The solution is primarily used to protect us. It's a tool that we have installed on all the users from sales.
CISO at a financial services firm with 51-200 employees
Well priced, simple to set up and easy to layer in with other products
Pros and Cons
- "It's a scalable product as it is a cloud offering."
- "Specifically, there are gaps when it comes to security."
What is our primary use case?
What is most valuable?
Overall, it's a good tool. It's doing a good job for what it is designed for.
It is easy to set up.
The solution is stable.
It's a scalable product as it is a cloud offering.
You can layer in this solution with others. I like layering myself with various technologies, depending on the environment we're working in.
The product offers good pricing.
What needs improvement?
Everything can always be improved. Specifically, there are gaps when it comes to security.
For how long have I used the solution?
I've been using the solution for a couple of years now.
Buyer's Guide
Check Point Harmony Endpoint
June 2025

Learn what your peers think about Check Point Harmony Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
What do I think about the stability of the solution?
If you go by the recommended version, yes, it's stable.
What do I think about the scalability of the solution?
The cloud offering is scalable.
We have about two hundred or more users on the solution.
Which solution did I use previously and why did I switch?
We're also using Sophos.
How was the initial setup?
The solution is very straightforward to set up. It's not overly complex or difficult.
To set it up from the server-side, the deployment takes a couple of hours. To set it up from the user side, it's a couple of minutes.
What's my experience with pricing, setup cost, and licensing?
The product is reasonably priced. It's not overly expensive.
Which other solutions did I evaluate?
Currently, we're looking at CrowdStrike. We have not yet bought it. We're currently talking about options. I'm already set with a good partner on it and just discussing right now, discussing what is best suited as a product, rather than pricing.
What other advice do I have?
I am a customer and an end-user.
I'm not sure which version we are using currently, however, it is visible in the portal. The solution is a software as a service.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

IT Security Manager at a manufacturing company with 1,001-5,000 employees
Great threat emulation and threat extraction features with helpful forensics
Pros and Cons
- "The forensics allows us to search retrospectively for an URL or file opened by users, for example, when you need to quickly check who else has clicked on a phishing link."
- "Unfortunately, the web (cloud) management system and log search performance are quite bad."
What is our primary use case?
We use Harmony on every PC to add additional protection primarily to file downloads. We use it alongside our classic AV solution (non-Check Point). Every file is scanned via Threat Emulation (virtual sandboxing) and Threat Extraction (sanitizing files by removal of active content).
The anti-phishing module scans every new web form, that the user is trying to enter data in. Based on visual similarities to known sign-in websites (like Microsoft Azure's) it blocks the phishing ones that are similar.
The forensics module allows us to retrospectively search for a wide number of events on all PCs (for example for now-known malicious URLs or files)
How has it helped my organization?
Harmony mainly filled the gap in e-mail security, allowing us to check what the user has clicked (and blocks it when needed).
It also has a nice phishing form detection blocking users from entering their credentials on many real-life phishing websites.
The forensic log search (as described above) allows us to quickly do a retrospective search for a file or URL that we found malicious.
The features come in handy during Covid-related extended remote work times, when we were able to provide better security to our employees working off-premises.
What is most valuable?
The most valuable features are threat emulation and threat extraction. Despite some false positives, it gives quite good security for file downloading.
Phishing form detection based on on-site similarity (not only on URL) has at least 50% efficiency in real-life examples that passed our antispam systems (and most of the false negatives are pretty general forms, which are not so convincing to the user).
The forensics allows us to search retrospectively for an URL or file opened by users, for example, when you need to quickly check who else has clicked on a phishing link.
What needs improvement?
Unfortunately, the web (cloud) management system and log search performance are quite bad. Sometimes it takes longer to perform simple tasks and scrolling the results of the log is annoying due to frequent refreshes.
The exception management was always the Achilles' heel of Check Point products. It was a bit improved in Harmony, still, you can't for example exclude a site from anti-phishing form checks (which could take a few secs) while not excluding it from attachment scanning.
The forensics module still doesn't allow for HTTPS URLs entered by users. You are limited to DNS search or IP lookup. This doesn't make sense from a technical standpoint as the URLs are passing Harmony checks so they are known to the solution.
Anti-phishing cannot scan a form located inside an HTML e-mail attachment (which is a common practice in real-life attacks).
For how long have I used the solution?
I've used the solution for one year.
What do I think about the scalability of the solution?
Cloud management performance is sometimes quite bad for day-to-day tasks, although it is not related to the number of endpoints.
