<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony Endpoint Upgrade via SCCM Fails - Self Protection Suspected in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Upgrade-via-SCCM-Fails-Self-Protection/m-p/279972#M11564</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/129023"&gt;@Aftermath1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;To answer &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;'s question first: based on your description — SCCM, E88.72 → E89.10, previously upgrading via a &lt;STRONG&gt;SmartEndpoint Deployment Policy&lt;/STRONG&gt; — this is &lt;STRONG&gt;Windows&lt;/STRONG&gt;, not macOS. That matters, because &lt;STRONG&gt;sk171012 is macOS-only&lt;/STRONG&gt;: it documents the cpSelfProtection utility, and that binary does not exist on Windows clients. So if you went looking for it on your endpoints, that's why you wouldn't find it.&lt;/P&gt;&lt;P&gt;On Windows, the supported mechanism is different:&lt;/P&gt;&lt;H3&gt;Is there a supported method to temporarily disable Self Protection?&lt;/H3&gt;&lt;P&gt;Yes — but it's &lt;STRONG&gt;not a policy setting&lt;/STRONG&gt;, it's a &lt;STRONG&gt;Push Operation&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Asset Management &amp;gt; Push Operations &amp;gt; Create operation&lt;/STRONG&gt; → &lt;STRONG&gt;Agent Settings&lt;/STRONG&gt; → &lt;STRONG&gt;Enable / Disable Self Protection&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Supported on Windows and macOS (not Linux). The same operation exists in on-prem SmartEndpoint.&lt;/P&gt;&lt;H3&gt;Can it be disabled only for the upgrade and re-enabled automatically?&lt;/H3&gt;&lt;P&gt;&lt;STRONG&gt;Yes — that's built in.&lt;/STRONG&gt; The operation has three fields: &lt;STRONG&gt;Enable&lt;/STRONG&gt;, &lt;STRONG&gt;Disable&lt;/STRONG&gt;, and &lt;STRONG&gt;Timeout Command Expiration&lt;/STRONG&gt;. Per the Administration Guide: &lt;EM&gt;"After the timeout, the command expires, and the self protection capabilities will be enabled automatically."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;So you set &lt;STRONG&gt;Disable&lt;/STRONG&gt; with a timeout that covers your deployment window, and protection restores itself with no follow-up action. It's also a genuine fail-safe: if an endpoint goes offline mid-window or the deployment fails, self-protection still comes back on its own. (You can also push &lt;STRONG&gt;Enable&lt;/STRONG&gt; explicitly to close the window early.)&lt;/P&gt;&lt;H3&gt;Best practices / prerequisites for SCCM&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Scope and sequence:&lt;/STRONG&gt; in the Devices tab use &lt;STRONG&gt;Custom&lt;/STRONG&gt; to target only the group matching your SCCM collection, and send the push operation &lt;STRONG&gt;before&lt;/STRONG&gt; releasing the deployment — then confirm it actually landed. A push operation is a runtime command (no reboot or policy install needed), but the client must be &lt;STRONG&gt;online&lt;/STRONG&gt; to receive it.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Verify per endpoint:&lt;/STRONG&gt; the push operation's &lt;STRONG&gt;per-device status&lt;/STRONG&gt; in the console is the reliable confirmation — use it as your gate before starting the SCCM run.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Confirm self-protection really is the blocker.&lt;/STRONG&gt; Since it's "suspected", run the MSI with verbose logging and look at the actual failure:&lt;PRE&gt;msiexec.exe /i &amp;lt;path&amp;gt;\EPS.msi /qn /l*v C:\Windows\Temp\eps_upgrade.log&lt;/PRE&gt;Search for access-denied / file-in-use / a failing custom action. Client-side logs (via the &lt;STRONG&gt;Collect Client Logs&lt;/STRONG&gt; push operation) are in C:\ProgramData\CheckPoint\Endpoint Security\Temp on E88.31+.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Uninstall password:&lt;/STRONG&gt; make sure the organizational uninstall password is set and known (Client Settings) — replacing protected components during an upgrade can require it. Default is secret.