<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot Fully Disable Capabilities on Harmony Endpoint in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Cannot-Fully-Disable-Capabilities-on-Harmony-Endpoint/m-p/234380#M9715</link>
    <description>&lt;P&gt;You may want to check that the policies are correctly applied to the Endpoints in question (Menu &amp;gt; Advanced &amp;gt; View Policies).&lt;BR /&gt;They should have the same version/date.&lt;BR /&gt;And yes, I second the suggestion to get TAC involved.&lt;BR /&gt;They are probably going to want logs, which you collect from the client (Menu &amp;gt; Advanced &amp;gt; Collect) and review for yourself as it might provide some clues.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Dec 2024 21:28:46 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-12-02T21:28:46Z</dc:date>
    <item>
      <title>Cannot Fully Disable Capabilities on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Cannot-Fully-Disable-Capabilities-on-Harmony-Endpoint/m-p/234143#M9701</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I’m facing issues when trying to disable capabilities on Harmony Endpoint. Here’s the summary of the problem:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Inconsistent Behavior Across Endpoints:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When I disable capabilities (e.g., Anti-Malware, Anti-Ransomware, File Protection), some features turn off, but others remain enabled.&lt;/LI&gt;&lt;LI&gt;On some endpoints, after disabling capabilities, the status temporarily shows "In Progress" but then reverts to "Enabled."&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7be3dd34-f4c9-4009-ade7-7499bf181b59.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28611i5327AE0E09993631/image-size/medium?v=v2&amp;amp;px=400" role="button" title="7be3dd34-f4c9-4009-ade7-7499bf181b59.png" alt="7be3dd34-f4c9-4009-ade7-7499bf181b59.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Running Services in Service(Local), Task Manager:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Even after disabling capabilities, certain services related to Harmony Endpoint continue to run in Service(Local), Task Manager, as shown in the attached screenshots.&lt;/LI&gt;&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="572e0d2e-edb5-49c3-ba72-d8a7aa90856e.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28602i3A6C45D5BFE31E59/image-size/medium?v=v2&amp;amp;px=400" role="button" title="572e0d2e-edb5-49c3-ba72-d8a7aa90856e.jpg" alt="572e0d2e-edb5-49c3-ba72-d8a7aa90856e.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20241129-145149.485-3.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28608i84EC007B05485A36/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20241129-145149.485-3.jpg" alt="20241129-145149.485-3.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20241129-145149.485-4.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28609i2F3326DF2BFE047E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20241129-145149.485-4.jpg" alt="20241129-145149.485-4.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20241129-145149.485-6.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28610i3ACE763E3375C8F0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="20241129-145149.485-6.jpg" alt="20241129-145149.485-6.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Variations in Endpoint Behavior:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I noticed differences in behavior across endpoints. For example:&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Endpoint A&lt;/STRONG&gt;: Some features successfully disable, but others stay active. (Endpoint Version 88.32.2003)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a0d30f81-9d3d-40c3-816e-d57cbd4eb9a4.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28598i299D911F70F1E5C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="a0d30f81-9d3d-40c3-816e-d57cbd4eb9a4.png" alt="a0d30f81-9d3d-40c3-816e-d57cbd4eb9a4.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Endpoint B&lt;/STRONG&gt;: Some features successfully disable, but others stay active.&amp;nbsp;(Endpoint Version 88.32.2003)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="messageImage_1732779019747.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28603i85CB1FA751165306/image-size/medium?v=v2&amp;amp;px=400" role="button" title="messageImage_1732779019747.jpg" alt="messageImage_1732779019747.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Endpoint C&lt;/STRONG&gt;: Features revert to "Enabled" immediately after attempting to disable them.(Endpoint Version 88.32.2003)&lt;/LI&gt;&lt;LI&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6365318716112w400h225r251" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6365318716112" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6365318716112w400h225r251');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6365318716112"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;Troubleshooting Steps Tried:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I attempted to disable capabilities directly from the Harmony Endpoint Console.&lt;/LI&gt;&lt;LI&gt;Verified policies in the &lt;STRONG&gt;Software Deployment&lt;/STRONG&gt; section and applied a specific policy to the problematic endpoint.&lt;/LI&gt;&lt;LI&gt;Removed the &lt;STRONG&gt;Package&lt;/STRONG&gt; for the problematic endpoint using the &lt;STRONG&gt;Apply to&lt;/STRONG&gt; feature, followed by a restart of the endpoint.&lt;/LI&gt;&lt;LI&gt;After the restart, upgraded the &lt;STRONG&gt;Threat Prevention&lt;/STRONG&gt; package from the endpoint interface and attempted to disable capabilities again.&lt;/LI&gt;&lt;LI&gt;Observed that some capabilities could not be disabled or reverted to the "Enabled" state after appearing as "In Progress."&lt;/LI&gt;&lt;LI&gt;Checked Task Manager and &lt;STRONG&gt;Services (Local)&lt;/STRONG&gt; to find that some services related to Harmony Endpoint were still running despite attempting to disable capabilities.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="d19e938f-5da5-49cc-9a69-2d6af0cd985e.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28607iE1A24616FFEE239C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="d19e938f-5da5-49cc-9a69-2d6af0cd985e.png" alt="d19e938f-5da5-49cc-9a69-2d6af0cd985e.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;Expected Behavior:&lt;/STRONG&gt;&lt;BR /&gt;All capabilities should be disabled consistently across endpoints once the policy is applied.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Request for Help:&lt;/STRONG&gt;&lt;BR /&gt;Could you please provide guidance on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Why certain capabilities remain enabled or revert after disabling them?&lt;/LI&gt;&lt;LI&gt;How to ensure consistent disabling of capabilities across endpoints?&lt;/LI&gt;&lt;LI&gt;Steps to verify that services are completely stopped after disabling capabilities.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thank you for your assistance!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 08:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Cannot-Fully-Disable-Capabilities-on-Harmony-Endpoint/m-p/234143#M9701</guid>
      <dc:creator>PHUM888</dc:creator>
      <dc:date>2024-11-29T08:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Fully Disable Capabilities on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Cannot-Fully-Disable-Capabilities-on-Harmony-Endpoint/m-p/234148#M9702</link>
      <description>&lt;P&gt;Open SR# with CP TAC to get the reason for this behaviour !&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 08:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Cannot-Fully-Disable-Capabilities-on-Harmony-Endpoint/m-p/234148#M9702</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-11-29T08:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Fully Disable Capabilities on Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Cannot-Fully-Disable-Capabilities-on-Harmony-Endpoint/m-p/234380#M9715</link>
      <description>&lt;P&gt;You may want to check that the policies are correctly applied to the Endpoints in question (Menu &amp;gt; Advanced &amp;gt; View Policies).&lt;BR /&gt;They should have the same version/date.&lt;BR /&gt;And yes, I second the suggestion to get TAC involved.&lt;BR /&gt;They are probably going to want logs, which you collect from the client (Menu &amp;gt; Advanced &amp;gt; Collect) and review for yourself as it might provide some clues.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 21:28:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Cannot-Fully-Disable-Capabilities-on-Harmony-Endpoint/m-p/234380#M9715</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-02T21:28:46Z</dc:date>
    </item>
  </channel>
</rss>