How was the initial setup?
If you limit browser extension via GPO, there might be conflicts with Harmony's that generally overwrites your config in some modes (per user vs per device enforcement).
What's my experience with pricing, setup cost, and licensing?
Pricing isn't cheap, especially if you want to extend forensic log retention period from default one week.
What other advice do I have?
It's still being actively developed and still needs some improvement.
In general, it's quite good now regarding security and might get even better.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Check Point Harmony Endpoint
June 2025

Learn what your peers think about Check Point Harmony Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
Project Manager at Junta de Andalucia
Enables us to centralize all the security software used in a console and avoid ransomware
Pros and Cons
- "The graphical interface is very easy to use and intuitive, which greatly facilitates the work and greatly facilitates the work and the location of threats on the users' computers."
- "SandBlast Agent had moments in which it had a high load, we escalated it to the CheckPoint support that helped us to stabilize it. We had a problem with the parameterization of the solution. Once corrected by following the CheckPoint instructions, everything worked normally again."
What is our primary use case?
We were looking for a solution as complete as possible to replace the existing antivirus and, if possible, integrate it with other products that we have, such as the CheckPoint firewall.
We decided to use the Check Point SandBlast agent to prevent ransomware on users' computers.
We subsequently expanded the scope of the solution to detect malicious activity on our network.
It is a very complete product but you have to know how to parameterize it well to avoid high CPU consumption.
It is also missed that it does not have a client for Linux.
How has it helped my organization?
Check Point SandBlast Agent allows us to centralize all the security software used in a console and avoid, mainly, ransomware in the company.
Many of our users have laptops to carry out teleworking, with this tool we can secure their web browsing, and in the event of suffering some type of attack, the computer is notified by SandBlast Agent and provides information about it and the security actions carried out. It even allows you to restore files modified during the attack.
You also have the option of performing a forensic analysis of the infected computer by providing a lot of information.
What is most valuable?
What we liked the most about the product, apart from detecting any attempted attack, is the graphical interface.
The graphical interface is very easy to use and intuitive, which greatly facilitates the work and greatly facilitates the work and the location of threats on the users' computers.
We also highly value the anti-ransomware functionality, which creates a copy of the files on the computers and in case of infection by ransomware is able to restore them to a date when the computer was not infected.
What needs improvement?
It is a very complete product but you have to know how to parameterize it well to avoid high CPU consumption.
SandBlast Agent had moments in which it had a high load, we escalated it to the CheckPoint support that helped us to stabilize it. We had a problem with the parameterization of the solution. Once corrected by following the CheckPoint instructions, everything worked normally again.
It is also missed that it does not have a Linux client since some administrators use this type of operating system.
For how long have I used the solution?
I have been using SandBlast for over 1 year now.
What do I think about the stability of the solution?
It is a very mature product that provides great stability in service.
What do I think about the scalability of the solution?
It is a very mature product with good performance. Currently we have not needed to use its scalability.
How are customer service and support?
Our experience with customer service and support is very good, the support is totally professional and responds quickly.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we used third-party antivirus software and switched to Check Point SandBlast Agent for its ease of integration with other Check Point products and to improve protection against ransomware.
How was the initial setup?
Initial setup is easy, policies and user groups are defined and then applied. Then we adjusted the policies until we got what we needed.
What about the implementation team?
We implemented it with an internal team and when we had doubts, we consulted the manufacturer's support with a totally satisfactory result due to their great experience.
What was our ROI?
Currently we have not quantified our ROI but we have avoided the loss of information on user computers due to viruses, ransomware, ...
What's my experience with pricing, setup cost, and licensing?
The cost of the solution is similar to other products on the market.
Which other solutions did I evaluate?
We have been evaluating other products, such as Bitdefender and Broadcom (Symantec Enterprise).
What other advice do I have?
It is a very complete product but you have to know how to parameterize it well to avoid high CPU consumption.
It is also missed that it has no client for linux.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a renewables & environment company with 51-200 employees
Great cloud management and reporting with on easy pane of glass
Pros and Cons
- "The rollout and management of devices were very simple."
- "The web filter service could be improved."
What is our primary use case?
We wanted to consolidate a several-point solution to one endpoint. With so many new cyber threats and having a growing environment, what we had in place had too many gaps or grey areas between solutions and vendors.
Also, with a rapid transition to hybrid working, we needed to reconsider our end point protection. Having used Check Point NGFW for five years, it seemed like a good fit. Also, the experience and long term position of Check Point in the security market gave us good confidence. This mature position in the market also helped with finding several resellers and experience.
