We are still in the testing stages so there is not currently any primary use case beyond the base use of endpoint protection.
This is a recommended solution for total end-to-end protection
Pros and Cons
- "Being a cloud solution it is very flexible in serving internal and external connections and a broad range of devices."
- "Cortex is a very good total solution on the endpoints."
- "The connection to the internet has not performed as expected."
- "As an improvement, I would like to see enhanced connection speeds."
What is our primary use case?
What is most valuable?
Cortex has several good features that I am interested in. There is a nice Sandbox function that is very strong, there is the Traps (endpoint protection) solution, the real-time filtering of suspect linkages is good, and the automatic blocking of suspect behavior is always active and protecting the network.
What needs improvement?
As an improvement, I would like to see enhanced connection speeds. On China's side, we need to set up a local server for the definition updates, and the performance has not been very good for the company when directly connected to the internet. We are a little disappointed with that.
For how long have I used the solution?
We have been using Cortex XDR (Extended Detection and Response) for around two months.
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
894,998 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is stable. From the moment we installed it has been up with no restarts of maintenance until now.
What do I think about the scalability of the solution?
I think that this product is scalable. The testing environment we use right now has around 200 users. In the future, when we deploy it to the company we will move up to around 4,000 users.
How are customer service and support?
The technical support is okay. They have already helped us to fix the installation and then we had an issue and they were available for correction of the problem. They also have made some useful suggestions. So the support team is okay in my estimation.
Which solution did I use previously and why did I switch?
We have been exploring a similar solution. Right now I am also doing testing on Sentinel at the center. This is a similar solution. But we have only just begun testing Sentinel, so we do not really have enough experience with it to comment on the product.
How was the initial setup?
As we just started with Cortex and we are using a cloud solution, I do not have the impression that it was difficult to install and begin using.
What's my experience with pricing, setup cost, and licensing?
The setup costs are a bit higher than some other solutions. Overall it is a little bit expensive, I think. If we could get it for around a 10% discount then that would be a better price point for us.
For our pricing plan, we are not on a subscription, so we do not have to pay every month. We have a yearly license for the product.
The approximate amount we pay per license is around $80 per user per year.
What other advice do I have?
My suggestion for people considering this product is that Cortex is a very good total solution on the endpoints. Because I needed Cortex to work for external and internal users and devices, it helps that it is cloud-based because it is good for working in the office or other locations. So we wanted to have the total end-to-end protection including on the mobile devices, that is what we got. This product will be a good suggestion for people who need the same capability.
On a scale from one to ten where one is the worst and ten is the best, I would rate Cortex XDR as around nine-out-of-ten. The cost is the reason it would not be higher. Nine is good but this is a very good product except for the cost.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant Cybersecurity at a consultancy with 10,001+ employees
An antivirus that provides EDR and XDR, but it is expensive
Pros and Cons
- "The solution's most valuable feature is the user interface."
- "The solution lags to the real-time scenarios here and there."
What is our primary use case?
Cortex XDR by Palo Alto Networks is an antivirus tool that provides EDR and XDR.
What is most valuable?
The solution's most valuable feature is the user interface. I've used other solutions like Cylance and CrowdStrike, but Cortex XDR stands out from all the products. It has also moved to XSIAM. Cortex XDR introduced it long ago, while other tools are implementing it now.
What needs improvement?
The solution lags to the real-time scenarios here and there.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for five years.
What do I think about the stability of the solution?
The solution would have bugs, but we get support 24/7 to deal with them.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is a scalable solution.
How was the initial setup?
The solution’s initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
Cortex XDR by Palo Alto Networks is an expensive solution.
What other advice do I have?
Cortex XDR by Palo Alto Networks is a cloud-based solution. I would recommend the solution to other users if they can afford it. Cortex XDR by Palo Alto Networks is worth the money. It is easy for a beginner to learn to use the solution for the first time.
Overall, I rate the solution a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
894,998 professionals have used our research since 2012.
