<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [EN] Agent Upgrade Best Practices: Deployment Rules &amp;amp; Gradual Rollouts in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/EN-Agent-Upgrade-Best-Practices-Deployment-Rules-amp-Gradual/m-p/280952#M11598</link>
    <description>&lt;P&gt;&lt;EM&gt;Article 5 of the Harmony Endpoint Deep Dives series · &lt;STRONG&gt;A note on management:&lt;/STRONG&gt; Harmony Endpoint is cloud-managed (Infinity Portal / Web Management) in most deployments today. The content below follows the cloud model; where an on-premises Management Server behaves differently, that is called out.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;Every client release forces the same question: how do I upgrade hundreds of Harmony Endpoint clients without breaking FDE, flooding the WAN, or rebooting the CFO's laptop at 2 PM? In the cloud model, Check Point runs the management service, so the job is no longer about repositories and server versions — it is about choosing an upgrade mechanism and scoping it. This article consolidates the cloud upgrade mechanics into a practical playbook: &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt;, Deployment Rules, gradual rollouts, exported packages, Local Deployment, and the Installation and Upgrade Settings that decide the user experience.&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] Endpoint Administrators&lt;/LI&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[ ] SOC Analysts&lt;/LI&gt;
&lt;LI&gt;[x] Beginners&lt;/LI&gt;
&lt;LI&gt;[x] Experts&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Prerequisites&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Access to the Harmony Endpoint &lt;STRONG&gt;Web Management&lt;/STRONG&gt; console (Infinity Portal) with rights to edit the &lt;STRONG&gt;Software Deployment&lt;/STRONG&gt; policy&lt;/LI&gt;
&lt;LI&gt;Familiarity with the &lt;STRONG&gt;Deployment Rules&lt;/STRONG&gt; concept (Default Policy rule plus custom rules by OU, computer, or Virtual Group)&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;The Golden Rules (before anything else)&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;The Full Disk Encryption component cannot be removed during an upgrade&lt;/STRONG&gt; — all other components and settings can change, but FDE stays.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;FDE discipline:&lt;/STRONG&gt; do not upgrade while the disk is not fully encrypted, do not start a second upgrade before the first completes protection, and do not uninstall an upgrade before the machine is fully protected by the new version.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The user experience is a policy setting, not luck.&lt;/STRONG&gt; Whether the client reboots silently or lets the user postpone comes from &lt;STRONG&gt;Installation and Upgrade Settings&lt;/STRONG&gt; — configure it before you touch a version.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prefer the managed path.&lt;/STRONG&gt; In the cloud, &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; keeps clients on the latest approved version silently; reach for manual version bumps only when you need tight control over timing.&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;Automatic Client Update (the cloud default)&lt;/H2&gt;
&lt;P&gt;This is the feature that changes the upgrade conversation in cloud environments. &lt;STRONG&gt;Automatic Client Update automatically upgrades Endpoint Security clients to the latest version&lt;/STRONG&gt;, straight from the Software Deployment policy.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; Automatic Client Update is available &lt;STRONG&gt;only for cloud-managed&lt;/STRONG&gt; Endpoint Security environments — it is not supported for clients managed by an on-premises Management Server. It is supported on &lt;STRONG&gt;Windows only&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to enable it:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Policy &amp;gt; Deployment Policy &amp;gt; Software Deployment&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select the policy (rule).&lt;/LI&gt;
&lt;LI&gt;In the &lt;STRONG&gt;Capabilities &amp;amp; Exclusions&lt;/STRONG&gt; pane, turn on the &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; toggle for the appropriate operating system.&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Install Policy&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;All clients associated with that policy are then upgraded to the latest version. Upgrades run &lt;STRONG&gt;silently&lt;/STRONG&gt; — no end-user interaction is required, unless the upgrade impacts user experience. Blade selection and activation logic stay exactly the same whether the toggle is on or off.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Defaults you must know (they bite people):&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Context&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Automatic Client Update default&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;New tenants&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Enabled&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Newly cloned rules (including clones in existing tenants)&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Enabled&lt;/STRONG&gt; — this is the recommended configuration&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Existing rules in existing tenants&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Disabled&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;A rule exported from one tenant and imported into another&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Enabled&lt;/STRONG&gt; in the imported rule&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; on an established tenant, existing rules ship with the toggle &lt;STRONG&gt;off&lt;/STRONG&gt;. If you want hands-off upgrades there, turn it on deliberately — don't assume it is already working.&lt;/P&gt;
