<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EN - What Changed in Harmony Endpoint E89.x: Automatic Client Updates &amp;amp; Conflict Guard in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/EN-What-Changed-in-Harmony-Endpoint-E89-x-Automatic-Client/m-p/282366#M11650</link>
    <description>&lt;P&gt;&lt;EM&gt;Extra guide from the Harmony Endpoint Deep Dives series · A roundup of what the E89.x Windows client line actually brings, based on the official release notes. This is recent, shipped functionality, not a roadmap of future features.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;The E89.x line moved fast, and some of it changes how you operate the fleet, not just what a blade detects. This guide summarizes the operationally relevant changes across E89.00 to E89.25, plus the upgrade deadline Check Point published for older clients. Every item cites the release-note SK it comes from.&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] Endpoint Administrators&lt;/LI&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[x] IT Operations&lt;/LI&gt;
&lt;LI&gt;[ ] Beginners&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;First, the deadline you cannot ignore&lt;/H2&gt;
&lt;P style="background-color: #f8d7da; border-left: 4px solid #b02a37; padding: 10px;"&gt;&lt;STRONG&gt;Upgrade notice (02 Aug 2026):&lt;/STRONG&gt; starting &lt;STRONG&gt;September 1, 2026&lt;/STRONG&gt;, Windows Endpoint clients running versions &lt;STRONG&gt;earlier than E88.70 (excluding E88.32)&lt;/STRONG&gt; get &lt;STRONG&gt;limited functionality&lt;/STRONG&gt;, which impacts their security posture. The recommendation is to upgrade those machines to the latest version, E89.25.&lt;/P&gt;
&lt;P&gt;If you still have a tail of old clients, this is the first thing to check. The current &lt;STRONG&gt;Recommended&lt;/STRONG&gt; version is &lt;STRONG&gt;E89.10&lt;/STRONG&gt;; the current &lt;STRONG&gt;Latest&lt;/STRONG&gt; is &lt;STRONG&gt;E89.25&lt;/STRONG&gt;.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Automatic Client Updates (E89.21)&lt;/H2&gt;
&lt;P&gt;This is the headline change. Automatic Client Updates keeps endpoints up to date on their own, delivering the latest protections, critical fixes, and new features without a manual upgrade cycle.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Available only for &lt;STRONG&gt;cloud-managed&lt;/STRONG&gt; Endpoint Security environments. It is &lt;STRONG&gt;not supported&lt;/STRONG&gt; for clients managed by an on-premises Endpoint Security Management Server.&lt;/LI&gt;
&lt;LI&gt;To join, upgrade the Windows devices to E89.21 and follow the feature's video or admin guide.&lt;/LI&gt;
&lt;LI&gt;Rollout is gradual, so the option may take a while to appear in your console.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-automatic-client-updates.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35300i19686370958B56DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-automatic-client-updates.png" alt="diag2-automatic-client-updates.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Conflict Guard (E89.25)&lt;/H2&gt;
&lt;P&gt;A new capability that monitors for high resource usage and starts automated, targeted optimization. It uses scanner.exe through the File Protection component (CPFileAnlyz.exe). In practice this is Check Point reacting to the classic complaint of an endpoint agent fighting other software for CPU and disk.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Blocking SMB attacks without the Firewall blade (E89.25)&lt;/H2&gt;
&lt;P&gt;Blocking attacks over SMB is now possible without the Endpoint Firewall blade, using the Windows Defender Firewall. When an attack is identified, inbound &lt;STRONG&gt;SMB (TCP 445)&lt;/STRONG&gt; and &lt;STRONG&gt;NetBIOS (TCP 139, UDP 137/138)&lt;/STRONG&gt; traffic is automatically blocked. Outbound traffic stays allowed, and the containment is time limited. A log is sent to the Management Server.&lt;/P&gt;
&lt;P&gt;This matters for shops that run Harmony Endpoint without the Firewall blade and rely on Windows Defender Firewall.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Smart Pre-boot is GA (E89.05)&lt;/H2&gt;
&lt;P&gt;Smart Pre-boot went from Early Availability to GA. It adds &lt;STRONG&gt;Self-Unlock&lt;/STRONG&gt; and &lt;STRONG&gt;Mobile Login&lt;/STRONG&gt; using simple MFA through a smartphone, plus clearer mobile login instructions and Wi-Fi setup guidance at pre-boot. This is the modern replacement for the classic FDE pre-boot experience.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Quarantine Management and Remote Memory Dump (E89.05)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Quarantine Management:&lt;/STRONG&gt; a central way to analyze, restore, or delete quarantined files across the organization. Available for Early Availability customers and requires the Server on a supported version. Quarantined files are auto-deleted after 30 days by default.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Remote Memory Dump:&lt;/STRONG&gt; collect process, kernel, or full memory dumps remotely. Kernel dumps do not require a reboot (not supported on Windows 7). Full memory dumps trigger a BSOD and need prior configuration. All dumps are zipped, segmented if needed, and uploaded to Check Point FTP, Amazon S3, or a custom FTP server.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;SHA256 hashing for IoC (E89.00 / E89.10)&lt;/H2&gt;
