R82 Check Point Endpoint Security Web Management Administration Guide
R82 Endpoint Security Web Management Administration Guide
Search
Introduction to Endpoint Web Management
Logging into Endpoint Web Management Console
Supported Operating Systems for the Endpoint Security Client
To enable token-limited registration
Automatic Deployment of Endpoint Clients
Automatic Deployment of Endpoint Clients
Troubleshooting Issues with the Tiny Agent on Windows OS
Endpoint Security Component Package
To create new deployment rules for automatic deployment
Manual Deployment of Endpoint Clients
Installing the Exported Package or Client
Adding a New VPN Site to an Exported Package
Remote Installation of Initial Client
Enable Access to the Task Scheduler Through the Windows Firewall in a Domain Profile
Remotely Installing the Initial Client
To install the Initial Client remotely from the "Push Operations" view
To install the Initial Client remotely from the Computer Management view
Windows Task Scheduler on endpoint devices
Progress of Installation and Error Handling
Monitoring Endpoint Security Deployment and Policy
Uninstalling Third-Party Anti-Virus Software Products
Manually uninstall Symantec, McAfee, or Kaspersky
To uninstall Symantec, McAfee and Kaspersky together manually
To uninstall any other Anti-Virus software manually
How to Verify that Endpoint Security can Access Check Point Servers
Uninstalling a product using an updated Products.json file
Endpoint Security Product Licenses
Getting and Applying Contracts
Managing Administrators for the Endpoint Web Management Console
Managing Users in Endpoint Security
Working with the Computers Table
Managing Storage and Peripheral Devices
Managing Storage Device Groups
Vulnerability Assessment Table
Device and Application View Reference
Configuring the Threat Prevention Policy
Policy Rule Definition Reference
To import URLs from an external source
Download (Web) Emulation & Extraction
The Behavioral Guard & Anti-Ransomware Component
Adding Exclusions to a Specific Rule
Adding Exclusions from Security Overview
Adding a New Exclusion to an Exclusion Category
Web and Files Protection Exclusions
Analysis & Response Exclusions
Optimizing the Endpoint Security Client for Servers and Profiles
Optimizing the Endpoint Security Client for Servers
To automatically optimize the Endpoint client for a server
Endpoint Security Client Device Restart Requirements
Configuring the Data Protection Policy
Configuring Full Disk Encryption
The Policy rule consists of these parts
Authentication before the Operating System Loads (Pre-boot)
User Authorization before Encryption
Passwordless Pre-boot Authentication
Enable passwordless preboot authentication
Single Sign-On with OneCheck Logon
BitLocker Encryption for Windows Clients
Taking Control of Unmanaged BitLocker Devices
FileVault Encryption for macOS
Global Policy Settings for Full Disk Encryption
Check PointFull Disk Encryption Self-Help Portal
Activating the Self-Help Portal
Configuring the Self-Help Portal
User Settings for the Self-Help Portal
Monitoring the Self-Help Portal Policy
Configuring Media Encryption and Port Protection
Configuring Business-Related File Types
See the list of business-related and non-business-related file types
Configure business and non-business related file types
Configuring Authorization Settings
To add an exclusion to a device
Advanced Settings for Media Encryption
Media Lockout (Lockout Settings)
To create a new Port Protection rule
Global Policy Settings for Media Encryption
Configuring Access & Compliance Policy
Configuring Firewall Rule Advanced Settings
Configuring Inbound/Outbound Rules
Managing Firewall Objects and Groups
Configuring the Application Control Policy
Creating the List of Applications on the Reference Device
Collect a list of applications on the reference device
Uploading the Appscan XML File to the Endpoint Security Management Server
Configuring Application Permissions in the Application Control Policy
Disabling or Enabling Windows Subsystem for Linux (WSL)
Configure Developer protection
Exclusions to Developer Protection
Configuring Compliance Policy Rules
Ensuring Alignment with the Deployed Profile
Remote Access Compliance Status
Compliance Remediation Objects
Create or change a Remediation object
Ensuring that Windows Server Updates Are Installed
Detecting Common Vulnerabilities and Exposures
Configuring Posture Assessment Settings
Configuring Global Policy Settings
Customized Browser Block Pages
Installation and Upgrade Settings
Configure a Super Node through the toolbar
Connected, Disconnected and Restricted Rules
Configure an Indicator of Compromise
Capabilities of Offline Client
Check Point Full Disk Encryption Recovery
Full Recovery with Recovery Media
Full Disk Encryption Drive Slaving Utility
To get the recovery key for a client computer
Password Reset using a Personal Key
Decrypt and recover a FileVault-encrypted Mac with APFS
For a volume formatted as CoreStorage on macOS 10.12 or higher
Giving Remote Help to Full Disk Encryption Users
Managing Active Directory Scanners
Required Permissions to Active Directory
Required configuration for domains
Active Directory Authentication
Configuring Active Directory Authentication
Configuring Alternative Domain Names
Troubleshooting Authentication in Server Logs
Troubleshooting Authentication in Client Logs
Add a device to a virtual group
Delete a device from a virtual group
Export logs from the web management interface
Creating Security Certificates for TLS Mutual Authentication
Sending Forensics Data to Third-Party Analytics Tool
Download the forensics report of an event
Endpoint Security for Linux Overview
Deploying Endpoint Security for Linux
Configuring a Proxy Server on the Endpoint Security Management Server
Downloading the Installation Script
Endpoint Security for Linux CLI Commands
Uninstall Endpoint Security for Linux
Endpoint Security for Linux Additional Information
Endpoint Security for Windows Virtual Desktop Infrastructure (VDI)
Software Blades for Persistent Desktops
Creating a Basic Golden Image for Persistent Desktops
Configuring Clients for Persistent Desktops
Creating a Pool for Persistent Desktops
Configuring Clients for Non-Persistent Desktops
Creating a Pool for Non-Persistent Desktops
Disabling the Anti-Malware Periodic Scan
Software Blades for Non-Persistent Desktops
Software Blades for Non-Persistent Desktops
Assigning Policies to VDI Pools
Disabling the Anti-Malware Periodic Scan
Advanced Settings for Persistent Desktops
Advanced Settings Non-Persistent Desktops
Disabling the Anti-Malware Periodic Scan
Advanced Settings for Persistent Desktops
Advanced Settings Non-Persistent Desktops
Configuring the Client Machine
Endpoint Security for Terminal Server / Remote Desktop Services
Deploying the Endpoint Security Client on a Terminal Server / Remote Desktop Service
Best Practice to Enable Software Blades
Appendix A - Deploying Endpoint Security Client using SCCM
Step 1: Create the Endpoint Security Windows Application in SCCM
Step 2: Deploy the Endpoint Security Windows Application in SCCM
Appendix B - Uninstalling the Endpoint Security Client (For macOS and Windows)
Appendix C - Deploying Endpoint Security Client Using Microsoft Intune
Preparing the Endpoint Security Client Windows Package for Deployment
Endpoint Security Configuration
Creating the Endpoint Security Client Windows App in Microsoft Intune
Appendix D - Microsoft Intune Wipe and Windows Reset with Full Disk Encryption
25 June 2026