My primary use of this solution is as an endpoint security client.
EMEA IT Infrastructure Manager at a consumer goods company with 5,001-10,000 employees
Good management capabilities but has poor performance
Pros and Cons
- "The management capabilities, allow an IT organization to get quite a good picture of attempted cyber attacks."
- "Impact on system performance is horrible, adding a lot of delays for users."
What is our primary use case?
How has it helped my organization?
This product has not improved my organization - in fact, we are in the process of moving back to another product as a result of Cortex's horrible impact on system performance.
What is most valuable?
The most valuable features of this product are the management capabilities, which allow an IT organization to get quite a good picture of attempted cyber attacks, and its out-of-the-box investigation capabilities.
What needs improvement?
The product's impact on system performance is horrible, adding a lot of delays for users.
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
For how long have I used the solution?
I have been using this solution for four months.
How was the initial setup?
The onboarding process was quite cumbersome. It took some time to deploy as we had to investigate about 500 cases of clients who did not get the agent immediately.
What about the implementation team?
I implemented using a vendor team.
What other advice do I have?
I would rate this solution as five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

A stable and scalable solution with an easy setup and out-of-the-box playbooks and integration
Pros and Cons
- "The integrations are out-of-the-box, as are the playbooks."
- "The solution should offer more dashboards and they should be better customized."
What is our primary use case?
I have deployed some customized playbooks and modified ones which are out-of-the-box with more integration with SIEM solutions such as ArcSight, QRadar, ADRs and Trend Micro.
What needs improvement?
The solution should offer more dashboards and they should be better customized. The case number of items should be addressed.
I have found the interface of Azure to be more simple and customizable than that of the solution.
For how long have I used the solution?
I have worked on Cortex XDR by Palo Alto Networks with my customers for a number of weeks.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
The scalability is fine.
We have plans to increase the usage.
How was the initial setup?
The initial setup was simple.
The deployment took no more than two hours.
What's my experience with pricing, setup cost, and licensing?
So far, I have made use of the free license which is offered. Once it ended, I was able to buy a license based on the number of users or divisions. The license varies with the number of users or applications involved.
If one wishes to work with another team or large number of users at a future point, he must purchase a license for them.
Which other solutions did I evaluate?
The interface of Azure is more simple and customizable than Cortex XDR by Palo Alto Networks.
What other advice do I have?
I have found the solution to be very easy in respect of the integration and configurable. The integrations are out-of-the-box, as are the playbooks.
The solution is deployed solely on-premises on a single server.
As of now, there are six users making use of the solution.
My advice is that the on-premises environments for the product's use should be increased.
I rate Cortex XDR by Palo Alto Networks as an eight out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
IT manager at a computer software company with 11-50 employees
Provides ability to see what's going on with your assets and react to cyber attacks
Pros and Cons
- "Its ability to react to cyber data attacks is awesome. That is pretty much the use of it. What blows your mind is the ability to access your assets remotely and see what is actually going on with them. You can not only see them in a console. You can also react very rapidly to your assets that are compromised."
- "It should support more mobile operating systems. That is one of the cons of their infrastructure right now."
What is our primary use case?
I use it for visibility, mitigation, and analysis of advanced threat attacks.
What is most valuable?
Its ability to react to cyber data attacks is awesome. That is pretty much the use of it. What blows your mind is the ability to access your assets remotely and see what is actually going on with them. You can not only see them in a console. You can also react very rapidly to your assets that are compromised.
What needs improvement?
It should support more mobile operating systems. That is one of the cons of their infrastructure right now.
For how long have I used the solution?
I have been using this solution for more than four years.
What do I think about the stability of the solution?
It has been extremely stable.
What do I think about the scalability of the solution?
It is easily scalable. For example, if you have version 2, Palo Alto upgrades it automatically. The agents for your assets are also scalable for new operating systems. So, it is very scalable.
How are customer service and technical support?
Their technical support is very agile and very good. I would rate them a nine out of 10.
How was the initial setup?
It is way too easy to deploy it and set it up.
What other advice do I have?
I would highly recommend it unless you have iOS assets on your network.
I would rate Cortex XDR an eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer:
Assistant PhD at Stefan Cel Mare University of Suceava
Good technical support , reasonable pricing, and has good detection capabilities
Pros and Cons
- "Threat identification and detection are the most valuable features of this solution."
- "I would like to see some additional features related to email protection included."
What is most valuable?
Threat identification and detection are the most valuable features of this solution.
What needs improvement?
I would like the Panorama module included. It's another solution that is provided by Palo Alto and we are interested in that.
I would like to see some additional features related to email protection included.
For how long have I used the solution?
I have been working with Cortex XDR for a year and a half.
How are customer service and technical support?
Technical support is okay.
What's my experience with pricing, setup cost, and licensing?
I don't have any issues with the pricing. We are satisfied with the price.
What other advice do I have?
I would rate Cortex XDR by Palo Alto Networks a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General manager at a tech services company with 201-500 employees
Highly scalable, effective intelligence, and reliable
Pros and Cons
- "One of the main benefits of the solution is its intelligence to correlate the events into an incident."
- "The solution could improve by providing better integration with their own products and others."
What is our primary use case?
I use the solution for endpoint protection.
What is most valuable?
