> Source: [sk183452](https://support.checkpoint.com/results/sk/sk183452)

# sk183452 - Enterprise Endpoint Security E89.20 Windows Clients

| Property | Value |
|----------|-------|
| Solution ID | sk183452 |
| Date Created | 2025-05-11 |
| Last Modified | 2026-08-26 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E89.X |
| OS | Windows |

## Solution

|------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------|
| * **In a Nutshell** * **New Features and Enhancements** * **Resolved Issues** * **Endpoint Security Client Downloads** | * **Standalone Client Downloads** * **Endpoint Security Server Downloads** * **Management Console Downloads** | * **Utilities/Services Downloads** * **Known Limitations** * **Documentation \& Related SK Articles** |

**Notes:**

* See **[Endpoint Security Homepage.](https://support.checkpoint.com/results/sk/sk117536)**
* Enterprise Endpoint Security E89.20 Windows Clients is the last version supported on 32-bit Microsoft Operating Systems.
* **Full Disk Encryption is not supported on 32-bit Microsoft Operating Systems in E89.20 version**.
* Starting from E89.20, the Remediation Manager for Administrators (*AdminRemediationManagerUI.exe*) is removed. Its functionality is now integrated into the Endpoint Security Quarantine Manager.
* This release includes all limitations of earlier releases unless explicitly shown as resolved.

Click Here to Show the Entire Article

In a Nutshell {#1}
------------------

|---------------------------|-------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
| Item                      | Description                                                       | Download Link                                                                                                            |
| **Managed Client**        | E89.20 Endpoint Security Clients for Windows OS - Dynamic package | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137571) (EXE) |
| **Managed Client**        | E89.20 Endpoint Security Clients for Windows OS - Initial Client  | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137572) (ZIP) |
| **VPN Standalone Client** | E89.20 Remote Access VPN Clients for Windows                      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137575) (MSI) |

List of New Features and Enhancements in E89.20 for Windows {#2}
----------------------------------------------------------------

|------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| General                                                                                                                                                                                                                                                                                                                                                                                                                                                              ||
| AHTP-32988             | Improved and upgraded the infrastructure of the File Protection and Anti-Malware components to enhance performance.                                                                                                                                                                                                                                                                                                                          |
| AHTP-34416             | Improved and upgraded the infrastructure of the Anti-Ransomware, Behavioral Guard and Forensics components to enhance performance.                                                                                                                                                                                                                                                                                                           |
| AHTP-34273, AHTP-34204 | Improved general performance through more efficient handling of path exclusions and log file scanning.                                                                                                                                                                                                                                                                                                                                       |
| AHTP-34036             | The Remediation Manager for Administrators (AdminRemediationManagerUI.exe) is removed. Its functionality is now integrated into the Endpoint Security Quarantine Manager. Some functionality is available in the Remediation Manager UI, with an option to switch to Admin mode by providing the uninstallation password.                                                                                                                    |
| AHTP-33870             | Introduced a new application for quickly generating Endpoint Security exclusion rules by pointing to any process window or file, automatically collecting all relevant attributes.                                                                                                                                                                                                                                                           |
| Anti-Ransomware, Behavioral Guard and Forensics                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| AHTP-34564             | Optimized forensics analysis and monitoring to reduce resource usage.                                                                                                                                                                                                                                                                                                                                                                        |
| AHTP-33438             | Introduced the *hepctrl* troubleshooting tool to the Anti-Ransomware, Behavioral Guard and Forensics Software Blade, enabling debugging and investigation of forensics?related issues and injection behavior, including the ability to disable all injections or specific injection features to facilitate analysis. To use it, turn off the Self Protection feature, open a PowerShell session with admin permissions, and run "*hepctrl*". |
| AHTP-34087             | Expanded support for advanced signatures.                                                                                                                                                                                                                                                                                                                                                                                                    |
| AHTP-33437             | Improved handling of repeated unexpected exits in injected processes. The fix applies locally to the affected machine, and an event log is sent to the server.                                                                                                                                                                                                                                                                               |
| AHTP-34552             | Improved accuracy and reliability of forensics logs and reports.                                                                                                                                                                                                                                                                                                                                                                             |
| AHTP-34578             | Improved remediation when there is no Internet.                                                                                                                                                                                                                                                                                                                                                                                              |
| Full Disk Encryption                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| EPS-61248              | The Windows features "Reset this PC" and "Intune wipe" are now supported. To see the limitations, refer to [Check Point Endpoint Security Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Default.htm).                                                                                                                                                            |

