Alright, let's add another notch to the "modern security suite vs. actual infrastructure" bedpost. I'm in the middle of a forced migration from a legacy on-prem SIEM to Cortex XDR (don't ask, it was a C-level decision after a slick demo). The agent deployment is, predictably, where the fantasy meets the dusty reality of our server room.
The Pro version agent (v8.x) simply refuses to install on our remaining Windows Server 2012 R2 boxes. The installer runs, does its thing, and then the service fails to start with a cryptic error in the Windows Event Log about a "module initialization failure." No helpful guidance from the Palo Alto docs, which seem to assume the world is running Server 2016 or later.
Before I get the usual "it's EOL, upgrade" lecture from support—we know. This is a phased, multi-year project. Right now, these boxes run a legacy line-of-business app that can't be moved yet, but they still need security coverage.
Has anyone else hit this wall? I've tried:
* Running the installer with every compatibility setting and admin privilege imaginable.
* Disabling other AV/EDR temporarily (a thrilling risk on a legacy OS).
* Manually extracting the MSI and pushing it via our RMM tool—same result.
The core question I'm getting at: is there a known, specific prerequisite or blocker for Server 2012 R2 that Palo Alto isn't advertising? Or is this their quiet way of forcing infrastructure upgrades? I'm looking for a workaround, not a lecture on Microsoft's lifecycle policy. If the agent genuinely can't run here, that's a major mark against Cortex XDR's claimed "broad compatibility" for my evaluation matrix.