We don't have many customers moving to Cortex XDR by Palo Alto Networks. But recently, we started offering them both pro and basic options.
Digital Business Solutions Manager at Bahrain Telecommunication Company BSC (Batelco)
A stable and scalable extended detection and response platform, but it would be better if they educated their customers more
Pros and Cons
- "It's a nice product that's stable and scalable."
- "It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."
What is our primary use case?
What is most valuable?
It's a nice product that's stable and scalable.
What needs improvement?
It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support.
What do I think about the stability of the solution?
The product is stable. Palo Alto only works on security, and the product by default is stable. They are releasing new features, OS, and an ML-based thing on the firewall itself, which is quite impressive. Palo Alto is quite stable compared to other competitors in the market.
Buyer's Guide
Cortex XDR by Palo Alto Networks
February 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It's scalable. I see whatever is written on their datasheets, and all it's real. If I talk to some other vendor and they say that they currently provide 20 Gbps reports, but when you activate it, IPSec and all, it goes to 2 Gbps. With Palo Alto, whatever is there is working, and it's scalable.
How are customer service and support?
Technical support is quite good. When compared to others, I feel it's quite impressive.
What's my experience with pricing, setup cost, and licensing?
The price is on the higher side, but it's okay.
What other advice do I have?
I would tell potential users that it's a complete solution from Palo Alto with firewalls and all to give you more precise logs and information. Product-wise, it's top of the line. If you have investment, always go for that and go for the best solution.
Palo Alto is one of the tech vendors that always provides top-of-the-line products. Price-wise it will be on the higher side, but it depends on how you deal with the backend support or the account manager of Palo Alto to get that discount.
On a scale from one to ten, I would give Cortex XDR by Palo Alto Networks a seven.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner

Cyber Security Engineer at ACPL
Performs stitching between a number of security domains
Pros and Cons
- "We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action."
- "Cortex XDR should have a lightweight agent, and the agent size should not be heavy."
What is our primary use case?
Cortex XDR does the stitching between a number of security domains, like email security, API security, and web security. The solution does the stitching from different sources and makes a logical incident.
What is most valuable?
We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action. We don't need to navigate different solutions and tools or use our human intelligence to correlate all the information to make the logic. Cortex XDR entirely does it, and we can take action.
What needs improvement?
Cortex XDR should have a lightweight agent, and the agent size should not be heavy. Cortex XDR’s technical support should also be improved.
Cortex XDR should provide a feature to remove or uninstall an agent directly from the console itself without the help of an IT engineer. No one wants to do a manual installation of the agent. Everyone is looking for a solution to remove the agent from the console directly.
For how long have I used the solution?
I have been working with Cortex XDR by Palo Alto Networks for two years.
What do I think about the stability of the solution?
I rate Cortex XDR a ten out of ten for stability.
What do I think about the scalability of the solution?
I rate Cortex XDR a five out of ten for scalability.
How are customer service and support?
The technical support of Cortex XDR and other OEM products is not very good. Cortex XDR's technical support does not usually respond quickly.
How would you rate customer service and support?
Neutral
How was the initial setup?
I rate Cortex XDR’s initial setup an eight out of ten.
What's my experience with pricing, setup cost, and licensing?
Cortex XDR’s pricing is very reasonable. I rate Cortex XDR a five out of ten for pricing.
What other advice do I have?
I am using the latest version of Cortex XDR by Palo Alto Networks. Cortex XDR is usually deployed in our clients’ organization on cloud. The time it takes to deploy Cortex XDR depends totally upon the organization.
The biggest drawback of Cortex XDR is that it has a heavyweight agent. Cortex XDR would be a good product if this issue could be resolved.
Overall, I rate Cortex XDR an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Buyer's Guide
Cortex XDR by Palo Alto Networks
February 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Cloud Specialist at Eazzy Solutions
Scalable and high availability
Pros and Cons
- "Cortex XDR by Palo Alto Networks should be a stable solution."
- "Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console."
What is our primary use case?
Cortex XDR by Palo Alto Networks is a network management solution.
What needs improvement?
Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console.
For how long have I used the solution?
I have sold Cortex XDR by Palo Alto Networks within the last 12 months.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks should be a stable solution.
What do I think about the scalability of the solution?
The scalability of Cortex XDR by Palo Alto Networks is very good.
What's my experience with pricing, setup cost, and licensing?
The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month.
What other advice do I have?
I would recommend this solution to others.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
A stable and scalable solution with good customer support
Pros and Cons
- "The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
- "The product's pricing could be better."
