I could not reproduce this on the current Recommended client. On Harmony Endpoint 89.10.0370 (Recommended), that exact link (https://login.microsoftonline.com/common/FederationMetadata/2007-06/FederationMetadata.xml) renders correctly in Firefox, Chrome and Edge with the Web Protection extension active. Combined with @wizard_pl noting it does not happen on another machine with the same builds, this looks version or config dependent rather than universal, which is worth pinning down before or alongside a TAC case.
A few things that would help narrow it, if you can share them:
- The exact Harmony Endpoint client version on the affected machine, not just the extension build. You listed extension 990.106.104 and Firefox 140 ESR / 153, but the client version is usually the piece that matters here.
- Confirmation of what you are doing and where it works: is it only Firefox that strips the tags while Chrome and Edge are fine on the same machine with the same file, and is it any XML/WSDL or only specific ones.
- A screenshot of the corrupted rendering, so we can see exactly how the tags are stripped.
For evidence and logs:
- From the browser extension, use “Collect event logs” in the Harmony Endpoint extension popup (the button at the bottom of the panel).
- From the client, open the client UI, go to the Logging section, “Collect additional information for technical support”, and click Collect to generate a client cpinfo.
One concrete test: since it renders fine on the current Recommended client, update the affected machine to the latest Check Point Recommended version and re-test the same file in Firefox. If it clears up, it was fixed or config related; if it persists, you now have a clean cpinfo plus extension logs to hand to TAC.
If you can gather those, share them here and we can try to help narrow what differs between the affected machine and the one that works. @PhoneBoy is right that this may still need TAC, but that package makes their job much faster.