Business Development Manager For Palo Alto Networks at a tech services company with 1,001-5,000 employees
Has a simple setup process and efficient stability
Pros and Cons
- "The product's most valuable features are massive user and feature intelligence exploit detection."
- "It is an enterprise-level solution. Its price could be less expensive."
What is our primary use case?
We use the product as a detection and response application.
What is most valuable?
The product's most valuable features are massive user and feature intelligence exploit detection. It is very useful in detecting threats to databases. The last meter statistics prove the efficient capabilities of the solution.
What needs improvement?
It is an enterprise-level solution. Its price could be less expensive.
For how long have I used the solution?
We have been using Cortex XDR by Palo Alto Networks for three years.
What do I think about the stability of the solution?
The product is 100% stable. I have never received any complaints from the customers.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is easily scalable as it is a cloud-based product.
How are customer service and support?
We provide support services for our customers. Palo Alto's support services are expensive, and customers also encounter language barriers.
How was the initial setup?
The initial process is simple. It requires training of about three to four days to understand the installation process. It is deployed on the cloud. The number of software engineers required depends on the number of the endpoints.
What's my experience with pricing, setup cost, and licensing?
We pay in advance for the product's license. It has reasonable pricing for the use cases it provides to the company. We can split this payment monthly, quarterly, or yearly, according to the customer's requirements. For a cost-benefit analysis when choosing a security solution, consider factors such as the number of attacks prevented, the impact of those attacks, potential losses, and other hidden costs.
What other advice do I have?
I rate Cortex XDR by Palo Alto Networks for ten out of ten. It could be improved from a commercial perspective. It could approach the SMB market as well.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
A stable and scalable solution with good customer support
Pros and Cons
- "The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
- "The product's pricing could be better."
What is our primary use case?
We use the solution for telemetry and for its anti-virus capability.
What is most valuable?
The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better.
What needs improvement?
The product's pricing could be better.
For how long have I used the solution?
I have been using the tool for several years.
What do I think about the stability of the solution?
The solution is stable. I would rate its stability a nine out of ten.
What do I think about the scalability of the solution?
The product is scalable.
How are customer service and support?
The technical support team is good.
How was the initial setup?
The initial setup was easy.
What was our ROI?
The tool is worth its money.
What other advice do I have?
I would rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Servicio Posventa at a security firm with 11-50 employees
A pinpoint evasive threats with patented behavioral analytics solution with a useful policy extension feature
Pros and Cons
- "One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
- "I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs."
What is our primary use case?
Our clients want to correlate information they have in their network. Many engineers or companies have different tools like CMs, firewalls, VPNs, and some other things related to networks. They mentioned that after they acquired the Cortex XDR solution they have all of the information in one place. That is important because they improved the time to solve security issues.
What is most valuable?
One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers.
Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network.
What needs improvement?
I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs.
For how long have I used the solution?
I have worked with Cortex XDR by Palo Alto Network for about four years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Network is a stable solution. I have been working with it for years, and it only went down once.
On a scale from one to ten, I would give stability a nine.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Network is a scalable solution.
How are customer service and support?
Technical support is okay.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward and not very complicated. I think it takes about two hours to deploy this solution. The number of personnel needed depends on the company. For example, banks usually have five cybersecurity engineers installing and maintaining this solution.
On a scale from one to ten, I would give the initial setup a seven.
What's my experience with pricing, setup cost, and licensing?
I don't like that they have different types of licenses.
On a scale from one to nine, I would give licensing costs a seven.
What other advice do I have?
I consider Cortex XDR by Palo Alto Network a good solution. They have good support, and they listen to customer feedback.
On a scale from one to nine, I would give Cortex XDR by Palo Alto Network a nine.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and security engineer at a tech services company with 11-50 employees
Easy to set up and won't slow down your system but is expensive
Pros and Cons
- "It'll not slow down your system when compared to others."
- "If you are looking to deploy a security solution as a whole, this is a good option."
- "We would also like to have advanced tech protection and email scanning."
- "We would also like to have advanced tech protection and email scanning."
What is our primary use case?
I'm testing the product right now. I use the solution for endpoint security.
What is most valuable?