How has it helped my organization?
There is one pane of glass to all end points, events, and incidents which is providing our team with a clear picture of the environment. We have already experienced several items that previously just got lost in the greyness of a multi-solution environment.
The rollout and management of devices were very simple. It allowed for a rollout of 200+ devices - all remote - in just a couple of weeks. Having cloud-based management also really helped get started, as, within the day, we had a POC running and just started to grow from there.
What is most valuable?
Cloud management and reporting are great. The management interface is very simple and easy to navigate. Just getting a logon to start is very helpful. The Check Point support at this stage was great. While it was very simple and intuitive, having someone talk over the defaults provided recommendations that helped us jump forward very easily.
Again, the cloud management service has a several inbuilt default reports which are easy to customize and provide more visibility than we have had previously with several solutions.
What needs improvement?
The web filter service could be improved. It would be great to have a self-service user request for sites. An administrator would still need to approve, however.
The block screen could have a nicer screen or allow it to be customized.
The list of exceptions for URLs could be improved with a separate screen for a large list of exceptions. Having the same exception list for mobile and endpoints would be great.
We are hoping to transition to the SOC based service. Think this is still new; we're looking forward to get more information and test.
For how long have I used the solution?
We just transitioned to Check Point Harmony, and have been running it now for six weeks.
What do I think about the stability of the solution?
Stability seems very strong, however, it's early days.
What do I think about the scalability of the solution?
Scalability seems very strong, however, it is early days.
How are customer service and support?
We don't know yet.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
The move to hybrids has been working well during Covid.
How was the initial setup?
The initial setup was not complex.
What about the implementation team?
We did both - we implemented through a vendor and in-house.
What was our ROI?
The product offers a great lower cost than previous solutions.
What's my experience with pricing, setup cost, and licensing?
I'd advise users to talk to your Check Point partners or find a good one.
Which other solutions did I evaluate?
We spent a long time reviewing the marketplace and comparison sites however, we did not test anything.
What other advice do I have?
I am very positive in terms of the solution and Check Point in general.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Specalist at vTech Solution
Constantly updated with good zero-day prevention and excellent prevention capabilities
Pros and Cons
- "Harmony Endpoint is a complete endpoint security solution built to protect the remote workforce from today's complex threat landscape."
- "They could improve memory consumption."
What is our primary use case?
Check Point Endpoint Security is to protect our employee endpoints as we're currently working from home. The user is totally unaware of the cyber threats, so the basic functionality of endpoint security provides a lot more security. With it, any threat attack can be rebuffed. Any user downloading any suspicious data from the web will first have Check Point scan it deeply. If there's malware then it quarantines it. Otherwise, the user can access it. We're using it on a primary basis. We don't have any other solutions in place apart from the Check Point.
How has it helped my organization?
Harmony Endpoint is a complete endpoint security solution built to protect the remote workforce from today's complex threat landscape.
It prevents the most imminent threats to the endpoint such as ransomware, phishing, or drive-by malware, while quickly minimizing breach impact with autonomous detection and response. That's how our organization improved its security. Before that, we didn't have the security to prevent such threats as ransomware, phishing, etc. Due to that, our IT environment is more secure and business has also increased.
What is most valuable?
The product offers advanced anti-malware and antivirus protection to protect, detect, and correct malware across multiple endpoint devices and operating systems. Proactive web security is available to ensure safe browsing on the web. Data classification and data loss prevention are there to prevent data loss and exfiltration.
SandBlast Agent defends endpoints and web browsers with a complete set of real-time advanced browser and endpoint protection technologies, including Threat
Emulation, Threat Extraction, Anti-Bot, and Zero Phishing.
The zero-day prevention is very valuable.
What needs improvement?
Personally, I'm looking forward to separating server management policies. They could improve memory consumption. Once we installed a CP agent in our system, we found that it was consuming more memory. Even a normal configuration system can be hung.
Malware detection is an add-on plan that can't be added on. It's the most important part of endpoint security. There's a forensic addon which is very important after threat hunting against attacks.
For how long have I used the solution?
I've been using this solution for two years.
What do I think about the stability of the solution?
I haven't seen any corruption on the agent side. It's stable.
What do I think about the scalability of the solution?
It's scalable. It always updates its malware database for security concerns on a daily basis
How are customer service and support?
Technical support is good. You can raise a ticket with the CP support portal and a technician will contact you based on the severity.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I didn't have that much experience with anything else. When I was joined, our company was using the same solution.
