> Source: [sk110975](https://support.checkpoint.com/results/sk/sk110975)

# sk110975 - Check Point Endpoint Security Client for macOS - General Limitations 

| Property | Value |
|----------|-------|
| Solution ID | sk110975 |
| Date Created | 2016-04-12 |
| Last Modified | 2026-07-05 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |
| OS | macOS |

## Solution

**This article lists general limitations for Check Point Endpoint Security Client for macOS.**   
**These limitations are in addition to those listed in the corresponding Known Limitations articles for each release.** For the list of macOS releases, see [Endpoint Security Homepage](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117536)

<br />

{#General}

|------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| General Limitations                                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| EPS-47949  | Time-limited installations are not supported.                                                                                                                                                                                                                                                                                                                                                                                                                           |
| EPS-41116  | Some Push Operations are not supported in Endpoint Security Client for macOS. See the full list in [Harmony Endpoint EPMaaS Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Introduction.htm) \> Performing Push Operations.                                                                                                                                                       |
| -          | These configurations in Common Client Settings Policy are not supported: * Client user interface settings: configurations such as custom pre-boot and One Check images and appearance of tray icon. * Allowing users to disable network protection on their computers.                                                                                                                                                                                                  |
| -          | The Big Sur macOS, (and later) may ask users to grant access to security modules after some special activities. In such cases, follow OS directives. To avoid this, Check Point recommends MDM management tools to predefine the desired configurations.                                                                                                                                                                                                                |
| -          | If nodeJS is installed on the Mac, build directories should be excluded in SBA policy (AR/EFR and TE) to improve performance.                                                                                                                                                                                                                                                                                                                                           |
| -          | The "Browsers status" column on the Asset Management page is not supported.                                                                                                                                                                                                                                                                                                                                                                                             |
| -          | The Disable Capabilities feature is supported, except the Timeout and Password options.                                                                                                                                                                                                                                                                                                                                                                                 |
| EPS-56774  | The Push Operation prompts the user with user-check/postpone messages, although the operation is not supported.                                                                                                                                                                                                                                                                                                                                                         |
| EPS-57956  | CA certificate push operation (in SmartEndpoint only) is ignored.                                                                                                                                                                                                                                                                                                                                                                                                       |
| EPS-40849  | When a device is offline, only one set of user policies is cached locally, so if a user logs out and a different user logs in, the system applies this single cached policy to all users, regardless of their identity, as it cannot retrieve the correct user-specific policies.                                                                                                                                                                                       |
| EPS-58493  | Network protection settings configured under "Client Settings" are not enforced by Harmony Endpoint Protection on macOS devices.                                                                                                                                                                                                                                                                                                                                        |
| EPS-57784  | MacOS security feature blocks execution of Check Point/Endpoint Security apps downloaded from Microsoft Teams. Refer to [sk182727](https://support.checkpoint.com/results/sk/sk182727).                                                                                                                                                                                                                                                                                 |
| EPS-48004  | Dynamic package is not supported. Exported packages and software deployment upgrade packages maintain a consistent file size, irrespective of the number of blades or components involved.                                                                                                                                                                                                                                                                              |
| EPS-61233  | Endpoint Security Clients installation is silently blocked when Harmony Browse is installed. Uninstall Harmony Browse before installing Endpoint Security Clients.                                                                                                                                                                                                                                                                                                      |
| Anti-Malware                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| EPS-26010  | Enable Web protection - not supported (always off).                                                                                                                                                                                                                                                                                                                                                                                                                     |
| EPS-26011  | Scan Mail messages - not supported (always off).                                                                                                                                                                                                                                                                                                                                                                                                                        |
| EPS-26016  | Configure Threat Cloud knowledge sharing - not supported.                                                                                                                                                                                                                                                                                                                                                                                                               |
| EPS-26017  | Process exclusion - MD5 not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| -          | Anti-Malware does not support process remediation.                                                                                                                                                                                                                                                                                                                                                                                                                      |
| EPS-62439  | Anti-Malware does not support Analysis and Remediation settings.                                                                                                                                                                                                                                                                                                                                                                                                        |
| Compliance and Posture                                                                                                                                                                                                                                                                                                                                                                                                                                                              ||
| -          | Remediation actions are not triggered on macOS.                                                                                                                                                                                                                                                                                                                                                                                                                         |
| -          | Environment variables in path of checked files are not supported                                                                                                                                                                                                                                                                                                                                                                                                        |
| -          | Compliance blade on macOS currently supports checks for these Anti-Virus vendors: |------------------------------------|-----------------------------------|-----------------------| | * Kaspersky * Check Point * Sophos | * McAfee * Symantec * CrowdStrike | * TrendMicro * Norton |                                                                                                                                                                                 |
| -          | These Compliance checks are not supported: * Latest service packs installed * running secure screen saver                                                                                                                                                                                                                                                                                                                                                               |
