> Source: [sk183968](https://support.checkpoint.com/results/sk/sk183968)

# sk183968 - Policies Not Applying Correctly to Virtual Groups

| Property | Value |
|----------|-------|
| Solution ID | sk183968 |
| Date Created | 2025-10-20 |
| Last Modified | 2025-10-24 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Policies are not correctly applied to endpoints in Virtual Groups.
* Affected endpoints receive the default policy instead of the intended Virtual Group policy.
* The issue persists even after multiple client updates and computer restarts.
* Both on-premises and VPN-connected endpoints are affected.
* All affected endpoints can successfully communicate with both Endpoint Management Servers (EMS).

## Cause

The **Policy Operation Mode** is set to **Mixed Mode** using Old Calculation logic. In this mode, policies are matched by user rather than computer, causing incorrect policy assignment to endpoints.

## Solution

Change the **Policy Operation Mode** to **Computer mode**.  
1. Log in to Infinity Portal and access Harmony Endpoint Administrator Portal.

2. Navigate to **Endpoint** **Settings** \> **Policy Operation Mode**.

3. Change the mode to **Computer Mode**.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183968/Computer Mode202510231548211.jpg)

For more information on Policy Modes Overview, see the sections below. **Policy Modes Overview**  
**Policy Calculation Modes:**

* Old calculation - Policies are assigned and calculated either by computer or user, not both.
* New Calculation - Policies can be assigned and calculated by both user and computer. User-based rules take precedence.

**Policy Operation Modes** A policy can be assigned only according to its operation mode.

* Mixed mode - Each policy has its own defined operation mode: User, Computer, or Both (for New Calculation).
* Computer mode - All policies are assigned by computer. User-based assignment is disabled.

**Notes:**

* New servers start in Computer Mode for all blade families.
* Some policies are fixed to specific assignment types. For example: Anti-Ransomware, Behavioural Guard, Forensics, and Full Disk Encryption are always Computer policies; OneCheck is always a User policy.

The new calculation view displays combined user and device icons.
![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1757941316429/2202509151817281.jpg)  
The old calculation view shows either a user or a device icon, not both.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1757941316429/image (1)202509151817573.jpg)  

**Note:** If the policy is found to be operating in the old calculation mode, open a support ticket. Include screenshots showing the policy operation mode and the server connection token or tenant ID.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