How was the initial setup?
The solution's initial setup is straightforward. Even new users can handle the process with help of online guidelines.
What about the implementation team?
We used a vendor team and they were experts in what they were doing.
What was our ROI?
As a security solution, of course, it gives back lots of return on investment.
What's my experience with pricing, setup cost, and licensing?
The setup cost is nothing. The licensing is costly due to the fact that, in return, it's giving the best security.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Presales Engineer at Data Warden
Robust and reliable with a useful Full Disk Encryption feature
Pros and Cons
- "There's the possibility of being able to do the administration from the Check Point portal, maintaining control and visibility of the different security events at all times."
- "They could be focused on the analysis of USB devices."
What is our primary use case?
We started using the product months before the start of the pandemic. It is a robust solution for the protection of endpoints. It contains the classic antivirus, however, it has anti-bot and disk encryption functions (FDE) as well as the integration of a sandboxing for the consultation and download of files in a safe way (whether they are downloaded from a page or from an email).
It is a very complete tool for users who need to be able to connect from home or some other public access point since it has a VPN service, in addition to different layered-in security solutions.
How has it helped my organization?
The addition of Check Point's Harmony Endpoint as the main security tool for the company's collaborators has represented a reliable source of security since updates can be executed automatically or manually, as may be required.
There's the possibility of being able to do the administration from the Check Point portal, maintaining control and visibility of the different security events at all times.
Admin users are able to access an adjustable dashboard that shows the most relevant information about the status of the endoints and the statistics of threats found.
What is most valuable?
Without a doubt, the best security feature is Full Disk Encryption (FDE). In cases where the endpoint is stolen or lost, you are sure that the information will not be accessible without the access password being the correct, maintaining the confidentiality of files at all times.
In addition, if someone tries to extract the physical disk and places it as a removable disk in a PC, they will not have access to the information either, since the files are still encrypted, ensuring that this method of extracting the information does not work without the decryption key.
What needs improvement?
They could be focused on the analysis of USB devices. It has the ability to block the use of USB storage memories until it is completely scanned for any virus or threat. We need to ensure that the USB device will not be available until the scan has been completed, however, this may represent a malfunction when using other tools such as Rufus, as, by blocking access to USB drives, Harmony Endpoint will block access to these drives, thus Rufus will not be properly detecting USB drives and therefore it cannot operate properly.
For how long have I used the solution?
I've used the solution for one year and eight months.
What do I think about the stability of the solution?
I have had almost no problems with the execution of the software agent and it is very useful when I need to do research on the internet.
What do I think about the scalability of the solution?
It is fully scalable by scheduling updates from the console. When the agent is updated it will be necessary to update the PC, however.
How are customer service and support?
As a user, I have not had contact with the manufacturer's technical support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We did not use a different solution.
How was the initial setup?
Although it is an intuitive configuration, due to the variety of blades available, it may take some time to complete the configuration. Everything will depend on the number of blades a company needs to configure.
What about the implementation team?
We handled the implementation in-house.
What's my experience with pricing, setup cost, and licensing?
Licensing is based on sizing and based on the number of users and the desired security blades. All versions include access to the Check Point web portal for administration.
Which other solutions did I evaluate?
We did not evaluate other options.
What other advice do I have?
By acquiring this tool, companies will have a robust and reliable solution for endpoint protection.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager, IT Infrastructure and Security at Control Southern Inc.
Great anti-ransomware blade, provides HTML reports, and protects endpoints well
Pros and Cons
- "One of the coolest features is that it provides an HTML report on the laptop and the endpoint console for the administrator."
- "The product updates are a manual process for my administrator and can take several hours out of his day."
What is our primary use case?
This solution handles AV, malware, VPN, ransomware and so much more. It's a solution for all of our endpoints. We have 250 users spread out over the southeast US and they all connect back to corporate for onsite ERP.
Most of our workforce is remote in offices or homes in Georgia, Alabama, Florida, and Tennessee. We also have technicians that work in plants with limited or no internet connectivity so when they get to a hotel or other public internet hotspots. The auto-connect to VPN is critical to them having a secure connection to our corporate network.
How has it helped my organization?
The solution has provided enhanced security on all endpoints for URL filtering, VPN, media encryption, and scanning. One of the most common responses from our clients is that they love the auto-connect of the VPN, yet hate that we scan all USB devices they plugin.