{#resolvedTable}

List of Resolved Issues in E89.20 for Windows {#3}
--------------------------------------------------

{#Infrastructure}{#Infrastructure}{#Infrastructure}{#Infrastructure}{#Infrastructure}

|------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID         | Description                                                                                                                                                                                                                                               |
| General                                                                                                                                                                                                                                                               ||
| EPS-62602  | In a rare scenario, the computer becomes unresponsive after the Endpoint Security Client upgrade.                                                                                                                                                         |
| EPS-62445  | Stability improvement.                                                                                                                                                                                                                                    |
| Anti-Malware E2 (US-DHS and EU compliant)                                                                                                                                                                                                                             ||
| AHTP-34447 | In the Anti-Malware module, when a file is sent to quarantine, the "Restore" and "Permanently delete" options are available in the ClientUI's Remediation (Quarantine) page, even when policy settings are configured to prevent access to these actions. |
| Anti-Ransomware, Behavioral Guard, and Forensics                                                                                                                                                                                                                      ||
| AHTP-34719 | Fixed an issue that could cause disk usage on the endpoint to increase over time due to a processing issue in the Forensics component.                                                                                                                    |
| AHTP-34717 | For Windows Server 2016, Microsoft .NET Framework 4.7.2 must be installed on the machine before installing EP client.                                                                                                                                     |
| AHTP-33695 | In rare scenarios, there may be high CPU usage.                                                                                                                                                                                                           |
| EPS-62413  | The EFR service may exit.                                                                                                                                                                                                                                 |
| AHTP-34443 | Installation of Outlook add-in fails with the Load Behavior "*Not loaded. A runtime error during the loading of the COM Add-in*".                                                                                                                         |
| AHTP-34428 | Multi-method exclusions that combine both file path and process path are handled incorrectly.                                                                                                                                                             |
| AHTP-33436 | If a wildcard character (such as asterisk \*) is part of a path to be excluded in Behavioral Guard, the path does not work as expected for the injection sensor.                                                                                          |
| AHTP-33162 | High CPU spikes related to the logon sensor.                                                                                                                                                                                                              |
| Firewall and Application Control                                                                                                                                                                                                                                      ||
| EPS-58923  | WiFi adapter gets stuck as "Disabled" after disconnecting from LAN when the checkbox "Allow wireless connections when connected to the LAN" is not selected.                                                                                              |
| EPS-62057  | When the Application Control Software Blade is enabled, the VSMON.EXE process (part of the Endpoint Security client) may cause high CPU and memory usage.                                                                                                 |
| EPS-60760  | In rare scenarios, the Firewall filter driver fails to load.                                                                                                                                                                                              |
| EPS-62145  | After a policy update, Application Control custom rules are not applied for a few seconds.                                                                                                                                                                |
| EPS-62594  | The VSMON process may unexpectedly exit while validating some digital signature.                                                                                                                                                                          |
| EPS-63100  | In a rare scenario, an upgrade of the Endpoint Security Clients triggers a Blue Screen of Death (BSOD). When this happens, the installation process automatically rolls back and retries the upgrade.                                                     |
| Remote Access VPN                                                                                                                                                                                                                                                     ||
| ESVPN-4785 | Stability improvement.                                                                                                                                                                                                                                    |