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Documented SCCM flow:&lt;/STRONG&gt; Harmony Endpoint Administration Guide, &lt;STRONG&gt;Appendix A – Deploying Endpoint Security Client using SCCM&lt;/STRONG&gt;. Note it's written around deploying the &lt;STRONG&gt;Initial client&lt;/STRONG&gt;; management-driven upgrades handle self-protection natively, which is why the Deployment Policy path never hits this. If SCCM must own the upgrade as well, the push-operation window above is the supported way to make room for it.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;FYI there's a closely related thread running in parallel ("Harmony Endpoint E88.72 → E89.10 Upgrade via SCCM – Best Practice for Uninstall Protection") — worth following both so the findings land in one place.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Jorge Dias Junior&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jul 2026 11:53:20 GMT</pubDate>
    <dc:creator>jorgeluiznim</dc:creator>
    <dc:date>2026-07-21T11:53:20Z</dc:date>
    <item>
      <title>Harmony Endpoint Upgrade via SCCM Fails - Self Protection Suspected</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Upgrade-via-SCCM-Fails-Self-Protection/m-p/279951#M11558</link>
      <description>&lt;DIV class=""&gt;&lt;SPAN&gt;Hi Team&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I'm currently trying to upgrade &lt;STRONG&gt;Harmony Endpoint Security&lt;/STRONG&gt; to the latest recommended version using &lt;STRONG&gt;SCCM&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Previously, upgrades were performed through a &lt;STRONG&gt;Deployment Policy&lt;/STRONG&gt; from the SmartEndpoint console, but we are now transitioning to SCCM-based deployments.&lt;/P&gt;&lt;P&gt;The upgrade package is being deployed successfully by SCCM, however the actual endpoint upgrade fails. After reviewing the logs and performing initial troubleshooting, there are indications that &lt;STRONG&gt;Self Protection&lt;/STRONG&gt; may be preventing the installer from updating or replacing certain Harmony Endpoint components.&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is there a supported method to temporarily disable &lt;STRONG&gt;Self Protection&lt;/STRONG&gt; through a policy?&lt;/LI&gt;&lt;LI&gt;If so, which policy settings should be modified?&lt;/LI&gt;&lt;LI&gt;Is it possible to disable Self Protection only for the duration of the upgrade and then re-enable it automatically?&lt;/LI&gt;&lt;LI&gt;Are there any specific best practices or prerequisites for upgrading Harmony Endpoint via SCCM?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Has anyone encountered a similar issue when deploying upgrades through SCCM?&lt;/P&gt;&lt;P&gt;Any guidance would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Jul 2026 08:42:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Upgrade-via-SCCM-Fails-Self-Protection/m-p/279951#M11558</guid>
      <dc:creator>Aftermath1</dc:creator>
      <dc:date>2026-07-21T08:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Upgrade via SCCM Fails - Self Protection Suspected</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Upgrade-via-SCCM-Fails-Self-Protection/m-p/279952#M11559</link>
      <description>&lt;P&gt;In your case, are you installing Endpoint on Macs? If yes, see&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk171012" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk171012&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 08:48:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Upgrade-via-SCCM-Fails-Self-Protection/m-p/279952#M11559</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-07-21T08:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Upgrade via SCCM Fails - Self Protection Suspected</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Upgrade-via-SCCM-Fails-Self-Protection/m-p/279972#M11564</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/129023"&gt;@Aftermath1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;To answer &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;'s question first: based on your description — SCCM, E88.72 → E89.10, previously upgrading via a &lt;STRONG&gt;SmartEndpoint Deployment Policy&lt;/STRONG&gt; — this is &lt;STRONG&gt;Windows&lt;/STRONG&gt;, not macOS. That matters, because &lt;STRONG&gt;sk171012 is macOS-only&lt;/STRONG&gt;: it documents the cpSelfProtection utility, and that binary does not exist on Windows clients. So if you went looking for it on your endpoints, that's why you wouldn't find it.