Hi All,
I am about to deploy Check Point Endpoint Security client 80.30 with Antimalware Engine 2 (E2) on a number of Windows Server 2019 and 2016 Hyper-V Guest VMs and at least 1 bare metal server.
As of yet, I have not heard what the official installation procedure should be considering the content of this Knowledgebase article, which indicates that Server 2019 no longer plays nice by disabling it's internal antivirus and firewall components when 3rd party security clients are installed.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
The SK mentions that you must disable Windows Defender Antivirus and Firewall BEFORE installing the CPEP client,
I had not seen or heard of this behavior before installing CPEP on a windows server 2019 VM hosting our Blackberry UEM MDM platform, so CPEP went in on top of the MS components. I have since only disabled the Windows Defender Firewall for just "domain" network profile for that VM.)
The SK also mentions that this can be done "via GPO" but does not cover how. (caveat, I have yet to, but will fully read through the whole admin guide and whatever other documentation I can find for the latest releases of CPEP to see if it is covered there and will report back if I have a definitive answer)
With that said,
The following Microsoft post:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windo...
Which suggests that a registry edit will make WD AV go "passive" is enough,
Is somewhat in conflict with this Microsoft post
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windo...
Which somewhat ambiguously seems to state that you can uninstall windows defender completely using the add remove roles and features Wizard, after suggesting earlier in the post that removing the feature components only removes the user interface.
All very confusing.
Anyway, would anyone from Check Point proper like to suggest the specific steps one should take if we intend to deploy CPEP to even a newly built Windows 2016 or 2019 server with nothing but the OS installed yet?
What would be the GPO to which the SK refers?
Should we be uninstalling the whole feature as described in the second Microsoft link?
Also, regarding the aforementioned Blackberry UEM server: I deployed the client while actually working with CP support on a Zoom remote support session. I happened to notice that windows firewall was still running during the same remote session; I was told at that stage that the wscsvc service was removed in the OS and this is Microsoft's doing and by their design. At the end of the day I am therefore at a disadvantage in the case of this specific production server if I was supposed to turn off Windows Defender Anti-Malware BEFORE installing CPEP.
So, a specific question, did I break anything by having installed CPEP on a windows Server 2019 machine before "turning off" Windows Defender Anti-Malware? I would assume not if the TAC engineer did not indicate this, but I want to be sure. Once I know what the correct "turn off" method is for Defender per CP, I just hope there is nothing I need to worry about having done things in the wrong order.
I would be interested to hear anyone's experiences with CPEP and Windows Server 2016 / 2019 and whether you noticed any issues, or whether you realized that Windows Defender components were still running.
Thanks!
Chris.
EDIT:
This is Microsoft's Antivirus and antimalware software: FAQ for reference:
https://support.microsoft.com/en-us/help/4466972/windows-10-antivirus-and-antimalware-software-faq#m...