> Source: [sk183471](https://support.checkpoint.com/results/sk/sk183471)

# sk183471 - Frequent "Threat Emulation is disabled due to invalid license" Logs and Intermittent License Status Changes in Harmony Endpoint Security Overview 

| Property | Value |
|----------|-------|
| Solution ID | sk183471 |
| Date Created | 2025-05-15 |
| Last Modified | 2025-05-16 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | R81.20 |

## Symptoms

- * *Threat Emulation is disabled due to invalid license* log appears frequently in the logs across many devices.
* Intermittent changes in license status from *Valid* to *Invalid* on endpoint machines, typically resolving within 2 minutes
* The issue is observed after client or service restarts.
* The error message appeared frequently even though license contracts were valid and up to date.

## Cause

The issue could be caused by any of these reasons:

1. Backend License Response Issue  
   The Endpoint Security Management Server intermittently sent empty license responses to the clients after service restarts or license checks. This caused clients to temporarily mark their license as invalid. The issue was due to a backend problem in the license response handling logic.  

2. Policy Configuration  
   The policy configuration on the Security Management Server did not have either Threat Emulation or Threat Extraction capabilities enabled for some device groups. At least one of these capabilities must be enabled for Threat Emulation to be assigned and the license to be considered valid.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
