Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
zaryhu
Participant
Jump to solution

Clarification on Automatic Client Updates and Rollback Capabilities for Endpoint Security E89.21

I was reviewing the E89.21 Windows Client release notes and noticed the introduction of the Automatic Client Updates feature:

"Introducing the Automatic Client Updates feature that ensures endpoints always stay up to date by automatically delivering the latest protections and improvements, eliminating the need for manual upgrade cycles and helping maintain continuous security."

I would appreciate some clarification on how this feature impacts change management and operational support for organizations using Check Point Endpoint Security.

Specifically:

  • Does this mean that functionality changes to the Endpoint Security thick client can now be delivered automatically outside of the traditional upgrade process?
  • If so, how are customers notified of changes that may affect user experience, security controls, or administrative workflows?
  • Will release notes continue to be published for all client changes that are delivered through Automatic Client Updates, including minor feature modifications?
  • Is there a mechanism available to delay, approve, or otherwise control deployment of these automatic updates prior to broad release?
  • In the event that a newly introduced change causes operational issues or conflicts within our environment, what rollback options are available?
  • Can organizations revert to a previous client version, or can individual automatic updates be withdrawn from endpoints?
  • Are there any administrative controls available to disable or opt out of Automatic Client Updates if an organization requires formal testing and change approval processes before client modifications are introduced?

Our concern is ensuring that we maintain visibility into changes that affect endpoint functionality and that we have a documented rollback strategy should an update introduce unexpected issues in production.

Any guidance or documentation you can provide on these topics would be greatly appreciated.

Thank you,

Zac Hudson
Information Security Analyst

1 Solution

Accepted Solutions
jorgeluiznim
Collaborator

Hi @zaryhu 

Based on my experience working with Harmony Endpoint, I’d like to share a few practical observations that may help.

Rollback

Currently, there is no native rollback mechanism for the Harmony Endpoint client. Once a client has been upgraded, it cannot simply be reverted to the previous version.

If you need to return to an earlier version, the only supported approach is to:

Uninstall the current Endpoint client.
Manually install the desired previous version.

Personally, I believe it would be very beneficial if Check Point introduced an official rollback feature, as it would greatly simplify change management and reduce operational risk.

Controlling Automatic Updates

You can control how client upgrades are handled through the Endpoint Policy.

Go to:

Policy → Client Settings → (select the policy assigned to the endpoint) → Capabilities & Exclusions → Installation & Upgrade

Under Default Installation and Upgrade, you can configure the client upgrade behavior.

From my understanding:

If this option is enabled, users can postpone the installation, but the upgrade will be enforced after a maximum of 48 hours.
If this option is disabled, there is no postponement. As soon as the endpoint receives the upgrade instruction, it will begin downloading and installing the new client version.

This provides administrators with some flexibility when planning client upgrades.

Full Disk Encryption Consideration

One important point to consider is environments using Full Disk Encryption (FDE).

In many cases, client upgrades require a system reboot. Because of this, it's important to schedule upgrades during maintenance windows whenever possible to minimize disruption for end users.

My Recommendation

In my opinion, this new Automatic Client Updates feature has the potential to simplify administration, but it may also introduce instability if updates are deployed too quickly into production.

Check Point usually identifies one client version as the Recommended release (for example, E98.10.0370 DHS (Recommended). I always recommend using the current Recommended version in production whenever possible.

Although newer releases frequently include valuable improvements and fixes, they can also introduce unexpected issues. My recommendation is to:

Keep production systems on the current Recommended version.
Test new client versions on a small group of pilot machines.
Validate that everything works correctly in your environment.
Only after successful testing should you deploy the new version to the remaining endpoints.

This approach has consistently provided the best balance between stability and staying up to date.

I hope this information helps.

If you need any additional assistance, please feel free to reach out. I'd be happy to help explain the behavior in more detail or even assist with collecting information before opening a case with Check Point TAC.

Today we also have tools that can analyze the endpoint CPInfo package, which can be very useful during troubleshooting and often helps speed up the investigation process.

Best regards,

Greetings from Brazil!

Júnior Dias

View solution in original post

(1)
1 Reply
jorgeluiznim
Collaborator

Hi @zaryhu 

Based on my experience working with Harmony Endpoint, I’d like to share a few practical observations that may help.

Rollback

Currently, there is no native rollback mechanism for the Harmony Endpoint client. Once a client has been upgraded, it cannot simply be reverted to the previous version.

If you need to return to an earlier version, the only supported approach is to:

Uninstall the current Endpoint client.
Manually install the desired previous version.

Personally, I believe it would be very beneficial if Check Point introduced an official rollback feature, as it would greatly simplify change management and reduce operational risk.

Controlling Automatic Updates

You can control how client upgrades are handled through the Endpoint Policy.

Go to:

Policy → Client Settings → (select the policy assigned to the endpoint) → Capabilities & Exclusions → Installation & Upgrade

Under Default Installation and Upgrade, you can configure the client upgrade behavior.

From my understanding:

If this option is enabled, users can postpone the installation, but the upgrade will be enforced after a maximum of 48 hours.
If this option is disabled, there is no postponement. As soon as the endpoint receives the upgrade instruction, it will begin downloading and installing the new client version.

This provides administrators with some flexibility when planning client upgrades.

Full Disk Encryption Consideration

One important point to consider is environments using Full Disk Encryption (FDE).

In many cases, client upgrades require a system reboot. Because of this, it's important to schedule upgrades during maintenance windows whenever possible to minimize disruption for end users.

My Recommendation

In my opinion, this new Automatic Client Updates feature has the potential to simplify administration, but it may also introduce instability if updates are deployed too quickly into production.

Check Point usually identifies one client version as the Recommended release (for example, E98.10.0370 DHS (Recommended). I always recommend using the current Recommended version in production whenever possible.

Although newer releases frequently include valuable improvements and fixes, they can also introduce unexpected issues. My recommendation is to:

Keep production systems on the current Recommended version.
Test new client versions on a small group of pilot machines.
Validate that everything works correctly in your environment.
Only after successful testing should you deploy the new version to the remaining endpoints.

This approach has consistently provided the best balance between stability and staying up to date.

I hope this information helps.

If you need any additional assistance, please feel free to reach out. I'd be happy to help explain the behavior in more detail or even assist with collecting information before opening a case with Check Point TAC.

Today we also have tools that can analyze the endpoint CPInfo package, which can be very useful during troubleshooting and often helps speed up the investigation process.

Best regards,

Greetings from Brazil!

Júnior Dias

(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events