What is our primary use case?
We use the solution for telemetry and for its anti-virus capability.
What is most valuable?
The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better.
What needs improvement?
The product's pricing could be better.
For how long have I used the solution?
I have been using the tool for several years.
What do I think about the stability of the solution?
The solution is stable. I would rate its stability a nine out of ten.
What do I think about the scalability of the solution?
The product is scalable.
How are customer service and support?
The technical support team is good.
How was the initial setup?
The initial setup was easy.
What was our ROI?
The tool is worth its money.
What other advice do I have?
I would rate the solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Site administrator officer at a tech services company with 11-50 employees
Effective machine learning capabilities, responsive support, and easy to understand
Pros and Cons
- "The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
- "Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
What is our primary use case?
Cortex XDR is used for monitoring and securing large numbers of endpoints, typically in the range of 5,000 to 10,000. It is considered to be an effective solution for mitigating security risks in these environments.
What is most valuable?
The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions.
What needs improvement?
Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for approximately four months.
What do I think about the stability of the solution?
The solution is stable.
I rate the stability of Cortex XDR by Palo Alto Networks an eight out of ten.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is a highly scalable solution.
I rate the scalability of Cortex XDR by Palo Alto Networks an eight out of ten.
How are customer service and support?
The support team at Cortex XDR by Palo Alto Networks is very responsive and helpful in addressing any issues or challenges that may arise. They are highly accessible and knowledgeable about the products they offer. Overall, I have been very satisfied with the support provided by Palo Alto while deploying their solutions.
Which solution did I use previously and why did I switch?
We previously used CrowdStrike Falcon X.
Cortex XDR by Palo Alto Networks is easier to understand and use compared to CrowdStrike Falcon X endpoint. The dashboard and interface of CrowdStrike Falcon X can be cluttered, making it difficult for some users to understand where to begin when it comes to incident response or threat hunting. In contrast, Cortex XDR by Palo Alto Networks is simple to navigate and understand.
How was the initial setup?
The initial setup of the solution can take approximately one hour. One hour is the longest it has ever taken us for the setup. We have not had an issue with the setup.
I rate the initial setup of Cortex XDR by Palo Alto Networks a seven out of ten.
What about the implementation team?
We do the implementation of the solution.
What's my experience with pricing, setup cost, and licensing?
The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help.
Customers tend to rather have a less expensive solution than the best one.
I rate the price of Cortex XDR by Palo Alto Networks an eight out of ten.
What other advice do I have?
We are using two engineers for the maintenance of the solution.
In our market here in Malaysia, the solution is perceived as being of high quality and providing good service.
I would recommend this solution to others, it is a good solution. It is my job to recommend solutions.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
The solution is not perfect and that is why I gave the rating of eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
CIO/CTO at a manufacturing company with 501-1,000 employees
Good GUI, however lacks features overall and tends to eat memory
Pros and Cons
- "They have a new GUI which is just fantastic."
- "There's an overall lack of features."
What is our primary use case?
We primarily use the solution for our endpoint server and endpoint protection.
What is most valuable?
There aren't many features we find valuable on the solution.
They have a new GUI which is just fantastic.
What needs improvement?
The solution eats memory of the computer, unlike anything I've ever seen. It eats more memory than Chrome.
I have a lot of users that are eating my memory each hour every day and it's causing us problems. We have to go and buy more memory for each computer. When you have a lot of computers like we do, is not a very good situation.
Some of the computers are only using 4 GB of memory, so if you put aside the differences, most only have some Chrome, some internet, and Office and that's it. And yet, the memory is getting eaten.
If someone catches something like malware, or something else, I want to know if the file was spread to other machines and what the target was. I want to be able to get ahead of the spread. This solution doesn't do enough to protect us against these types of vulnerabilities or to give us much information about the spread. The tool really does need some more reverse engineering features.
There's an overall lack of features.
The initial setup could use improvement. Currently, I must go to each machine and deploy everything manually. We are in 2020, not in 1980. It seems like such a dated way of doing large deployments.
For how long have I used the solution?
I've been using the solution for a year and a half.
What do I think about the stability of the solution?
When I was experimenting with stability early on, I did run into issues when testing the solution in the sandbox.
Eventually, it catches one of the executive files and if you go to the management section of the solution and you release this file, it takes seven or eight tries to do it. You need to keep trying, again and again, using the same procedures to release the file for usage. That was in the beginning and we still have this issue, even though they made a new GUI for management. It's still not resolved.
