Global Exceptions - Configure Global Exceptions permissions for Endpoints. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Configure Global Exceptions permissions for Endpoints.

Global Exceptions allow security teams to exclude specific items from detection, such as creating hash-based exceptions (SHA256, MD5) and defining path-based exceptions for files and folders.

Note

Global Exceptions are part of the Prevention section and apply to prevention policies/profiles.

Caution

Global Exceptions can significantly impact security coverage. Implement approval workflows and regular exception reviews. Consider requiring dual approval for exception creation.

For more information, see Add a global endpoint policy exception.

Permissions

Description

Roles Example

None

Cannot view the Global Exceptions menu (InventoryEndpointsPolicy ManagementPreventionGlobal Exceptions, and cannot create an exception from an issue or case.

View

Read-only access for the Global Exceptions menu, and cannot create an exception from an issue or case.

  • SOC Tier-1 Analyst: Understanding exceptions helps explain why certain files weren't blocked.

  • SOC Tier-2 Analyst: Exception visibility is critical for understanding why threats may have bypassed protection.

  • Threat Hunter: Exceptions represent potential blind spots. Hunters need visibility.

View/Edit

All view permissions plus managing exceptions, adding an exception from an issue or case, setting exception expiration, and defining execution scope.

  • SOC Tier 3 Analyst: May need temporary exceptions for remediation, requires approval.

  • Security Engineer: Responsible for exception management with proper documentation.