&lt;P&gt;The behavior is identical for MSP accounts, which makes this the natural way for a provider to keep many tenants current from one workflow.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Why the Dynamic Package Still Matters&lt;/H2&gt;
&lt;P&gt;Even with Automatic Client Update doing the heavy lifting, the &lt;STRONG&gt;Dynamic Package&lt;/STRONG&gt; is the packaging that makes cloud upgrades cheap on the wire.&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Property&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Dynamic Package (.EXE)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;CPU&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Any CPU&lt;/STRONG&gt; — one file for 32/64-bit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Contents&lt;/TD&gt;
&lt;TD&gt;Combined with the Tiny Agent, it &lt;STRONG&gt;installs only what is necessary&lt;/STRONG&gt; for each machine&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Network&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Reduces traffic&lt;/STRONG&gt; for installing selected blades&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;EPMaaS&lt;/TD&gt;
&lt;TD&gt;In Endpoint Management as a Service, admins can upload/download &lt;STRONG&gt;only&lt;/STRONG&gt; the Dynamic Package (*.EXE)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; the Dynamic Package is &lt;STRONG&gt;not supported for macOS, Linux, or Browse Security&lt;/STRONG&gt; — those use their own package types.&lt;/P&gt;
&lt;P&gt;When you build an export package, the &lt;STRONG&gt;Minimize package size (takes longer)&lt;/STRONG&gt; option trades build time for a smaller download — useful when bandwidth to the endpoint is the constraint.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 1 — Manual Version Bump with a Deployment Rule&lt;/H2&gt;
&lt;P&gt;When you want explicit control over &lt;EM&gt;when&lt;/EM&gt; a group upgrades (instead of always-latest), drive it from the rule:&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-upgrade-deployment-rules.png" style="width: 268px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35024iD7C934A7FC0E54A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-upgrade-deployment-rules.png" alt="diag1-upgrade-deployment-rules.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notes that matter in production:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Changing the client version in a rule upgrades &lt;STRONG&gt;every computer assigned to that rule&lt;/STRONG&gt; — scope the rule (OU, specific computers, Virtual Group) before you touch the version.&lt;/LI&gt;
&lt;LI&gt;The user experience (silent forced restart vs. postpone prompt) comes from &lt;STRONG&gt;Installation and Upgrade Settings&lt;/STRONG&gt;, not from the rule. See the next section.&lt;/LI&gt;
&lt;LI&gt;Deployment Rules work on &lt;STRONG&gt;Windows and macOS&lt;/STRONG&gt;; Linux is not supported for deployment rules yet.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Installation and Upgrade Settings — where the "2 PM reboot" is prevented&lt;/H3&gt;
&lt;P&gt;By default, users &lt;STRONG&gt;can postpone&lt;/STRONG&gt; the installation or upgrade. You tune that under the Installation and Upgrade Settings:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Default reminder interval&lt;/STRONG&gt; — minutes after which the user is reminded to install.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Force Installation and automatically restart after&lt;/STRONG&gt; — hours after which the install starts automatically.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Maximum delay in download of packages&lt;/STRONG&gt; — the maximum hours an end user can postpone.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; set the force timer so the automatic restart lands &lt;EM&gt;outside&lt;/EM&gt; business hours. That single setting is what keeps the upgrade off the CFO's screen at 2 PM.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 2 — Gradual Rollout (pilot first)&lt;/H2&gt;
