> Source: [sk159932](https://support.checkpoint.com/results/sk/sk159932)

# sk159932 - Threat Emulation policy is not enforced on Endpoint Security Client  

| Property | Value |
|----------|-------|
| Solution ID | sk159932 |
| Date Created | 2019-08-07 |
| Last Modified | 2021-09-15 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |
| OS | Windows |

## Symptoms

- * Changes that were\\are made in the Threat emulation policy do not reflect on the Endpoint machine. For example, excluded domains that are excluded from inspection by the SandBlast extension are now being inspected while downloading a file from these domains.
* In the Endpoint Security Client "Display Overview", you see the correct Threat Emulation policy version number, and it even changes to a new version number if a new policy is pushed via SmartEndpoint.
* In *"C:\\ProgramData\\CheckPoint\\Logs\\TELog.log"* the following errors are displayed:   

  2019-07-24 14:18:56,553 \[1470:3\] **\[ERROR\] \[NetDAF\] Policy: Threat Emulation failure: DAF adaptor failed query policy content**   
  .  
  .  
  .  
  2019-07-24 14:18:57,162 \[1470:3\] \[ERROR\] \[Engine\] System.InvalidOperationException: There is an error in XML document (0, 0). ---\> System.Xml.XmlException: Root element is missing.  
  ?at System.Xml.XmlTextReaderImpl.Throw(Exception e)  
  ?at System.Xml.XmlTextReaderImpl.ParseDocumentContent()  
  ?at System.Xml.XmlTextReaderImpl.Read()  
  ?at System.Xml.XmlTextReader.Read()  
  ?at System.Xml.XmlReader.MoveToContent()  
  ?at Microsoft.Xml.Serialization.GeneratedAssembly.XmlSerializationReaderTEPolicy.Read37_TEPolicy()  
  --- End of inner exception stack trace ---  
  ?at System.Xml.Serialization.XmlSerializer.Deserialize(XmlReader xmlReader, String encodingStyle, XmlDeserializationEvents events)  
  ?at System.Xml.Serialization.XmlSerializer.Deserialize(Stream stream)  
  ?at CheckPoint.ThreatEmulation.Infrastructure.Misc.StringUtilities.DeserializeXmlFromStream\[T\](Stream stream)  
  ?at CheckPoint.ThreatEmulation.Infrastructure.Misc.StringUtilities.DeserializeXmlFromString\[T\](String xmlString)  
  ?at CheckPoint.ThreatEmulation.Infrastructure.Configuration.PolicyContainer..ctor(String xml, ePAC pac, ePolicyType type)  
  ?at CheckPoint.ThreatEmulation.Service.Engine.Engine.ApplyTePolicy()  
  2019-07-24 14:18:58,100 \[1470:3\] \[WARN\] \[SettingsProvider\] **Applying default TE policy**   
  .  
  .  
  .  
  2019-07-24 14:18:58,724 \[1470:d\] \[INFO\] \[ChromeExtensionManager\] Chrome found extension key: '1', value: 'bmnndakniegiodbmnnpcanpjddnheelf;https://clients2.google.com/service/update2/crx'  
  2019-07-24 14:18:58,724 \[1470:d\] \[INFO\] \[ChromeExtensionManager\] Removing unnecessary key. Key: '1'  
  2019-07-24 14:18:58,724 \[

## Cause

Corruption in the Threat Emulation policy files that are saved on the Endpoint machine.

## Solution

This problem was fixed. The fix is included starting from:

* [Enterprise Endpoint Security E85.20 Windows Clients](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk174345&partition=Basic&product=Endpoint)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
