Choose a Cortex deployment
Choose a Defender endpoint deployment or an Egress Gateway shared deployment for your team.
- Managed devicesDefender on macOS and Windows
- Headless LinuxDefender service on one host
- Shared gatewayEgress Gateway on Kubernetes
Choose your deployment
Choose the path that matches where Cortex will run. Defender runs locally on an endpoint. Egress Gateway is a shared gateway that AI clients connect to. A client connecting to an existing Egress Gateway does not need a local Defender installation.
Defender on managed macOS and Windows devices
Use this path when IT deploys Defender through managed-device tooling. It covers organization onboarding, the supplied macOS and Windows installers, MDM rollout, pilot validation, fleet operations, and removal.
Deploy Defender on managed macOS and Windows devices
Defender on a headless Linux host
Use this path when one Linux host runs Defender as a local service for its configured AI tools. It covers local capture, optional enrollment for managed upload, and restoring the host configuration. It does not deploy a shared gateway.
Run Defender on a headless Linux host
Egress Gateway on Kubernetes
Use this path when a platform team is deploying the platform-supplied shared gateway into Kubernetes. It covers the deployment inputs, networking, validation, and operating procedures to agree with your platform team.
Deploy Egress Gateway on Kubernetes
Connect to an existing Egress Gateway
If your platform team has already deployed Egress Gateway, configure the AI client with the issued gateway endpoint and credential. This client connection is separate from operating the gateway.
Connect your AI tools to Egress Gateway