&lt;P&gt;The gradual model is simple and effective:&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-gradual-rollout.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35025iBFF3D69C4A1F932D/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-gradual-rollout.png" alt="diag2-gradual-rollout.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Tip:&lt;/STRONG&gt; combine with the predefined Virtual Groups (&lt;STRONG&gt;All Laptops&lt;/STRONG&gt;, &lt;STRONG&gt;All Desktops&lt;/STRONG&gt;) to slice pilot rings without touching AD.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; a &lt;STRONG&gt;cloned&lt;/STRONG&gt; rule has Automatic Client Update &lt;STRONG&gt;enabled by default&lt;/STRONG&gt; — expected for a pilot ring, but confirm the toggle matches your intent before you Install Policy.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 3 — Upgrading with an Exported Package (manual)&lt;/H2&gt;
&lt;P&gt;For clients managed outside Deployment Rules (third-party software distribution, shared path, email):&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Policy &amp;gt; Export Package&lt;/STRONG&gt; and select or create the package (choose OS, version, capabilities).&lt;/LI&gt;
&lt;LI&gt;Build it, then download the package for the target OS (&lt;CODE&gt;EPS_&amp;lt;Year&amp;gt;_&amp;lt;Version&amp;gt;.exe&lt;/CODE&gt; for Windows).&lt;/LI&gt;
&lt;LI&gt;Distribute to users — on &lt;STRONG&gt;Windows 8.1 and higher&lt;/STRONG&gt;, install with &lt;STRONG&gt;Run as administrator&lt;/STRONG&gt; (double-click does not work).&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 4 — Local Deployment (upgrade without pulling from the service)&lt;/H2&gt;
&lt;P&gt;For bandwidth-constrained sites, clients can upgrade from a &lt;STRONG&gt;local path or URL&lt;/STRONG&gt; instead of downloading the package from the management service:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Stage the same package version in a local location on the client computers (for example &lt;CODE&gt;C:\TEMP\EPS\...\EPS.msi&lt;/CODE&gt;).&lt;/LI&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Policy &amp;gt; Client Settings &amp;gt; Installation &amp;gt; Deployment from Local Paths and URLs&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Allow to install software deployment packages from local folders and URLs&lt;/STRONG&gt;, and add the &lt;STRONG&gt;Deployment Paths&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Optionally select &lt;STRONG&gt;Enable Deployment from Server when no MSI was found in local paths&lt;/STRONG&gt; as a fallback.&lt;/LI&gt;
&lt;LI&gt;Create or edit the deployment rule with that package version, then &lt;STRONG&gt;Install Policy&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; &lt;STRONG&gt;Warning:&lt;/STRONG&gt; the version in the deployment rule and the version staged in the local path &lt;STRONG&gt;must match&lt;/STRONG&gt; — a mismatch means the client is not deployed, and the console shows an error.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;FDE and the Upgrade&lt;/H2&gt;
&lt;P&gt;Full Disk Encryption is the one component that constrains an upgrade, and the cloud rules are strict but simple:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;You cannot remove the FDE component during an upgrade.&lt;/STRONG&gt; Plan any FDE removal as a separate, post-upgrade change.&lt;/LI&gt;
&lt;LI&gt;Make sure encryption is &lt;STRONG&gt;not mid-run&lt;/STRONG&gt; before upgrading, and never stack a second upgrade on top of one still protecting the disk.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; on cloud tenants, make &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; your default for steady-state upgrades; keep manual version bumps for change-controlled windows.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; pilot ring first (clone a rule scoped to a Virtual Group), production rings after validation.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; align &lt;STRONG&gt;Installation and Upgrade Settings&lt;/STRONG&gt; (force-restart timer) with your business hours before installing any upgrade.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; change the default &lt;STRONG&gt;Agent Uninstall Password&lt;/STRONG&gt; (&lt;CODE&gt;secret&lt;/CODE&gt;) so upgrades and clients can't be tampered with — it only protects you if it isn't the default.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Common Mistakes&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Mistake&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Assuming Automatic Client Update is already on in an existing tenant&lt;/TD&gt;
&lt;TD&gt;Clients quietly stay on old versions&lt;/TD&gt;
&lt;TD&gt;Existing rules ship with the toggle &lt;STRONG&gt;off&lt;/STRONG&gt; — enable it deliberately&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Changing the version on a broad rule "just to test"&lt;/TD&gt;
&lt;TD&gt;Entire OU upgrades at once&lt;/TD&gt;
&lt;TD&gt;Clone the rule, scope it to a pilot Virtual Group first&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ignoring the force-restart timer&lt;/TD&gt;
&lt;TD&gt;The 2 PM reboot&lt;/TD&gt;
&lt;TD&gt;Set Installation and Upgrade Settings to restart outside business hours&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Removing FDE in the upgrade&lt;/TD&gt;
&lt;TD&gt;Not possible during upgrade&lt;/TD&gt;
&lt;TD&gt;Plan FDE removal as a separate, post-upgrade change&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Upgrading FDE mid-encryption&lt;/TD&gt;
&lt;TD&gt;Risk to the disk state&lt;/TD&gt;
