<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Stop Endpoint Agent Script in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Stop-Endpoint-Agent-Script/m-p/282957#M11671</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;I have an on-prem system with 1 virtual Management Server (R81.10), and some 10K connected Windows machines running on E88.50. I need a script to stop/disable (start/re-enable) the Endpoint agent.&lt;/P&gt;&lt;P&gt;How can I make this mission possible?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2026 16:22:09 GMT</pubDate>
    <dc:creator>vincent_tx</dc:creator>
    <dc:date>2026-09-28T16:22:09Z</dc:date>
    <item>
      <title>Stop Endpoint Agent Script</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Stop-Endpoint-Agent-Script/m-p/282957#M11671</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;I have an on-prem system with 1 virtual Management Server (R81.10), and some 10K connected Windows machines running on E88.50. I need a script to stop/disable (start/re-enable) the Endpoint agent.&lt;/P&gt;&lt;P&gt;How can I make this mission possible?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2026 16:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Stop-Endpoint-Agent-Script/m-p/282957#M11671</guid>
      <dc:creator>vincent_tx</dc:creator>
      <dc:date>2026-09-28T16:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Stop Endpoint Agent Script</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Stop-Endpoint-Agent-Script/m-p/282960#M11672</link>
      <description>&lt;P&gt;Not sure this is possible with Endpoint Management, particularly on the versions listed.&lt;BR /&gt;You should be able to stop/restart the relevant services on the client possibly using a remote scripting tool.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2026 16:33:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Stop-Endpoint-Agent-Script/m-p/282960#M11672</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-28T16:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Stop Endpoint Agent Script</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Stop-Endpoint-Agent-Script/m-p/282971#M11673</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/63535"&gt;@vincent_tx&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I looked into this for a similar need, and the short answer has a catch worth sharing.&lt;/P&gt;
&lt;P&gt;There is no documented way to start or stop the Endpoint agent itself from the management. The documentation does not provide a management action that stops the client processes on the machines.&lt;/P&gt;
&lt;P&gt;What does exist in the management is a feature called &lt;STRONG&gt;Disable Capabilities&lt;/STRONG&gt;, under &lt;STRONG&gt;Client Settings&lt;/STRONG&gt;. The important part: it does not stop anything on its own. It only enables the &lt;STRONG&gt;Edit Capabilities&lt;/STRONG&gt; option on the client, so that the user (or you, locally on the machine) can turn protections off from the client UI. In that policy you choose which capabilities can be disabled, set a timeout in minutes after which they are automatically re-enabled, and optionally require a password. So it is a permission plus a time window, not a remote stop. This password and timeout behavior is available from client E88.30 onward, so your E88.50 fleet has it.&lt;/P&gt;
&lt;P&gt;The reason you cannot simply script &lt;CODE&gt;sc stop&lt;/CODE&gt; or &lt;CODE&gt;taskkill&lt;/CODE&gt; against the services is &lt;STRONG&gt;Self-Protection (Tamper Protection)&lt;/STRONG&gt;. It is designed exactly to prevent the agent from being stopped or killed, so a plain service-stop script will not work while it is active.&lt;/P&gt;
&lt;P&gt;As far as I can tell, there is no management option to force-stop the agent at scale. When the processes really need to be stopped, for example during troubleshooting with Check Point to check whether a specific blade is interfering with a genuine Windows/OS service, that is done through a dedicated Check Point tool for this purpose, and it also requires the disable/uninstall password to stop the services on Windows.&lt;/P&gt;
&lt;P&gt;Given all that, my suggestion is to open a TAC case describing exactly what you want to achieve, so they confirm the right path:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If it is temporary suspension for maintenance, &lt;STRONG&gt;Disable Capabilities&lt;/STRONG&gt; with a timeout and a password is the supported route, and it scales through computer groups.&lt;/LI&gt;
&lt;LI&gt;If you truly need to stop the services (troubleshooting a blade against an OS service), TAC can point you to the proper tool and the password requirement.&lt;/LI&gt;
&lt;LI&gt;If the goal is removal, that is the uninstall path using the uninstall password (central Uninstall push operation, or MSI with &lt;CODE&gt;UNINST_PASSWORD&lt;/CODE&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2026 21:03:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Stop-Endpoint-Agent-Script/m-p/282971#M11673</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-09-28T21:03:44Z</dc:date>
    </item>
  </channel>
</rss>