&lt;P&gt;The File Protection component now computes &lt;STRONG&gt;SHA256&lt;/STRONG&gt; hashes for supported file types, which enables compatibility with SHA256-based indicators in Infinity IoC Management. If you drive blocks from threat-intel hashes, this closes the gap left by MD5/SHA1-only matching.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Housekeeping you should plan for&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Capsule Docs reached End of Support&lt;/STRONG&gt; (E89.00). To upgrade a machine that has managed Capsule Docs to E89.x, you must uninstall Capsule Docs first.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Legacy Windows end of the line:&lt;/STRONG&gt; E89.10 is the &lt;STRONG&gt;last version&lt;/STRONG&gt; supported on Windows 7, Windows 8, Windows Server 2008, and Windows Server 2012 (see sk183765).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;FDE firmware compatibility (E89.25):&lt;/STRONG&gt; FDE now supports only devices that boot Windows through the standard UEFI boot order; devices that load Windows Boot Manager directly are blocked until the manufacturer ships a BIOS update, and the policy can be switched to BitLocker Management with admin consent. This one has real deployment impact and gets its own treatment in the upcoming Full Disk Encryption Deep Dive. Verify devices with BootModeReport.ps1 (sk185123) before upgrading.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;E89.x at a glance&lt;/H2&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-e89x-timeline.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35301i8B185DE9F6E8E19D/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-e89x-timeline.png" alt="diag1-e89x-timeline.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Headline&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;E89.00&lt;/TD&gt;
&lt;TD&gt;GA&lt;/TD&gt;
&lt;TD&gt;SHA256 for IoC; Smart Pre-boot EA; Capsule Docs End of Support; hardened TLS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.05&lt;/TD&gt;
&lt;TD&gt;GA&lt;/TD&gt;
&lt;TD&gt;Smart Pre-boot GA (Self-Unlock, Mobile Login); Quarantine Management; Remote Memory Dump; Windows 11 25H2 GA&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.10&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Recommended&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;SHA256 for IoC in the standard flow; Super Node upstream proxy; broad performance/stability; last version for Windows 7/8/2008/2012&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.21&lt;/TD&gt;
&lt;TD&gt;GA&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Automatic Client Updates&lt;/STRONG&gt; (cloud-only)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.25&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Latest&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Conflict Guard; SMB blocking via Windows Defender Firewall; FDE firmware compatibility gate&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; treat the September deadline as real. Inventory any clients below E88.70 and schedule them first.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; standardize on the Recommended version (E89.10) for the fleet, and use the Latest (E89.25) where you need a specific new capability.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; if you are cloud-managed, evaluate Automatic Client Updates on a pilot group before turning it loose on production, so you see the rollout behavior in your own environment.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point SecureKnowledge sk182722, &lt;EM&gt;Enterprise Endpoint Security E89.00 Windows Clients&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk183617, &lt;EM&gt;Enterprise Endpoint Security E89.05 Windows Clients&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk183132, &lt;EM&gt;Enterprise Endpoint Security E89.10 Windows Clients&lt;/EM&gt; (Recommended)&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk185038, &lt;EM&gt;Enterprise Endpoint Security E89.21 Windows Clients&lt;/EM&gt; (Automatic Client Updates)&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk184929, &lt;EM&gt;Enterprise Endpoint Security E89.25 Windows Clients&lt;/EM&gt; (Latest)&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk185123 (BootModeReport), sk183765 (legacy Microsoft OS support)&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-09-08&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial version. Roundup of E89.00 to E89.25 from the official release-note SKs, plus the September 2026 upgrade deadline&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Harmony Endpoint Windows clients E89.00 to E89.25; Recommended E89.10, Latest E89.25 &lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-09-08&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2026 10:07:56 GMT</pubDate>
    <dc:creator>jorgeluiznim</dc:creator>
    <dc:date>2026-09-15T10:07:56Z</dc:date>
    <item>
      <title>EN - What Changed in Harmony Endpoint E89.x: Automatic Client Updates &amp; Conflict Guard</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EN-What-Changed-in-Harmony-Endpoint-E89-x-Automatic-Client/m-p/282366#M11650</link>
      <description>&lt;P&gt;&lt;EM&gt;Extra guide from the Harmony Endpoint Deep Dives series · A roundup of what the E89.x Windows client line actually brings, based on the official release notes. This is recent, shipped functionality, not a roadmap of future features.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Purpose&lt;/H2&gt;
