Alright, fellow Cortex explorers, I've hit a deployment scenario that’s got me scratching my head and running some... let's call them "unplanned experiments" on my own 😅.
We're a pretty hybrid company, and our official stance is "VPN is available but not mandatory." In practice, this has created a growing class of users—especially in sales, design, and exec roles—who are *never* on the corporate VPN. Their laptops are corporate-managed (we use Intune for basic compliance/policy), but they live on home networks, coffee shop Wi-Fi, you name it. They’re productive and happy, but from a security tooling perspective, they’re essentially untethered satellites.
Our team wants to roll out Cortex XDR to these endpoints, and the classic "push via VPN/on-network" deployment method is a non-starter. I’m digging into the options and would love to compare notes on what’s actually working in the wild.
Here’s what I’ve been testing/considering:
* **The direct download/installer approach:** Just sending users a link to the installer and having them run it. Feels a bit... manual and trust-based. How are you handling initial credential/bootstrap for the agent to phone home correctly without a pre-configured network path? Are you wrapping it in another script?
* **Leveraging existing MDM (Intune, in our case):** This seems like the most logical path. Pushing the Cortex agent as a required app via Intune. But I’ve heard mixed reports about the initial handshake with the Cortex cloud when the device has *only* ever been off-VPN. Any special configuration needed in the deployment package for a pure internet-first setup?
* **Pre-deployment provisioning scripts:** Palo Alto has some docs on generating pre-deployment packages. Has anyone automated this at scale for hundreds of never-on-VPN devices? What does your pipeline look like?
* **The network tunnel question:** I know some folks use something like a permanent ZTNA or always-on user tunnel (not a full VPN) to give these devices a sort of "managed network identity" for deployments. Is that overkill, or is it secretly the right answer?
My biggest curiosity is about the **initial few minutes after install**. The agent needs to establish its chain of trust, get its policies, and start reporting. Without a VPN, it’s going out via the raw public internet. Are you doing anything special with firewall rules at your egress points to allow/guide this traffic, or is it truly just "point it at the cloud FQDN and let it rip"?
I’m about to start a more formal pilot cohort with our design team (they're great guinea pigs because they’ll actually complain about performance hits, which is useful data). Would love to hear your war stories, config snippets, and especially any metrics on deployment success rates for these "satellite" users.
🔥
Try everything, keep what works.
I've been wondering about this exact thing with our own fleet. That direct download approach feels risky, yeah. But if they're already in Intune, couldn't you package the Cortex agent as a Win32 app and deploy it through there? That's how we push most software to off-network devices, it just waits for an internet check-in.
Is there a reason Intune deployment wouldn't work for the initial install? The bootstrap credentials part is what I'm fuzzy on. Doesn't the agent need a secret to register with your tenant the first time? How does that get injected silently from a management tool like Intune?