&lt;TD&gt;Wait until fully encrypted; never stack upgrades&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Local Deployment version mismatch&lt;/TD&gt;
&lt;TD&gt;Client is not deployed; console error&lt;/TD&gt;
&lt;TD&gt;Keep the rule version and the local path version identical&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Troubleshooting&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt; After enabling Automatic Client Update (or bumping a rule's version) and installing policy, some clients never upgrade &lt;STRONG&gt;Environment:&lt;/STRONG&gt; Windows clients, cloud-managed &lt;STRONG&gt;Root Causes &amp;amp; checks (most common):&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The rule's &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; toggle is off (common on existing rules in existing tenants) — turn it on and Install Policy&lt;/LI&gt;
&lt;LI&gt;The computer is not in the rule's scope — verify entity assignment (OU / Virtual Group / Computer)&lt;/LI&gt;
&lt;LI&gt;The user keeps postponing — remember the install starts automatically after the &lt;STRONG&gt;Force Installation&lt;/STRONG&gt; timer; check Installation and Upgrade Settings&lt;/LI&gt;
&lt;LI&gt;Client not communicating with the service — check connectivity (see &lt;A href="https://community.checkpoint.com/../../architecture/03-agent-management-communication/README.md" target="_blank"&gt;Article 3&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Using Local Deployment with a version mismatch between the rule and the local path&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the fastest way to keep all my cloud clients on the latest version?&lt;/STRONG&gt; A: Turn on &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; in the Software Deployment policy (Capabilities &amp;amp; Exclusions pane) and Install Policy. Upgrades then run silently. It is Windows-only and cloud-only.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Is Automatic Client Update on by default?&lt;/STRONG&gt; A: For new tenants and newly cloned rules, yes. For existing rules in existing tenants, no — you must enable it.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Can I choose which components change during an upgrade?&lt;/STRONG&gt; A: Yes, all except &lt;STRONG&gt;Full Disk Encryption&lt;/STRONG&gt;, which cannot be removed during an upgrade.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: How do I stop upgrades from rebooting machines during the workday?&lt;/STRONG&gt; A: Set the &lt;STRONG&gt;Force Installation and automatically restart after&lt;/STRONG&gt; timer (and the reminder/download-delay settings) so the automatic restart lands outside business hours.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: How do I upgrade clients without every one of them downloading from the cloud service?&lt;/STRONG&gt; A: Use &lt;STRONG&gt;Local Deployment&lt;/STRONG&gt; — stage the package locally and point Client Settings at the local paths, keeping the local version identical to the rule's version.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Related Articles&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../architecture/01-harmony-endpoint-architecture-overview/README.md" target="_blank"&gt;Harmony Endpoint Architecture Overview&lt;/A&gt; — Article 1 · &lt;A href="https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-On-Premises-Architecture-Components/m-p/279803#M11550" target="_blank"&gt;Read on CheckMates ↗&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../architecture/03-agent-management-communication/README.md" target="_blank"&gt;Agent ↔ Management Communication&lt;/A&gt; — Article 3 (connectivity prerequisites)&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;Windows Agent Installation&lt;/EM&gt; (planned)&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Deploying Endpoint Clients&lt;/EM&gt; (Tiny Agent, Dynamic Package, Deployment Rules, Export Package)&lt;/LI&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Installation and Upgrade Settings&lt;/EM&gt;, &lt;EM&gt;Local Deployment Options&lt;/EM&gt;, &lt;EM&gt;Automatic Client Update&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-16&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial version&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-30&lt;/TD&gt;
&lt;TD&gt;2.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Cloud-first revalidation against the cloud Administration Guide: Automatic Client Update as the cloud default, Installation and Upgrade Settings, Local Deployment; removed on-prem repository/PreUpgrade.exe/legacy R73 and unsourced package-signature and delta-size claims&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Harmony Endpoint cloud management (Infinity Portal / Web Management); Automatic Client Update is Windows-only &lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-07-30&lt;/P&gt;
&lt;DIV id="gtx-trans" style="position: absolute; left: -5px; top: 3940.48px;"&gt;
&lt;DIV class="gtx-trans-icon"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 11 Aug 2026 11:37:47 GMT</pubDate>
    <dc:creator>jorgeluiznim</dc:creator>
    <dc:date>2026-08-11T11:37:47Z</dc:date>
    <item>
      <title>[EN] Agent Upgrade Best Practices: Deployment Rules &amp; Gradual Rollouts</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EN-Agent-Upgrade-Best-Practices-Deployment-Rules-amp-Gradual/m-p/280952#M11598</link>