&lt;P&gt;The E89.x line moved fast, and some of it changes how you operate the fleet, not just what a blade detects. This guide summarizes the operationally relevant changes across E89.00 to E89.25, plus the upgrade deadline Check Point published for older clients. Every item cites the release-note SK it comes from.&lt;/P&gt;
&lt;H2&gt;Audience&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[x] Endpoint Administrators&lt;/LI&gt;
&lt;LI&gt;[x] Security Engineers&lt;/LI&gt;
&lt;LI&gt;[x] IT Operations&lt;/LI&gt;
&lt;LI&gt;[ ] Beginners&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;First, the deadline you cannot ignore&lt;/H2&gt;
&lt;P style="background-color: #f8d7da; border-left: 4px solid #b02a37; padding: 10px;"&gt;&lt;STRONG&gt;Upgrade notice (02 Aug 2026):&lt;/STRONG&gt; starting &lt;STRONG&gt;September 1, 2026&lt;/STRONG&gt;, Windows Endpoint clients running versions &lt;STRONG&gt;earlier than E88.70 (excluding E88.32)&lt;/STRONG&gt; get &lt;STRONG&gt;limited functionality&lt;/STRONG&gt;, which impacts their security posture. The recommendation is to upgrade those machines to the latest version, E89.25.&lt;/P&gt;
&lt;P&gt;If you still have a tail of old clients, this is the first thing to check. The current &lt;STRONG&gt;Recommended&lt;/STRONG&gt; version is &lt;STRONG&gt;E89.10&lt;/STRONG&gt;; the current &lt;STRONG&gt;Latest&lt;/STRONG&gt; is &lt;STRONG&gt;E89.25&lt;/STRONG&gt;.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Automatic Client Updates (E89.21)&lt;/H2&gt;
&lt;P&gt;This is the headline change. Automatic Client Updates keeps endpoints up to date on their own, delivering the latest protections, critical fixes, and new features without a manual upgrade cycle.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Available only for &lt;STRONG&gt;cloud-managed&lt;/STRONG&gt; Endpoint Security environments. It is &lt;STRONG&gt;not supported&lt;/STRONG&gt; for clients managed by an on-premises Endpoint Security Management Server.&lt;/LI&gt;
&lt;LI&gt;To join, upgrade the Windows devices to E89.21 and follow the feature's video or admin guide.&lt;/LI&gt;
&lt;LI&gt;Rollout is gradual, so the option may take a while to appear in your console.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag2-automatic-client-updates.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35300i19686370958B56DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag2-automatic-client-updates.png" alt="diag2-automatic-client-updates.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Conflict Guard (E89.25)&lt;/H2&gt;
&lt;P&gt;A new capability that monitors for high resource usage and starts automated, targeted optimization. It uses scanner.exe through the File Protection component (CPFileAnlyz.exe). In practice this is Check Point reacting to the classic complaint of an endpoint agent fighting other software for CPU and disk.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Blocking SMB attacks without the Firewall blade (E89.25)&lt;/H2&gt;
&lt;P&gt;Blocking attacks over SMB is now possible without the Endpoint Firewall blade, using the Windows Defender Firewall. When an attack is identified, inbound &lt;STRONG&gt;SMB (TCP 445)&lt;/STRONG&gt; and &lt;STRONG&gt;NetBIOS (TCP 139, UDP 137/138)&lt;/STRONG&gt; traffic is automatically blocked. Outbound traffic stays allowed, and the containment is time limited. A log is sent to the Management Server.&lt;/P&gt;
&lt;P&gt;This matters for shops that run Harmony Endpoint without the Firewall blade and rely on Windows Defender Firewall.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Smart Pre-boot is GA (E89.05)&lt;/H2&gt;
&lt;P&gt;Smart Pre-boot went from Early Availability to GA. It adds &lt;STRONG&gt;Self-Unlock&lt;/STRONG&gt; and &lt;STRONG&gt;Mobile Login&lt;/STRONG&gt; using simple MFA through a smartphone, plus clearer mobile login instructions and Wi-Fi setup guidance at pre-boot. This is the modern replacement for the classic FDE pre-boot experience.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Quarantine Management and Remote Memory Dump (E89.05)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Quarantine Management:&lt;/STRONG&gt; a central way to analyze, restore, or delete quarantined files across the organization. Available for Early Availability customers and requires the Server on a supported version. Quarantined files are auto-deleted after 30 days by default.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Remote Memory Dump:&lt;/STRONG&gt; collect process, kernel, or full memory dumps remotely. Kernel dumps do not require a reboot (not supported on Windows 7). Full memory dumps trigger a BSOD and need prior configuration. All dumps are zipped, segmented if needed, and uploaded to Check Point FTP, Amazon S3, or a custom FTP server.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;SHA256 hashing for IoC (E89.00 / E89.10)&lt;/H2&gt;
