Hello
I’m facing issues when trying to disable capabilities on Harmony Endpoint. Here’s the summary of the problem:
Inconsistent Behavior Across Endpoints:
- When I disable capabilities (e.g., Anti-Malware, Anti-Ransomware, File Protection), some features turn off, but others remain enabled.
- On some endpoints, after disabling capabilities, the status temporarily shows "In Progress" but then reverts to "Enabled."
![7be3dd34-f4c9-4009-ade7-7499bf181b59.png 7be3dd34-f4c9-4009-ade7-7499bf181b59.png](https://community.checkpoint.com/t5/image/serverpage/image-id/28611i5327AE0E09993631/image-size/medium?v=v2&px=400)
Running Services in Service(Local), Task Manager:
- Even after disabling capabilities, certain services related to Harmony Endpoint continue to run in Service(Local), Task Manager, as shown in the attached screenshots.
![572e0d2e-edb5-49c3-ba72-d8a7aa90856e.jpg 572e0d2e-edb5-49c3-ba72-d8a7aa90856e.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/28602i3A6C45D5BFE31E59/image-size/medium?v=v2&px=400)
![20241129-145149.485-3.jpg 20241129-145149.485-3.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/28608i84EC007B05485A36/image-size/medium?v=v2&px=400)
![20241129-145149.485-4.jpg 20241129-145149.485-4.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/28609i2F3326DF2BFE047E/image-size/medium?v=v2&px=400)
![20241129-145149.485-6.jpg 20241129-145149.485-6.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/28610i3ACE763E3375C8F0/image-size/medium?v=v2&px=400)
Variations in Endpoint Behavior:
- I noticed differences in behavior across endpoints. For example:
- Endpoint A: Some features successfully disable, but others stay active. (Endpoint Version 88.32.2003)
![a0d30f81-9d3d-40c3-816e-d57cbd4eb9a4.png a0d30f81-9d3d-40c3-816e-d57cbd4eb9a4.png](https://community.checkpoint.com/t5/image/serverpage/image-id/28598i299D911F70F1E5C3/image-size/medium?v=v2&px=400)
- Endpoint B: Some features successfully disable, but others stay active. (Endpoint Version 88.32.2003)
![messageImage_1732779019747.jpg messageImage_1732779019747.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/28603i85CB1FA751165306/image-size/medium?v=v2&px=400)
- Endpoint C: Features revert to "Enabled" immediately after attempting to disable them.(Endpoint Version 88.32.2003)
Troubleshooting Steps Tried:
- I attempted to disable capabilities directly from the Harmony Endpoint Console.
- Verified policies in the Software Deployment section and applied a specific policy to the problematic endpoint.
- Removed the Package for the problematic endpoint using the Apply to feature, followed by a restart of the endpoint.
- After the restart, upgraded the Threat Prevention package from the endpoint interface and attempted to disable capabilities again.
- Observed that some capabilities could not be disabled or reverted to the "Enabled" state after appearing as "In Progress."
- Checked Task Manager and Services (Local) to find that some services related to Harmony Endpoint were still running despite attempting to disable capabilities.
![d19e938f-5da5-49cc-9a69-2d6af0cd985e.png d19e938f-5da5-49cc-9a69-2d6af0cd985e.png](https://community.checkpoint.com/t5/image/serverpage/image-id/28607iE1A24616FFEE239C/image-size/medium?v=v2&px=400)
Expected Behavior:
All capabilities should be disabled consistently across endpoints once the policy is applied.
Request for Help:
Could you please provide guidance on:
- Why certain capabilities remain enabled or revert after disabling them?
- How to ensure consistent disabling of capabilities across endpoints?
- Steps to verify that services are completely stopped after disabling capabilities.
Thank you for your assistance!