo Alto complies with all of the challenges.
Which solution did I use previously and why did I switch?
In terms of Security, we are working with a few products and a few brands.
We use Palo Alto and we also work with Barracuda. These solutions are used on the web firewall and for email protection.
We work with the entire Barracuda product line, but specifically for email protection and web filtering.
Barracuda Essentials is included with O365 protections, we work with those solutions.
Palo Alto is part of a different vertical layer than Barracuda. It's distinct. They are very different.
How was the initial setup?
The initial setup depends on the environment, but as a technology, I would say it's simple. It's not that difficult.
The length of time it takes for deployment is determined by the project and the surrounding environment. We can only determine the timeframe based on that, pinpointing a specific time period is difficult.
It does not require maintenance because regular updates and monitoring are required. So if there is anything, new patches and the like, it is done automatically, and there is no additional implementation unless there are any infrastructure changes.
What's my experience with pricing, setup cost, and licensing?
In comparison to other competing products, it is based on the customer's needs and the environment. However, when compared to other products, the price is slightly higher, but when considering technology and new innovation, that is the plus I would say when it comes to being XDR.
The price could be more competitive because it is not on the price wall when you go and question Palo Alto XDR. It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable.
What other advice do I have?
So far, it has met all of our requirements, and it should be able to cater to a wide range of product lines.
We must first determine what their business requirements are, as well as what other technical layers we are considering, and then propose the appropriate sizing and solution.
We mostly promote Palo Alto, but it depends on the customer's needs, as well as their budget, infrastructure, and what their business requires, all of those factors come into play when recommending a solution.
When you compare it with other products, I would rate Cortex XDR by Palo Alto Networks a nine out of ten.
It's close to being rated a ten out of ten because of their level of support, and the other is the solution and the most recent technology.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Microsoft Sentinel
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Fortinet FortiClient
Elastic Security
HP Wolf Security
Symantec Endpoint Security
Trellix Endpoint Security Platform
Trend Vision One Endpoint Security
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?