&lt;P&gt;The File Protection component now computes &lt;STRONG&gt;SHA256&lt;/STRONG&gt; hashes for supported file types, which enables compatibility with SHA256-based indicators in Infinity IoC Management. If you drive blocks from threat-intel hashes, this closes the gap left by MD5/SHA1-only matching.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;Housekeeping you should plan for&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Capsule Docs reached End of Support&lt;/STRONG&gt; (E89.00). To upgrade a machine that has managed Capsule Docs to E89.x, you must uninstall Capsule Docs first.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Legacy Windows end of the line:&lt;/STRONG&gt; E89.10 is the &lt;STRONG&gt;last version&lt;/STRONG&gt; supported on Windows 7, Windows 8, Windows Server 2008, and Windows Server 2012 (see sk183765).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;FDE firmware compatibility (E89.25):&lt;/STRONG&gt; FDE now supports only devices that boot Windows through the standard UEFI boot order; devices that load Windows Boot Manager directly are blocked until the manufacturer ships a BIOS update, and the policy can be switched to BitLocker Management with admin consent. This one has real deployment impact and gets its own treatment in the upcoming Full Disk Encryption Deep Dive. Verify devices with BootModeReport.ps1 (sk185123) before upgrading.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;E89.x at a glance&lt;/H2&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="diag1-e89x-timeline.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35301i8B185DE9F6E8E19D/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag1-e89x-timeline.png" alt="diag1-e89x-timeline.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="background-color: #fff3cd; padding: 10px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Headline&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;E89.00&lt;/TD&gt;
&lt;TD&gt;GA&lt;/TD&gt;
&lt;TD&gt;SHA256 for IoC; Smart Pre-boot EA; Capsule Docs End of Support; hardened TLS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.05&lt;/TD&gt;
&lt;TD&gt;GA&lt;/TD&gt;
&lt;TD&gt;Smart Pre-boot GA (Self-Unlock, Mobile Login); Quarantine Management; Remote Memory Dump; Windows 11 25H2 GA&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.10&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Recommended&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;SHA256 for IoC in the standard flow; Super Node upstream proxy; broad performance/stability; last version for Windows 7/8/2008/2012&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.21&lt;/TD&gt;
&lt;TD&gt;GA&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Automatic Client Updates&lt;/STRONG&gt; (cloud-only)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E89.25&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Latest&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Conflict Guard; SMB blocking via Windows Defender Firewall; FDE firmware compatibility gate&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;H2&gt;Best Practices&lt;/H2&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; treat the September deadline as real. Inventory any clients below E88.70 and schedule them first.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; standardize on the Recommended version (E89.10) for the fleet, and use the Latest (E89.25) where you need a specific new capability.&lt;/P&gt;
&lt;P style="background-color: #eef4fb; border-left: 4px solid #2e6da4; padding: 10px;"&gt;&lt;STRONG&gt;Best Practice:&lt;/STRONG&gt; if you are cloud-managed, evaluate Automatic Client Updates on a pilot group before turning it loose on production, so you see the rollout behavior in your own environment.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Check Point SecureKnowledge sk182722, &lt;EM&gt;Enterprise Endpoint Security E89.00 Windows Clients&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk183617, &lt;EM&gt;Enterprise Endpoint Security E89.05 Windows Clients&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk183132, &lt;EM&gt;Enterprise Endpoint Security E89.10 Windows Clients&lt;/EM&gt; (Recommended)&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk185038, &lt;EM&gt;Enterprise Endpoint Security E89.21 Windows Clients&lt;/EM&gt; (Automatic Client Updates)&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk184929, &lt;EM&gt;Enterprise Endpoint Security E89.25 Windows Clients&lt;/EM&gt; (Latest)&lt;/LI&gt;
&lt;LI&gt;Check Point SecureKnowledge sk185123 (BootModeReport), sk183765 (legacy Microsoft OS support)&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Revision History&lt;/H2&gt;
&lt;TABLE style="border-collapse: collapse;" border="1" cellpadding="8"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #d9e2f3;"&gt;
&lt;TD&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Author&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Changes&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2026-09-08&lt;/TD&gt;
&lt;TD&gt;1.0&lt;/TD&gt;
&lt;TD&gt;Jorge Luiz&lt;/TD&gt;
&lt;TD&gt;Initial version. Roundup of E89.00 to E89.25 from the official release-note SKs, plus the September 2026 upgrade deadline&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Versions:&lt;/STRONG&gt; Harmony Endpoint Windows clients E89.00 to E89.25; Recommended E89.10, Latest E89.25 &lt;STRONG&gt;Last Updated:&lt;/STRONG&gt; 2026-09-08&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 10:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EN-What-Changed-in-Harmony-Endpoint-E89-x-Automatic-Client/m-p/282366#M11650</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-09-15T10:07:56Z</dc:date>
    </item>
  </channel>
</rss>