      <description>&lt;P&gt;&lt;EM&gt;Article 5 of the Harmony Endpoint Deep Dives series · &lt;STRONG&gt;A note on management:&lt;/STRONG&gt; Harmony Endpoint is cloud-managed (Infinity Portal / Web Management) in most deployments today. The content below follows the cloud model; where an on-premises Management Server behaves differently, that is called out.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;Every client release forces the same question: how do I upgrade hundreds of Harmony Endpoint clients without breaking FDE, flooding the WAN, or rebooting the CFO's laptop at 2 PM? In the cloud model, Check Point runs the management service, so the job is no longer about repositories and server versions — it is about choosing an upgrade mechanism and scoping it. This article consolidates the cloud upgrade mechanics into a practical playbook: &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt;, Deployment Rules, gradual rollouts, exported packages, Local Deployment, and the Installation and Upgrade Settings that decide the user experience.&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] Endpoint Administrators&lt;/LI&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[ ] SOC Analysts&lt;/LI&gt;
&lt;LI&gt;[x] Beginners&lt;/LI&gt;
&lt;LI&gt;[x] Experts&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Prerequisites&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Access to the Harmony Endpoint &lt;STRONG&gt;Web Management&lt;/STRONG&gt; console (Infinity Portal) with rights to edit the &lt;STRONG&gt;Software Deployment&lt;/STRONG&gt; policy&lt;/LI&gt;
&lt;LI&gt;Familiarity with the &lt;STRONG&gt;Deployment Rules&lt;/STRONG&gt; concept (Default Policy rule plus custom rules by OU, computer, or Virtual Group)&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;The Golden Rules (before anything else)&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;The Full Disk Encryption component cannot be removed during an upgrade&lt;/STRONG&gt; — all other components and settings can change, but FDE stays.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;FDE discipline:&lt;/STRONG&gt; do not upgrade while the disk is not fully encrypted, do not start a second upgrade before the first completes protection, and do not uninstall an upgrade before the machine is fully protected by the new version.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The user experience is a policy setting, not luck.&lt;/STRONG&gt; Whether the client reboots silently or lets the user postpone comes from &lt;STRONG&gt;Installation and Upgrade Settings&lt;/STRONG&gt; — configure it before you touch a version.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prefer the managed path.&lt;/STRONG&gt; In the cloud, &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; keeps clients on the latest approved version silently; reach for manual version bumps only when you need tight control over timing.&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;Automatic Client Update (the cloud default)&lt;/H2&gt;
&lt;P&gt;This is the feature that changes the upgrade conversation in cloud environments. &lt;STRONG&gt;Automatic Client Update automatically upgrades Endpoint Security clients to the latest version&lt;/STRONG&gt;, straight from the Software Deployment policy.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; Automatic Client Update is available &lt;STRONG&gt;only for cloud-managed&lt;/STRONG&gt; Endpoint Security environments — it is not supported for clients managed by an on-premises Management Server. It is supported on &lt;STRONG&gt;Windows only&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to enable it:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Policy &amp;gt; Deployment Policy &amp;gt; Software Deployment&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select the policy (rule).&lt;/LI&gt;
&lt;LI&gt;In the &lt;STRONG&gt;Capabilities &amp;amp; Exclusions&lt;/STRONG&gt; pane, turn on the &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; toggle for the appropriate operating system.&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Install Policy&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;All clients associated with that policy are then upgraded to the latest version. Upgrades run &lt;STRONG&gt;silently&lt;/STRONG&gt; — no end-user interaction is required, unless the upgrade impacts user experience. Blade selection and activation logic stay exactly the same whether the toggle is on or off.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Defaults you must know (they bite people):&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Context&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Automatic Client Update default&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;New tenants&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Enabled&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Newly cloned rules (including clones in existing tenants)&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Enabled&lt;/STRONG&gt; — this is the recommended configuration&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Existing rules in existing tenants&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Disabled&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;A rule exported from one tenant and imported into another&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Enabled&lt;/STRONG&gt; in the imported rule&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; on an established tenant, existing rules ship with the toggle &lt;STRONG&gt;off&lt;/STRONG&gt;. If you want hands-off upgrades there, turn it on deliberately — don't assume it is already working.&lt;/P&gt;