{#resolvedTable}

Endpoint Security Client Downloads {#4}
---------------------------------------

Show / Hide this section  
> * Starting from E80.85, Endpoint Security improves coverage of malicious threats by sending anonymized Incident related data to the Check Point Threat Cloud. This feature is turned on by default. For more information, including how to disable this feature, refer to [sk129753](https://support.checkpoint.com/results/sk/sk129753).
>
> ### *Endpoint Security E89.20 Clients* {#Endpoint_Security_E85.10_ClientsE2}
>
> |----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------|
> | Package Description                                                                                                                                                                                                                                                                                                                          | Links                                                                                                                                                                                                                                             ||
> | Endpoint Security Clients for Windows OS - Dynamic package: > Complete Endpoint Security Client for any CPU (32bit or 64bit). This is a self-extracting executable EXE file with all components (Blades).                                                                                                                                    | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137571) (EXE)                                                                                                                          ||
> | Initial client: > Initial client is a very thin client without any blade used for software deployment purposes.                                                                                                                                                                                                                              | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137572) (ZIP)                                                                                                                          ||
> | Package Description                                                                                                                                                                                                                                                                                                                          | 32bit                                                                                                                    | 64bit                                                                                                                   |
> | **Endpoint Complete package:** > * Anti-Bot and URL Filtering > * Anti-Malware E2 (US-DHS and EU compliant) > * Anti-Ransomware, Behavioral Guard and Forensics > * Compliance and Posture > * Firewall and Application Control > * Full Disk Encryption > * Media Encryption and Port Protection > * Threat Emulation > * Remote Access VPN | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137573) (ZIP) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137574)(ZIP) |
>
> {#resolvedTable}   
> **Note**: Full Disk Encryption is not supported on 32-bit Microsoft Operating Systems in E89.20 version.

Standalone Client Downloads {#5}
--------------------------------

Show / Hide this section  

> **Note:** These Standalone clients do not require Endpoint Security Server installation as part of their deployment.  
>
> ### *Standalone E89.20 Clients*
>
> |----------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
> | Package                                                        | Description                                                                                                                                                                         | Link                                                                                                                     |
> | **Remote Access VPN Clients for Windows**                      | Remote Access VPN Client for SmartDashboard-managed clients                                                                                                                         | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137575) (MSI) |
> | **Remote Access VPN Clients (Automatic Upgrade file)**         | Remote Access VPN Client for automatic upgrade through the gateway. For SmartDashboard-managed clients only.                                                                        | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137576) (CAB) |
> | **Remote Access VPN Clients for ATM**                          | Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface.                                                                                    | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137577) (MSI) |
> | **Remote Access VPN Clients for ATM (Automatic Upgrade file)** | Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface for automatic upgrade through the gateway. For SmartDashboard-managed clients only. | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/137578) (CAB) |

> {#resolvedTable}

Endpoint Security Server Downloads {#6}
---------------------------------------

Show / Hide this section  
>
> |--------------------------|---------------------------------|----------------------------------------------------------------|
> | Endpoint Security Server | Package                         | Link                                                           |
> | **R82.10**               | Endpoint Security Server R82.10 | [sk183506](https://support.checkpoint.com/results/sk/sk183506) |
> | **R82**                  | Endpoint Security Server R82    | [sk181127](https://support.checkpoint.com/results/sk/sk181127) |
> | **R81.20**               | Endpoint Security Server R81.20 | [sk173903](https://support.checkpoint.com/results/sk/sk173903) |

> {#resolvedTable}

Management Console Downloads {#7}
---------------------------------

Show / Hide this section  
>
> ### *Management Console for Endpoint Security Server* {#SmartConsole for Endpoint Security Server}
>
> The SmartConsole for Endpoint Security Server allows the Administrator to connect to the Endpoint Security Server and to manage the new Endpoint Security Software Blades.
>
> |--------------------------|--------------------------------------------------|----------------------------------------------------------------------------------------------------------------|
> | Endpoint Security Server | Package                                          | Link                                                                                                           |
> | **R82.10**               | SmartConsole for Endpoint Security Server R82.10 | [link](https://support.checkpoint.com/results/download/135254)                                                 |
> | **R82**                  | SmartConsole for Endpoint Security Server R82    | [link](https://support.checkpoint.com/results/download/125531)                                                 |
> | **R81.20**               | SmartConsole for Endpoint Security Server R81.20 | [link](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20_SC/R81.20/R81.20-List-of-all-Resolved-Issues.htm) |