Everything is fine.
It'll not slow down your system when compared to others.
The initial setup is easy.
What needs improvement?
I'd like the solution to provide URL filtering and web-based prevention. We'd like to block web pages at a high level.
We would also like to have advanced tech protection and email scanning.
For how long have I used the solution?
I've been using the solution for a year.
What do I think about the stability of the solution?
The product is very stable and the performance is good. It doesn't slow down the systems it runs on. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution can scale well.
More than 100 people are using the solution right now.
How are customer service and support?
We've never needed the assistance of technical support just yet.
Which solution did I use previously and why did I switch?
I've also used McAfee MVISION Endpoint.
I'm testing them both and finding the advantages and disadvantages between them.
How was the initial setup?
The solution is very easy to set up.
What's my experience with pricing, setup cost, and licensing?
You do have to pay for a license in order to use a solution. It's expensive.
What other advice do I have?
We're a reseller.
We are using the latest, most up-to-date version, of the product.
I would recommend using it with another protection layer. Cortex should provide an additional layer of security apart from this. You might have to integrate with other vendors also.
If you are looking to deploy a security solution as a whole, this is a good option.
I'd rate the solution seven out of ten. If we had more advanced security features, I'd rate it higher.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
ISEC Unit Manager at a tech services company with 11-50 employees
We can manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus
Pros and Cons
- "Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
- "Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
- "Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
- "Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
What is our primary use case?
We have deployed Cortex XDR for a couple of clients in manufacturing.
What is most valuable?
Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus.
What needs improvement?
The dashboard could be more user-friendly.
For how long have I used the solution?
I've been using Cortex XDR for two years.
What do I think about the stability of the solution?
Cortex XDR is stable enough.
What do I think about the scalability of the solution?
Cortex's scalability is good. We have about 200 users on it at the moment.
How are customer service and support?
Palo Alto support is great.
How was the initial setup?
Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied. We need two people to deploy and maintain the solution.
What's my experience with pricing, setup cost, and licensing?
Our clients pay for the license every year. It's just a standard fee with no additional costs.
What other advice do I have?
I rate Cortex XDR eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Account Manager at CIPHER
Easy to use and good for managed threat hunting and incident response
Pros and Cons
- "Cortex XDR can integrate the firewalls and determine the tendencies of the attacks. It's a new generation antivirus, with protection endpoints and detection response. It is very easy to use and everybody can operate the solution."
- "It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
- "It is not easy to sell Cortex XDR, not because it isn't a good tool. Its marketing needs to be improved."
- "It is not easy to sell Cortex XDR, not because it isn't a good tool."
What is our primary use case?
My customer wanted to use EDR. We worked with the POC to demonstrate the antivirus and how it has more features for detecting threats.
How has it helped my organization?
It makes it easier and faster to investigate problems and incidents.
What is most valuable?
The most valuable features are that it can integrate the firewalls and determine the tendencies of the attacks.
It investigates problems and incidents quickly. Cortex is good at reducing alerts and for having a custom barrier. It's a new generation antivirus, with protection endpoints and detection response.
Cortex detects and shows what the problem is and how to resolve the problem or incident. Cortex is very easy to use and everybody can operate the solution.
It has tools for threat hunting and it has very good incident response features.
What needs improvement?
It is not easy to sell Cortex XDR, not because it isn't a good tool. Its marketing needs to be improved.
For how long have I used the solution?
I've been using it for a year.
How was the initial setup?
Setting it up is very simple.
What's my experience with pricing, setup cost, and licensing?
It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool.
What other advice do I have?
I'm rating this solution a ten out of ten because it is very good for managed threat hunting and incident response. It is the best XDR solution. It's better than other tools because it uses enterprise architecture. Everybody will find that this solution is easy to use.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Extended Detection and Response (XDR) Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
IBM Security QRadar
Microsoft Sentinel
Varonis Platform
Elastic Security
HP Wolf Security
Trellix Endpoint Security Platform
TrendAI Vision One
WatchGuard Firebox
Microsoft Defender XDR
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?














