Set up Cortex Defender
Sign in, connect your AI tools, and verify capture and workspace sync on a managed device.
- Managed deviceInstalled by your IT team
- Work accountSign in with your organization
- Capture and syncTest each source after connecting it
For employees using an organization-managed device. IT usually installs Cortex Defender before you begin.
Before you start
You need:
- The managed device where Cortex Defender was installed
- Your organization's domain, such as
example.com - Your work account
- Access to the browser window used for sign-in
If Cortex Defender is missing, contact your Cortex admin or IT team. There is no public installer for employees.
If a managed policy prevents a routing or certificate change, contact IT.
Open Cortex and sign in
Open Cortex Defender. On Welcome to Defender., select Get started.
Sign in to your organization
- Enter your Organization domain.
- Optionally enter your email or username.
- Select Continue.
- On Choose your sign-in, select the option your organization uses, then select Open sign-in.
- Complete the browser flow with your work account and return to Defender.
After sign-in, Cortex Defender enrolls the device in your organization workspace.
If Cortex cannot find the organization or sign-in does not complete, contact your Cortex admin. Include the domain, identity provider, work account, and approximate attempt time.
Connect your AI tools
Choose the apps you use and follow the setup action for each app. Browser apps may require the browser setup steps for Chrome or Safari.
Google ChromeBrowser connection
SafariBrowser connection
CursorAgent and IDE history
Open Connections to add or manage apps after setup. For local MCP capture, contact the Chaos Labs team. Use Supported AI tools for the steps for each surface.
Restart an app or browser when Defender asks. A device restart is usually unnecessary; restart it if Defender asks or several configured sources remain inactive.
Verify capture and sync
- Open Home and confirm Defender is on.
- Open Connections and check each source you use. Follow its setup or repair action if needed.
- Test each source separately: send a new prompt, finish a Cursor IDE conversation, or run a local MCP tool.
- Open the app's connection details and check Last activity seen for recent activity. During setup, the first-activity step confirms when a new session has been observed.
- Open Home → View health, select Run health check, and confirm Workspace sync is Up to date.
- In Cortex Atlas, open the relevant user profile and confirm the new prompt, completed conversation, or tool activity appears for the expected person.
Seeing activity locally does not prove it reached the workspace. If the first-activity screen shows activity waiting to sync, check workspace connectivity before treating setup as complete.
Cortex Defender continues running in the background after setup. Follow any recovery action shown in Health or use Troubleshooting. See Pause and stop capture to change which apps connect through Defender.
Continue to the Atlas overview to review synced activity.