{#resolvedTable}  

Utilities Downloads {#8}
------------------------

Show / Hide this section  
>
> |-------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
> | Package                                                                                   | Description                                                                                                                           | Link                                                                                                                     |
> | **Full Disk Encryption Offline Management Tool (OfflineMgmtTool.msi)**                    | The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery. | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/120236) (TGZ) |
> | **Full Disk Encryption Offline Management Tool - Japanese (OfflineMgmtToolJapanese.msi)** | The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery. | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/120237) (TGZ) |

{#resolvedTable} {#Full Disk Encryption Offline Management Tool}  

Known Limitations {#9}
----------------------

Show / Hide this section  
>
> |------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Issue ID   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
> | EPS-51129  | FDE Smart Pre-boot secondary external display connected via docking station may not work. Support for secondary display via docking stations is experimental and depends on hardware, firmware settings, and display connection type.                                                                                                                                                                                                                                                                                                                                                                                      |
> | EPS-50963  | Endpoint Client Posture Management is not supported on Windows 7 OS. Automatic Download is not displayed, and the Patch status is shown as "*Update not available*".                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
> | EPS-51871  | When Windows Smart App Control is enabled, it blocks the execution of the Media Encryption offline utility (which is located on the removeable media). As a workaround, you can copy the utility *Access To Business Data.exe* to a local disk and execute it from there.                                                                                                                                                                                                                                                                                                                                                  |
> | EPS-52957  | SmartCard authentication is not supported in FDE Smart Pre-boot.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
> | ESVPN-3943 | The login prompt of Implicit Secure Domain Logon (SDL) appears before the Windows logon on the computer, which is not part of any domain.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
> | ESVPN-4305 | * If the user changes the language of the Endpoint Security Client UI, the language of the VPN UI will not be changed until the next reboot. * If the user changes the language of Endpoint Security Client UI to a non-Latin language (Russian, Greek, Chinese, etc.), he might see question marks in VPN UI unless he sets the correct language for non-Unicode applications in Windows language settings.                                                                                                                                                                                                               |
> | AHTP-30337 | For Endpoint Security Clients with Anti-Malware E2 (US-DHS and EU compliant), after an upgrade from E88.31 or lower to E88.40 or higher version: * On Windows machines that support Azure Code Signing Signatures, Check Point Endpoint Security is registered twice in the Windows Security Center. Reboot resolves the issue. * On Windows machines that do not support Azure Code Signing Signatures; after updating Windows with configuration and dependencies to support Azure Code Signing signatures, Check Point Endpoint Security is registered twice in the Windows Security Center. Reboot resolves the issue. |
> | EPS-58003  | In some scenarios, the transition from Classic Pre-boot to Smart Pre-boot may require a restart.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
> | EPS-59275  | After uninstalling the Endpoint Security Client, the computer may remain listed as registered in the Management pane. This occurs only in networks where the Client communicates with the Server through an authenticated proxy. Such proxies are not supported for sending unregistered messages. This limitation does not apply if the Client communicates directly with the Server or through an unauthenticated proxy. In those cases, the computer is removed from asset management as expected.                                                                                                                      |
> | EPS-58798  | On the devices that are joined to Microsoft Entra ID (formerly known as Azure Active Directory), the Remote Help dialog displays usernames with the "AzureAD\\" prefix, which the Endpoint Security Management Server does not recognize. When searching for a user, enter the UPN (*UserName@ExampleCompany.com* ) or plain username (*UserName*) instead.                                                                                                                                                                                                                                                                |

Documentation \& Related SecureKnowledge Articles {#10}
-------------------------------------------------------