&lt;P&gt;The behavior is identical for MSP accounts, which makes this the natural way for a provider to keep many tenants current from one workflow.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Why the Dynamic Package Still Matters&lt;/H2&gt;
&lt;P&gt;Even with Automatic Client Update doing the heavy lifting, the &lt;STRONG&gt;Dynamic Package&lt;/STRONG&gt; is the packaging that makes cloud upgrades cheap on the wire.&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Property&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Dynamic Package (.EXE)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;CPU&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Any CPU&lt;/STRONG&gt; — one file for 32/64-bit&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Contents&lt;/TD&gt;
&lt;TD&gt;Combined with the Tiny Agent, it &lt;STRONG&gt;installs only what is necessary&lt;/STRONG&gt; for each machine&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Network&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Reduces traffic&lt;/STRONG&gt; for installing selected blades&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;EPMaaS&lt;/TD&gt;
&lt;TD&gt;In Endpoint Management as a Service, admins can upload/download &lt;STRONG&gt;only&lt;/STRONG&gt; the Dynamic Package (*.EXE)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; the Dynamic Package is &lt;STRONG&gt;not supported for macOS, Linux, or Browse Security&lt;/STRONG&gt; — those use their own package types.&lt;/P&gt;
&lt;P&gt;When you build an export package, the &lt;STRONG&gt;Minimize package size (takes longer)&lt;/STRONG&gt; option trades build time for a smaller download — useful when bandwidth to the endpoint is the constraint.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 1 — Manual Version Bump with a Deployment Rule&lt;/H2&gt;
&lt;P&gt;When you want explicit control over &lt;EM&gt;when&lt;/EM&gt; a group upgrades (instead of always-latest), drive it from the rule:&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-upgrade-deployment-rules.png" style="width: 268px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35024iD7C934A7FC0E54A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-upgrade-deployment-rules.png" alt="diag1-upgrade-deployment-rules.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notes that matter in production:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Changing the client version in a rule upgrades &lt;STRONG&gt;every computer assigned to that rule&lt;/STRONG&gt; — scope the rule (OU, specific computers, Virtual Group) before you touch the version.&lt;/LI&gt;
&lt;LI&gt;The user experience (silent forced restart vs. postpone prompt) comes from &lt;STRONG&gt;Installation and Upgrade Settings&lt;/STRONG&gt;, not from the rule. See the next section.&lt;/LI&gt;
&lt;LI&gt;Deployment Rules work on &lt;STRONG&gt;Windows and macOS&lt;/STRONG&gt;; Linux is not supported for deployment rules yet.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Installation and Upgrade Settings — where the "2 PM reboot" is prevented&lt;/H3&gt;
&lt;P&gt;By default, users &lt;STRONG&gt;can postpone&lt;/STRONG&gt; the installation or upgrade. You tune that under the Installation and Upgrade Settings:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Default reminder interval&lt;/STRONG&gt; — minutes after which the user is reminded to install.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Force Installation and automatically restart after&lt;/STRONG&gt; — hours after which the install starts automatically.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Maximum delay in download of packages&lt;/STRONG&gt; — the maximum hours an end user can postpone.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; set the force timer so the automatic restart lands &lt;EM&gt;outside&lt;/EM&gt; business hours. That single setting is what keeps the upgrade off the CFO's screen at 2 PM.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 2 — Gradual Rollout (pilot first)&lt;/H2&gt;
&lt;P&gt;The gradual model is simple and effective:&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-gradual-rollout.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35025iBFF3D69C4A1F932D/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-gradual-rollout.png" alt="diag2-gradual-rollout.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG&gt;Tip:&lt;/STRONG&gt; combine with the predefined Virtual Groups (&lt;STRONG&gt;All Laptops&lt;/STRONG&gt;, &lt;STRONG&gt;All Desktops&lt;/STRONG&gt;) to slice pilot rings without touching AD.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":information:"&gt;ℹ️&lt;/span&gt; &lt;STRONG&gt;Note:&lt;/STRONG&gt; a &lt;STRONG&gt;cloned&lt;/STRONG&gt; rule has Automatic Client Update &lt;STRONG&gt;enabled by default&lt;/STRONG&gt; — expected for a pilot ring, but confirm the toggle matches your intent before you Install Policy.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 3 — Upgrading with an Exported Package (manual)&lt;/H2&gt;