When our technicians are working at a plant with no internet and they go to a public hot spot, the VPN auto-connecting to corporate secures their data back to corporate without them having to do anything.
The scanning of ransomware has stopped dozens of attempts from malicious websites.
What is most valuable?
The anti-ransomware blade is great. It stops device encryption automatically and has caught hundreds of cases on client laptops.
One of the coolest features is that it provides an HTML report on the laptop and the endpoint console for the administrator. It will show you the forensic report of where it came from and if it spread to other systems that have the endpoint client installed.
The best thing is it never gets past the first client as it looks for bad behavior. If needed, you can open the console and allow it.
What needs improvement?
The product updates are a manual process for my administrator and can take several hours out of his day. I understand this is partially due to the Windows version limitations. When you do need to update the client version it is pretty easy. Usually, it's a case of the end-user not being online to accept the push of the software. That is where it can take up a few hours of my administrator's time. The administrator has to wait and email for our technicians to go to an internet available area. It is usually not a big deal, however, it can take time.
For how long have I used the solution?
I've been using the solution for five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Support Manager at Sefisa
Stable with great centralization and continuous innovation
Pros and Cons
- "They have a great knowledge base that you can leverage as a user."
- "The only thing that our customers want, is lower prices."
What is our primary use case?
We use the solution for many things. We don't only use it as an Endpoint client for antivirus. It is used for our next-generation antivirus. We are also using Harmony on other things, for example, our email. There's a Harmony email and office solution, which we also are using in order to protect our email.
What is most valuable?
The fact that everything is centralized is great. For example, the management is centralized on one portal in the cloud.
We like the fact that we have a lot of visibility with this solution and the protection is very good. I have seen cases where customers, get attacked by ransomware and it is very easy for Check Point to restore a file that has been compromised with ransomware. It's 100% effective.
They are developing new technologies. For example, they added SASE to their portfolio with Harmony. They also have Infinity SOC. If one of the Harmony Endpoints gets compromised, Check Point Infinity SOC is going to see it, and it's going to highlight that.
They're on the very edge of technology and are very fast with implementing new technologies.
The solution is very stable.
They have a great knowledge base that you can leverage as a user.
The product scales well.
Technical support is knowledgeable and responsive.
Every now and then, every vendor does have a vulnerability that is discovered. For example, when many vendors were using open SSL, they had to do some fixes on their software in order to fix that particular vulnerability. Check Point was the first one to fix that. It's clear that, unlike the competition, it is always keeping up with the patching of its own software.
What needs improvement?
We'd like it if the solution continued to add new features. For example, what would be specifically useful to us is a feature that allows threat hunting. They may be already working on that or have something available, however, we need something robust and effective.
I'm not sure if they need to improve anything right now. They are already developing new aspects that are quite innovative.
The only thing that our customers want, is lower prices.
For how long have I used the solution?
I've been using Check Point for 18 years.
What do I think about the stability of the solution?
The product is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We have found the solution to be very easy to scale. If you need to expand it you can do so.
How are customer service and support?
They have good technical support. They have very knowledgeable people, depending on the solution. Some specialize in Harmony Endpoint. It's very good.
How was the initial setup?
The initial setup is very easy. The management is on the cloud, and therefore, you practically don't have to do any installation. You only log in and then you begin to use it and you begin to deploy on your network, the endpoints. The time it takes to deploy depends on the size of endpoints you have. With a small network, such as 100 endpoints, you can do it in one day or a couple of hours.
What's my experience with pricing, setup cost, and licensing?
But they are a leader in detecting threat, therefore, it's reasonable that they are a little more expensive than some other competitors. However, customers always want to pay a bit less.
What other advice do I have?
We are a reseller.
My advice to new users would be to reconsider installing administration servers on-premise. The cloud solution can do it. It's going to lower the maintenance costs. Also, if you are on-premises, you often need some sort of expert on-side, whether it's a vendor or someone else - especially if you are upgrading. That requires knowledge. In contrast, on the cloud, everything is done for you. They have a high availability network so that when you upgrade the servers can keep up. You can upgrade without downtime if you choose the cloud.
I would rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Check Point Harmony Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
HP Wolf Security
Elastic Security
Trellix Endpoint Security Platform
Symantec Endpoint Security
Kaspersky Endpoint Security for Business
Trend Vision One Endpoint Security
Huntress Managed EDR
Buyer's Guide
Download our free Check Point Harmony Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is Check Point's software compatible with other products?
- What is the pricing for Check Point software?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Which ransomware is the biggest threat in 2020?