| -          | If the default name of the compliance rule for checking if assigned blades are running is changed, i.e. cloned or edited, this rule will not be applied to the macOS Compliance blade. Then, on the server side there will be no compliance reporting (inform, warn, restrict). Client will also not go into the assumed compliance state.                                                                                                                              |
| -          | SCV compliance check is not supported in Endpoint Security Client. SCV is supported only in VPN Standalone Client. Refer to [sk182226](https://support.checkpoint.com/results/sk/sk182226).                                                                                                                                                                                                                                                                             |
| Firewall and Application Control                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| EPS-57793  | Access Zone policy using IPv6 can be configured on the Server, but is not enforced on the client. The workaround is to configure an IPv6 rule without defining a zone.                                                                                                                                                                                                                                                                                                  |
| EPS-57770  | The "Isolate machine" push operation fails when there is no configured name server, resulting in an incomplete isolation process despite the server indicating progress.                                                                                                                                                                                                                                                                                                |
| EPS-51136  | * Stateful filtering of ICMPv6 packets is not supported on macOS. * Adding a rule which explicitly allows ICMPv4 packet adds a rule which allows ICMPv6 packet. * Some ICMPv6 packet types are always allowed.                                                                                                                                                                                                                                                          |
| -          | Firewall cannot block traffic in a VPN tunnel.                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -          | Disable Wireless on Lan feature is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ESVPN-4640 | Desktop Policy is not supported on macOS Endpoint Security Clients, only Firewall Policy is supported.                                                                                                                                                                                                                                                                                                                                                                  |
| FileVault Management Starting from E80.71 LA, the FDE Blade is replaced by FileVault Management                                                                                                                                                                                                                                                                                                                                                                                     ||
| EPS-36528  | Apple FileVault encryption cannot be stopped or reversed. Avoid install/uninstall/upgrade when FileVault is encrypting/decrypting.                                                                                                                                                                                                                                                                                                                                      |
| EPS-40903  | Time machine restore of a backup containing an Endpoint Security installation is not supported.                                                                                                                                                                                                                                                                                                                                                                         |
| -          | Only system volume is encrypted.                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| -          | Institutional Recovery Key can only be imported once.                                                                                                                                                                                                                                                                                                                                                                                                                   |
| -          | Audit logs are not generated.                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| -          | Assigning FileVault users using SmartEndpoint is not supported.                                                                                                                                                                                                                                                                                                                                                                                                         |
| -          | User Acquisition setting "Continue to acquire users after pre-boot has been enforced" is not supported.                                                                                                                                                                                                                                                                                                                                                                 |
| -          | User Acquisition setting "Pre-boot enforcement will begin after at least one user has been acquired after X days" is not supported.                                                                                                                                                                                                                                                                                                                                     |
| -          | Smart Card login is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| -          | OneCheck is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Media Encryption and Port Protection                                                                                                                                                                                                                                                                                                                                                                                                                                                ||
| -          | * ExFAT and FAT are supported by both Endpoint Security Client for Windows and Endpoint Security Client for macOS. * HFS+ is supported by Endpoint Security Client for macOS only. * NTFS is read-only on macOS. Media Encryption allows access of NON-BIZDATA but not BIZDATA.                                                                                                                                                                                         |
| -          | Offline Mode Remote Help (MEPP / macOS Offline Access Tool does not support Remote Help).                                                                                                                                                                                                                                                                                                                                                                               |
| -          | Custom Encryption is not supported (Media Encryption does not support configuration of which file(s) should be encrypted).                                                                                                                                                                                                                                                                                                                                              |
| -          | CD/DVDs and storage devices connected to ports other than USB are not supported.                                                                                                                                                                                                                                                                                                                                                                                        |
| -          | External Media that are mounted as virtual devices (Core Storage or APFS - Apple File System) are not supported.                                                                                                                                                                                                                                                                                                                                                        |
| -          | Anti-Malware scan of media is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                            |
| EPS-58442  | MEPP blade - Remote Help (Forgot password) * (E88.70 and earlier) After the correct response is entered, the media is not opened. There is an error message. * (E89.00 and later) After the correct response is entered, the media is opened, and files can be accessed. However, there is no way to set a new password. Files should be copied to different media. MEPP offline access utility - Remote Help (Forgot password) * There is no "Forgot Password" option. |
| EPS-62416  | Wildcard exclusions (\*) are not supported for "discovered devices" originating from Macs. It is recommended to use exact match exclusions instead.                                                                                                                                                                                                                                                                                                                     |
| EPS-62417  | Port protection "discovered devices" do not generate audit logs regardless of log settings, which are ignored. This applies to both "device access blocked" and "device access allowed" events when a device is attached to an endpoint computer.                                                                                                                                                                                                                       |
| EPS-60303  | Port Protection ignores the "Log" settings and always sends "discovered devices".                                                                                                                                                                                                                                                                                                                                                                                       |
| Threat Emulation                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| -          | Threat Emulation does not support process remediation.                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Remote Access VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| -          | Secure Domain Logon (SDL) is not supported                                                                                                                                                                                                                                                                                                                                                                                                                              |

{#resolvedTable}

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