&lt;P&gt;For clients managed outside Deployment Rules (third-party software distribution, shared path, email):&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Policy &amp;gt; Export Package&lt;/STRONG&gt; and select or create the package (choose OS, version, capabilities).&lt;/LI&gt;
&lt;LI&gt;Build it, then download the package for the target OS (&lt;CODE&gt;EPS_&amp;lt;Year&amp;gt;_&amp;lt;Version&amp;gt;.exe&lt;/CODE&gt; for Windows).&lt;/LI&gt;
&lt;LI&gt;Distribute to users — on &lt;STRONG&gt;Windows 8.1 and higher&lt;/STRONG&gt;, install with &lt;STRONG&gt;Run as administrator&lt;/STRONG&gt; (double-click does not work).&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;Path 4 — Local Deployment (upgrade without pulling from the service)&lt;/H2&gt;
&lt;P&gt;For bandwidth-constrained sites, clients can upgrade from a &lt;STRONG&gt;local path or URL&lt;/STRONG&gt; instead of downloading the package from the management service:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Stage the same package version in a local location on the client computers (for example &lt;CODE&gt;C:\TEMP\EPS\...\EPS.msi&lt;/CODE&gt;).&lt;/LI&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Policy &amp;gt; Client Settings &amp;gt; Installation &amp;gt; Deployment from Local Paths and URLs&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Allow to install software deployment packages from local folders and URLs&lt;/STRONG&gt;, and add the &lt;STRONG&gt;Deployment Paths&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Optionally select &lt;STRONG&gt;Enable Deployment from Server when no MSI was found in local paths&lt;/STRONG&gt; as a fallback.&lt;/LI&gt;
&lt;LI&gt;Create or edit the deployment rule with that package version, then &lt;STRONG&gt;Install Policy&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; &lt;STRONG&gt;Warning:&lt;/STRONG&gt; the version in the deployment rule and the version staged in the local path &lt;STRONG&gt;must match&lt;/STRONG&gt; — a mismatch means the client is not deployed, and the console shows an error.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;FDE and the Upgrade&lt;/H2&gt;
&lt;P&gt;Full Disk Encryption is the one component that constrains an upgrade, and the cloud rules are strict but simple:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;You cannot remove the FDE component during an upgrade.&lt;/STRONG&gt; Plan any FDE removal as a separate, post-upgrade change.&lt;/LI&gt;
&lt;LI&gt;Make sure encryption is &lt;STRONG&gt;not mid-run&lt;/STRONG&gt; before upgrading, and never stack a second upgrade on top of one still protecting the disk.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; on cloud tenants, make &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; your default for steady-state upgrades; keep manual version bumps for change-controlled windows.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; pilot ring first (clone a rule scoped to a Virtual Group), production rings after validation.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; align &lt;STRONG&gt;Installation and Upgrade Settings&lt;/STRONG&gt; (force-restart timer) with your business hours before installing any upgrade.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; change the default &lt;STRONG&gt;Agent Uninstall Password&lt;/STRONG&gt; (&lt;CODE&gt;secret&lt;/CODE&gt;) so upgrades and clients can't be tampered with — it only protects you if it isn't the default.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Common Mistakes&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Mistake&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Assuming Automatic Client Update is already on in an existing tenant&lt;/TD&gt;
&lt;TD&gt;Clients quietly stay on old versions&lt;/TD&gt;
&lt;TD&gt;Existing rules ship with the toggle &lt;STRONG&gt;off&lt;/STRONG&gt; — enable it deliberately&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Changing the version on a broad rule "just to test"&lt;/TD&gt;
&lt;TD&gt;Entire OU upgrades at once&lt;/TD&gt;
&lt;TD&gt;Clone the rule, scope it to a pilot Virtual Group first&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Ignoring the force-restart timer&lt;/TD&gt;
&lt;TD&gt;The 2 PM reboot&lt;/TD&gt;
&lt;TD&gt;Set Installation and Upgrade Settings to restart outside business hours&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Removing FDE in the upgrade&lt;/TD&gt;
&lt;TD&gt;Not possible during upgrade&lt;/TD&gt;
&lt;TD&gt;Plan FDE removal as a separate, post-upgrade change&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Upgrading FDE mid-encryption&lt;/TD&gt;
&lt;TD&gt;Risk to the disk state&lt;/TD&gt;
&lt;TD&gt;Wait until fully encrypted; never stack upgrades&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Local Deployment version mismatch&lt;/TD&gt;