&lt;/P&gt;&lt;P&gt;On Windows, the supported mechanism is different:&lt;/P&gt;&lt;H3&gt;Is there a supported method to temporarily disable Self Protection?&lt;/H3&gt;&lt;P&gt;Yes — but it's &lt;STRONG&gt;not a policy setting&lt;/STRONG&gt;, it's a &lt;STRONG&gt;Push Operation&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Asset Management &amp;gt; Push Operations &amp;gt; Create operation&lt;/STRONG&gt; → &lt;STRONG&gt;Agent Settings&lt;/STRONG&gt; → &lt;STRONG&gt;Enable / Disable Self Protection&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Supported on Windows and macOS (not Linux). The same operation exists in on-prem SmartEndpoint.&lt;/P&gt;&lt;H3&gt;Can it be disabled only for the upgrade and re-enabled automatically?&lt;/H3&gt;&lt;P&gt;&lt;STRONG&gt;Yes — that's built in.&lt;/STRONG&gt; The operation has three fields: &lt;STRONG&gt;Enable&lt;/STRONG&gt;, &lt;STRONG&gt;Disable&lt;/STRONG&gt;, and &lt;STRONG&gt;Timeout Command Expiration&lt;/STRONG&gt;. Per the Administration Guide: &lt;EM&gt;"After the timeout, the command expires, and the self protection capabilities will be enabled automatically."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;So you set &lt;STRONG&gt;Disable&lt;/STRONG&gt; with a timeout that covers your deployment window, and protection restores itself with no follow-up action. It's also a genuine fail-safe: if an endpoint goes offline mid-window or the deployment fails, self-protection still comes back on its own. (You can also push &lt;STRONG&gt;Enable&lt;/STRONG&gt; explicitly to close the window early.)&lt;/P&gt;&lt;H3&gt;Best practices / prerequisites for SCCM&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Scope and sequence:&lt;/STRONG&gt; in the Devices tab use &lt;STRONG&gt;Custom&lt;/STRONG&gt; to target only the group matching your SCCM collection, and send the push operation &lt;STRONG&gt;before&lt;/STRONG&gt; releasing the deployment — then confirm it actually landed. A push operation is a runtime command (no reboot or policy install needed), but the client must be &lt;STRONG&gt;online&lt;/STRONG&gt; to receive it.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Verify per endpoint:&lt;/STRONG&gt; the push operation's &lt;STRONG&gt;per-device status&lt;/STRONG&gt; in the console is the reliable confirmation — use it as your gate before starting the SCCM run.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Confirm self-protection really is the blocker.&lt;/STRONG&gt; Since it's "suspected", run the MSI with verbose logging and look at the actual failure:&lt;PRE&gt;msiexec.exe /i &amp;lt;path&amp;gt;\EPS.msi /qn /l*v C:\Windows\Temp\eps_upgrade.log&lt;/PRE&gt;Search for access-denied / file-in-use / a failing custom action. Client-side logs (via the &lt;STRONG&gt;Collect Client Logs&lt;/STRONG&gt; push operation) are in C:\ProgramData\CheckPoint\Endpoint Security\Temp on E88.31+.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Uninstall password:&lt;/STRONG&gt; make sure the organizational uninstall password is set and known (Client Settings) — replacing protected components during an upgrade can require it. Default is secret.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Documented SCCM flow:&lt;/STRONG&gt; Harmony Endpoint Administration Guide, &lt;STRONG&gt;Appendix A – Deploying Endpoint Security Client using SCCM&lt;/STRONG&gt;. Note it's written around deploying the &lt;STRONG&gt;Initial client&lt;/STRONG&gt;; management-driven upgrades handle self-protection natively, which is why the Deployment Policy path never hits this. If SCCM must own the upgrade as well, the push-operation window above is the supported way to make room for it.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;FYI there's a closely related thread running in parallel ("Harmony Endpoint E88.72 → E89.10 Upgrade via SCCM – Best Practice for Uninstall Protection") — worth following both so the findings land in one place.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Jorge Dias Junior&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 11:53:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Upgrade-via-SCCM-Fails-Self-Protection/m-p/279972#M11564</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-07-21T11:53:20Z</dc:date>
    </item>
  </channel>
</rss>

