Verify configuration and app installation - Verify that configuration and deployment were successful. - Administrator Guide - 8.9 - 9.2 - Cortex XDR Agent - Cortex XDR - Advanced Endpoint Protection - Cortex - Security Operations

Cortex XDR Agent iOS App

Product
Cortex XDR Agent
Cortex XDR
Version
9.2
Creation date
2026-06-01
Last date published
2026-06-30
Category
Administrator Guide
Abstract

Verify that configuration and deployment were successful.

Verify that configuration and deployment were successful.

On the Intune console
Verify configuration profiles (Notifications and Network Filter)

For the profiles configured under Configuration profiles (for example, Cortex XDR Notifications or Cortex XDR Network Content Filter):

  1. Go to Devices+iOS/iPadOS+Configuration profiles.

  2. Click the specific policy name you want to check (for example, Cortex XDR Notifications or Cortex XDR Network Content Filter).

  3. On the Overview page, check the statuses on the Device status and User status charts.

  4. Ensure that the status bar shows a green indicator for Succeeded.

    • You can also view the Device install status report to see all devices targeted by the policy.

    • The Per setting status report allows you to view the success of each individual setting within the policy.

Verify app configuration policy (XML settings)

For the policy configured under App configuration policies (where the Distribution ID and user tokens were added):

  1. Go to Apps+App configuration policies.

  2. Click the policy name (for example, Cortex XDR).

  3. In the Overview section, check the status on the Device Status ring chart.

  4. Verify that the Device status shows Succeeded (indicated by a green section in the chart).

Verify app installation status

To ensure the app itself is installed (which is a prerequisite for the configurations to apply):

  1. Go to Apps+iOS/iPadOS+iOS/iPadOS apps, and select Cortex XDR.

  2. To check installation status, in the Monitor section, click Device install status.

  3. To confirm installation, look for the Installed status in the device list.

On the iOS devices

After the policies are deployed from Intune, perform the following checks on the managed iOS device, to confirm they have been applied successfully.

Check device management profiles
  1. Open the Settings app on the iOS device.

  2. Go to General+VPN & Device Management.

  3. Verify that Content Filter is listed under Restrictions and Proxies.

  4. Ensure the status shows Running (Note: It might initially appear as Invalid before the app fully initializes).

  5. Tap Content Filter to confirm it is actively managed by Cortex XDR.

Verify notification settings
  1. In the Settings app, scroll down, and select the Cortex XDR app.

  2. Tap Notifications.

  3. Confirm that Allow Notifications is toggled ON.

  4. Verify that Critical Alerts and Time-Sensitive Notifications are enabled.

  5. Ensure all alert styles (Lock Screen, Notification Center, Banners) are checked and active.

  6. Confirm that Show Previews is set to Always (Default).

Validate app installation and protection status
  1. Open the Cortex XDR app from the home screen.

  2. The app should launch and automatically connect without requiring manual login credentials.

  3. Wait for the app to complete its initial checkup. You will see a progress circle indicating Contacting Server, Performing Checkup, and Updating Policies.

  4. Confirm the status updates to a green shield icon displaying Checkup performed! or Protected.

  5. Tap the Settings tab (bottom right) to view details such as the Distribution ID and Endpoint ID, confirming the policy values were successfully received.

Verify module activation
  1. Inside the Cortex XDR app, tap the Modules tab (bottom left).

  2. Verify that Basic requirements (Notifications & Background app refresh) and Network Shield are marked as Active with a green dot.

Test app removal restriction
  1. Attempt to remove the Cortex XDR app from the home screen.

  2. You should see a system alert stating Uninstall Not Allowed, confirming that the app is managed and required by your organization.