&lt;TD&gt;Client is not deployed; console error&lt;/TD&gt;
&lt;TD&gt;Keep the rule version and the local path version identical&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Troubleshooting&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt; After enabling Automatic Client Update (or bumping a rule's version) and installing policy, some clients never upgrade &lt;STRONG&gt;Environment:&lt;/STRONG&gt; Windows clients, cloud-managed &lt;STRONG&gt;Root Causes &amp;amp; checks (most common):&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The rule's &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; toggle is off (common on existing rules in existing tenants) — turn it on and Install Policy&lt;/LI&gt;
&lt;LI&gt;The computer is not in the rule's scope — verify entity assignment (OU / Virtual Group / Computer)&lt;/LI&gt;
&lt;LI&gt;The user keeps postponing — remember the install starts automatically after the &lt;STRONG&gt;Force Installation&lt;/STRONG&gt; timer; check Installation and Upgrade Settings&lt;/LI&gt;
&lt;LI&gt;Client not communicating with the service — check connectivity (see &lt;A href="https://community.checkpoint.com/../../architecture/03-agent-management-communication/README.md" target="_blank"&gt;Article 3&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Using Local Deployment with a version mismatch between the rule and the local path&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Q: What is the fastest way to keep all my cloud clients on the latest version?&lt;/STRONG&gt; A: Turn on &lt;STRONG&gt;Automatic Client Update&lt;/STRONG&gt; in the Software Deployment policy (Capabilities &amp;amp; Exclusions pane) and Install Policy. Upgrades then run silently. It is Windows-only and cloud-only.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Is Automatic Client Update on by default?&lt;/STRONG&gt; A: For new tenants and newly cloned rules, yes. For existing rules in existing tenants, no — you must enable it.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: Can I choose which components change during an upgrade?&lt;/STRONG&gt; A: Yes, all except &lt;STRONG&gt;Full Disk Encryption&lt;/STRONG&gt;, which cannot be removed during an upgrade.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: How do I stop upgrades from rebooting machines during the workday?&lt;/STRONG&gt; A: Set the &lt;STRONG&gt;Force Installation and automatically restart after&lt;/STRONG&gt; timer (and the reminder/download-delay settings) so the automatic restart lands outside business hours.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q: How do I upgrade clients without every one of them downloading from the cloud service?&lt;/STRONG&gt; A: Use &lt;STRONG&gt;Local Deployment&lt;/STRONG&gt; — stage the package locally and point Client Settings at the local paths, keeping the local version identical to the rule's version.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Related Articles&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../architecture/01-harmony-endpoint-architecture-overview/README.md" target="_blank"&gt;Harmony Endpoint Architecture Overview&lt;/A&gt; — Article 1 · &lt;A href="https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-On-Premises-Architecture-Components/m-p/279803#M11550" target="_blank"&gt;Read on CheckMates ↗&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/../../architecture/03-agent-management-communication/README.md" target="_blank"&gt;Agent ↔ Management Communication&lt;/A&gt; — Article 3 (connectivity prerequisites)&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;Windows Agent Installation&lt;/EM&gt; (planned)&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Deploying Endpoint Clients&lt;/EM&gt; (Tiny Agent, Dynamic Package, Deployment Rules, Export Package)&lt;/LI&gt;
&lt;LI&gt;Check Point Harmony Endpoint Administration Guide (cloud / Infinity Portal) — &lt;EM&gt;Installation and Upgrade Settings&lt;/EM&gt;, &lt;EM&gt;Local Deployment Options&lt;/EM&gt;, &lt;EM&gt;Automatic Client Update&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-16&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial version&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2026-07-30&lt;/TD&gt;
&lt;TD&gt;2.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Cloud-first revalidation against the cloud Administration Guide: Automatic Client Update as the cloud default, Installation and Upgrade Settings, Local Deployment; removed on-prem repository/PreUpgrade.exe/legacy R73 and unsourced package-signature and delta-size claims&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Harmony Endpoint cloud management (Infinity Portal / Web Management); Automatic Client Update is Windows-only &lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-07-30&lt;/P&gt;
&lt;DIV id="gtx-trans" style="position: absolute; left: -5px; top: 3940.48px;"&gt;
&lt;DIV class="gtx-trans-icon"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 Aug 2026 11:37:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EN-Agent-Upgrade-Best-Practices-Deployment-Rules-amp-Gradual/m-p/280952#M11598</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-08-11T11:37:47Z</dc:date>
    </item>
  </channel>
</rss>

