Hi @zaryhu
Based on my experience working with Harmony Endpoint, I’d like to share a few practical observations that may help.
Rollback
Currently, there is no native rollback mechanism for the Harmony Endpoint client. Once a client has been upgraded, it cannot simply be reverted to the previous version.
If you need to return to an earlier version, the only supported approach is to:
Uninstall the current Endpoint client.
Manually install the desired previous version.
Personally, I believe it would be very beneficial if Check Point introduced an official rollback feature, as it would greatly simplify change management and reduce operational risk.
Controlling Automatic Updates
You can control how client upgrades are handled through the Endpoint Policy.
Go to:
Policy → Client Settings → (select the policy assigned to the endpoint) → Capabilities & Exclusions → Installation & Upgrade
Under Default Installation and Upgrade, you can configure the client upgrade behavior.
From my understanding:
If this option is enabled, users can postpone the installation, but the upgrade will be enforced after a maximum of 48 hours.
If this option is disabled, there is no postponement. As soon as the endpoint receives the upgrade instruction, it will begin downloading and installing the new client version.
This provides administrators with some flexibility when planning client upgrades.
Full Disk Encryption Consideration
One important point to consider is environments using Full Disk Encryption (FDE).
In many cases, client upgrades require a system reboot. Because of this, it's important to schedule upgrades during maintenance windows whenever possible to minimize disruption for end users.
My Recommendation
In my opinion, this new Automatic Client Updates feature has the potential to simplify administration, but it may also introduce instability if updates are deployed too quickly into production.
Check Point usually identifies one client version as the Recommended release (for example, E98.10.0370 DHS (Recommended). I always recommend using the current Recommended version in production whenever possible.
Although newer releases frequently include valuable improvements and fixes, they can also introduce unexpected issues. My recommendation is to:
Keep production systems on the current Recommended version.
Test new client versions on a small group of pilot machines.
Validate that everything works correctly in your environment.
Only after successful testing should you deploy the new version to the remaining endpoints.
This approach has consistently provided the best balance between stability and staying up to date.
I hope this information helps.
If you need any additional assistance, please feel free to reach out. I'd be happy to help explain the behavior in more detail or even assist with collecting information before opening a case with Check Point TAC.
Today we also have tools that can analyze the endpoint CPInfo package, which can be very useful during troubleshooting and often helps speed up the investigation process.
Best regards,
Greetings from Brazil!
Júnior Dias