One of the main benefits of the solution is its intelligence to correlate the events into an incident.
What needs improvement?
The solution could improve by providing better integration with their own products and others.
For how long have I used the solution?
I have been using this solution for approximately one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
It is one of the best in the market for scalability.
We have approximately 500 people using this solution in my organization and we plan to increase usage.
How was the initial setup?
The initial installation is easy.
What about the implementation team?
We did the implantation of the solution with integrators.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is high for the license and in general.
Which other solutions did I evaluate?
We evaluated CrowedStrike and Darktrace.
What other advice do I have?
I would recommend this solution to others.
I rate Cortex XDR by Palo Alto Networks a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Relationship Manager at a financial services firm with 5,001-10,000 employees
Easy to use, but can have more security and integrations
Pros and Cons
- "It is easy to use."
- "Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
What is our primary use case?
We use it for malicious connections from malicious websites. There might also be some payloads that might be inside the traffic. We also use it to identify malicious processes or bugs that are running on the network and any activities that tend to lead to data infiltration.
What is most valuable?
It is easy to use.
What needs improvement?
Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms.
For how long have I used the solution?
I have been using this solution for about a year.
What do I think about the scalability of the solution?
We have maybe a thousand users of this solution because it is deployed on-prem.
How was the initial setup?
I don't think there were issues with the installation.
What's my experience with pricing, setup cost, and licensing?
It has a yearly renewal.
What other advice do I have?
I would recommend this solution. I would rate Cortex XDR a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security consultant at a computer software company with 1,001-5,000 employees
Sophisticated user interface, stable, and scalable
Pros and Cons
- "The user interface of the solution is sophisticated and straightforward."
- "In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
What is our primary use case?
We use this solution to protect our computer system against threats, such as exploits and malware.
What is most valuable?
The user interface of the solution is sophisticated and straightforward.
What needs improvement?
In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution.
For how long have I used the solution?
I have been using this solution for approximately two months.
What do I think about the stability of the solution?
The solution is stable, we have not had any issues.
What do I think about the scalability of the solution?
We have over 5,000 employees and they are being managed through this solution. It is scalable.
How are customer service and technical support?
We have our own IT support teams.
Which solution did I use previously and why did I switch?
We were previously using McAfee and we switched to this solution because they failed to provide us proper protection.
How was the initial setup?
We have an IT support team in our organization and they are managing everything remotely, such as laptops.
What about the implementation team?
Our internal team did the implementation of the solution.
What other advice do I have?
I would recommend this solution to others.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Security Engineer at ESKA
Scalable with excellent protection features and is very user-friendly
Pros and Cons
- "The solution doesn't need a high level of technical training."
- "Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well."
What is our primary use case?
Cortex XDR is used for endpoint detection and response. This is software placed into endpoints and work in this cloud. In cloud has the analytics, login, prevention models, et cetera.
What is most valuable?
If a company uses Palo Alto and supports Cortex XDR for endpoint protection it is very well protected. Palo Alto is the best security solution in the market. It's very advanced and its protection is extremely reliable.
The solution doesn't need a high level of technical training. The solution is very usable and doesn't take a lot of personnel.
The product is very scalable.
The stability is very good.
What needs improvement?
For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible.
Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well.
For how long have I used the solution?
I've been working with this security solution for ten years or so and Palo Alto Networks for two years.
What do I think about the stability of the solution?
The solution has been very stable and very reliable. There are no bugs or glitches. It doesn't crash or freeze. It's one of the best on the market.
What do I think about the scalability of the solution?
The solution is very scalable. It works well for companies that are quite sizeable. If an organization needs to expand it, it can do so easily.
We have about 50 to 55 users on the solution.
How are customer service and technical support?
I personally handle technical questions for those working with Palo Alto.
Support of Palo Alto is English, however, I work in this local technical solution, local technical and I'm working with customers with a warranty.
I've found technical support from Palo Alto to be very good. We're local and we can assist as well, however, Palo Alto is capable of handling any size of issue and they are quite helpful.
How was the initial setup?
I am not directly handling the installation. My client is.
You do need a team of people on this solution that understand the cloud and the solution itself if you have a large, complex environment. If you have a robust security team, it's good. However, if you don't have the resources, it's not an ideal product.
That said, if your company requires a small, simple setup, one person may be enough. It really depends on the size.
What about the implementation team?
My client is actually handling the installation. I often field questions from them, however, I don't participate in the installation directly.
What's my experience with pricing, setup cost, and licensing?
For basic needs, the solution isn't very expensive. However, as you grow more complex in your needs, the more you use, the more costly it can get.
The licensing is typically for one year. There's a one-time installation. If you would like to continue with the service, you can continue. There's no need to install and reinstall.
What other advice do I have?
Cortex XDR is a threat analytics security manager that allows users to see what threats are going to endpoints. It's a very high-security solution.
The next step up from Cortex XDR is Cortex XSOAR. XSOAR is an automated threat solution. It's a security solution from Palo Alto.
I'd recommend the solution to others. I'd rate it at a nine out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator

Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Microsoft Sentinel
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Fortinet FortiClient
Elastic Security
HP Wolf Security
Symantec Endpoint Security
Trellix Endpoint Security Platform
Trend Vision One Endpoint Security
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?