Show / Hide this section  
>
> |-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Endpoint Security Clients                                                                                                                                                                       |
> | [Endpoint Security Clients for Windows E89.x Release Notes](https://sc1.checkpoint.com/documents/E89.x/EN/Endpoint_Security_Clients_for_Windows_RN/Default.htm)                                 |
> | [Endpoint Security Clients for Windows User Guide](https://sc1.checkpoint.com/documents/HarmonyEndpoint/Endpoint_Security_Clients_for_Windows_UserGuide/Default.htm)                            |
> | [Replacing Anti-Malware Blade with US-DHS and EU compliant Blade](https://support.checkpoint.com/results/sk/sk178307)                                                                           |
> | [Endpoint Security for Windows MDM Deployment Guide](https://sc1.checkpoint.com/documents/HarmonyEndpoint/Harmony_Endpoint_Security_for_Windows_MDM_Deployment_Guide/Default.htm)               |
> | [sk120667 - How to upgrade to Windows 10 1607 and higher with FDE in-place](https://support.checkpoint.com/results/sk/sk120667)                                                                 |
> | [sk133174 - Enterprise Endpoint Security Windows Clients for ATM](https://support.checkpoint.com/results/sk/sk133174)                                                                           |
> | [sk183716 - Enterprise Endpoint Security Hotfixes for E89.x Windows Clients Releases](https://support.checkpoint.com/results/sk/sk183716)                                                       |
> | [Endpoint Security Safe Deployment Procedure (SDP)](https://sc1.checkpoint.com/documents/HarmonyEndpoint/Harmony_Endpoint_Safe_Deployment/Harmony_Endpoint_Safe_Deployment_Procedure_(SDP).pdf) |
> | Remote Access VPN Clients                                                                                                                                                                       |
> | [E89.x Remote Access VPN Clients for Windows Release Notes](https://sc1.checkpoint.com/documents/E89.x/EN/Remote_Access_VPN_Clients_for_Windows_RN/Default.htm)                                 |
> | [Remote Access VPN Clients for Windows Administration Guide](https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Default.htm)                                        |
> | EPMaaS                                                                                                                                                                                          |
> | [Endpoint Security EPMaaS Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Default.htm)                                |
> | Endpoint Security Server                                                                                                                                                                        |
> | [Endpoint Security Server R82.10 Administration Guide](https://sc1.checkpoint.com/documents/R82.10/SmartEndpoint_OLH/EN/Default.htm)                                                            |
> | [Endpoint Security Web Management R82.10 Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_HarmonyEndpointWebManagement_AdminGuide/Default.htm)     |
> | [R82.10 Release Notes](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_RN/Default.htm)                                                                                  |
> | [Endpoint Security Server R82 Administration Guide](https://sc1.checkpoint.com/documents/R82/SmartEndpoint_OLH/EN/Content/Topics-EPSG-R82.00/Intro-to-Endpoint_Security.htm)                    |
> | [Endpoint Security Web Management R82 Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_HarmonyEndpointWebManagement_AdminGuide/Default.htm)              |
> | [R82 Release Notes](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Default.htm)                                                                                           |
> | [Endpoint Security Server R81.20 Administration Guide](https://sc1.checkpoint.com/documents/R81.20/SmartEndpoint_OLH/EN/Default.htm)                                                            |
> | [Endpoint Security Web Management R81.20 Administration Guide](https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_HarmonyEndpointWebManagement_AdminGuide/Default.htm)     |
> | [R81.20 Release Notes](https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Whats-New.htm)                                                              |
>
> <br />
>
> For more information on Check Point releases, see: [Release map](https://support.checkpoint.com/results/sk/sk152052), [Upgrade and Backward Compatibility maps](https://support.checkpoint.com/results/sk/sk113113), [Releases plan](https://support.checkpoint.com/results/sk/sk95746).
> You can also visit our [Endpoint forum](https://community.checkpoint.com/community/infinity-general/endpoint), [Remote Access forum](https://community.checkpoint.com/community/infinity-general/remote-access), or any other [CHECKMATES forum](https://community.checkpoint.com/) to ask questions and get answers from technical peers and Support experts.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