What do I think about the scalability of the solution?
We have several hundred users.
I had some issues initially in the sandbox when I was testing scalability.
How are customer service and technical support?
I have reached out to technical support in the past. I find dealing with them is like talking to a wall. They aren't terrible, however, you don't really get any guidance. They ask over and over to get us to send them dump files and we do over and over. After all of the back and forth, nothing is really resolved to our satisfaction. You're paying for their services, and you don't get the level of service you would expect. It's a pain point.
How was the initial setup?
The initial setup was not complex. It was very straightforward.
The deployment did take a lot of time due to the fact that we had seven hundred computers.
What other advice do I have?
We simply use the solution as a customer.
I would not recommend the solution. I'd advise other companies to rather go with Palo Alto's firewall as a better option. I've already advised others not to touch it. It's not worth it at all to even consider using it.
I'd rate the solution six out of ten. Their new GUI is very nice, however, as a professional service, it's lacking in a lot of areas.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Servicio Posventa at a security firm with 11-50 employees
A pinpoint evasive threats with patented behavioral analytics solution with a useful policy extension feature
Pros and Cons
- "One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
- "I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs."
What is our primary use case?
Our clients want to correlate information they have in their network. Many engineers or companies have different tools like CMs, firewalls, VPNs, and some other things related to networks. They mentioned that after they acquired the Cortex XDR solution they have all of the information in one place. That is important because they improved the time to solve security issues.
What is most valuable?
One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers.
Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network.
What needs improvement?
I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs.
For how long have I used the solution?
I have worked with Cortex XDR by Palo Alto Network for about four years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Network is a stable solution. I have been working with it for years, and it only went down once.
On a scale from one to ten, I would give stability a nine.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Network is a scalable solution.
How are customer service and support?
Technical support is okay.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward and not very complicated. I think it takes about two hours to deploy this solution. The number of personnel needed depends on the company. For example, banks usually have five cybersecurity engineers installing and maintaining this solution.
On a scale from one to ten, I would give the initial setup a seven.
What's my experience with pricing, setup cost, and licensing?
I don't like that they have different types of licenses.
On a scale from one to nine, I would give licensing costs a seven.
What other advice do I have?
I consider Cortex XDR by Palo Alto Network a good solution. They have good support, and they listen to customer feedback.
On a scale from one to nine, I would give Cortex XDR by Palo Alto Network a nine.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Presales Manager at Doyen
Easy to set up with great policy configuration and is an excellent addition to the Palo Alto ecosystem
Pros and Cons
- "It has pretty much everything we need and works well within the Palo Alto ecosystem."
- "The GUI could be improved."
What is our primary use case?
The main use case was the integration with their Palo Alto firewall and Panorama. Apart from that, they also had integration with the FIM solution that they had. Overall, having it at the endpoint and having network integration for the overall threat scenario has been where we use it.
What is most valuable?
The policy configuration is great. The granularity of policies that are available is very helpful.
It is straightforward to set up.
It has pretty much everything we need and works well within the Palo Alto ecosystem.
What needs improvement?
The GUI could be improved. It's a little bit cumbersome. It could be more user-friendly.
For how long have I used the solution?
I've been using the solution for around two years.
What do I think about the stability of the solution?
The solution is quite stable. The only hiccup we had experienced was related to some false alerts where there was no detection, yet still the product showed that it detected something. There were a few false positives. Apart from that, it is quite stable.
What do I think about the scalability of the solution?
For cloud purposes, scaling is not an issue. Even with the on-premises deployments, we have not faced any scaling issues.
How are customer service and support?
Technical support is great. We haven't had any problems with them.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution is very simple and very straightforward to set up. It's not overly difficult or complex.
I'd rate it four out of five in terms of ease of setup.
What's my experience with pricing, setup cost, and licensing?
I do not deal with licensing costs. That is taken care of by our sales team.
What other advice do I have?
We do hybrid deployments. For some customers, it was on the cloud and for some, it was on-prem.
It's a good solution to go with. If you are dealing with the ecosystem of Palo Alto, like Palo Alto firewall, Palo Alto Prisma Access, and Palo Alto XDR, if you have a Palo Alto ecosystem, it's a must to have Cortex XDR. Individually, it also works well. However, having Palo Alto everywhere will be a better scenario or a better fit if you want to deploy Cortex.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cisco Secure Endpoint
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
HP Wolf Security
Check Point Harmony Endpoint
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?