The Check Point SASE team has introduced some important upgrades in recent weeks to improve your SASE management and user experience. Some of the highlights include new additions to the SASE console, a consolidated API, and general availability for key security features.

Early Availability

Browser Security and Workforce AI Security integration
The Check Point SASE console now includes controls for Browser Security and Workforce AI Security. This adds Zero Phishing protection, Password Reuse Protection, Browser Safe Search.

We’ve also added the ability to manage DLP policies for prompts sent to native AI applications such as Claude, ChatGPT, and Copilot. This makes it easier for SASE clients to manage their DLP settings from a single console.

Role Sync and Multiple Roles
Administrators can now assign multiple roles to a single member, with roles kept in sync automatically against the member’s role assignments in the Check Point management portal. This unifies the SASE role model with centrally managed identity rather than maintaining SASE-only legacy roles. First introduced in Early Availability in May 2026; generally available in Canada, Australia, and India on 8 July 2026, with further regions to follow.

New Features

SASE Public API v3.0.0
The SASE Public API is now consolidated into a single specification and expanded with new coverage: Internet Access policy management (SWG and HTTPS Inspection rules), Web Category and Application Control catalogs with the Updatable Objects feed, Private DNS configuration, Split Tunneling configuration, account-level support settings, and a per-rule firewall logging flag. Check out API v3.0 on Swaggerhub.

Milan 2 region
A second point of presence (PoP) in Milan is now available, offering both Standard and Enhanced Network options. See the full list of PoPs.

Threat Prevention Security Profiles
Now generally available to all tenants—having been introduced in Early Availability in December 2025—this release gives administrators:

Control over which protection blades apply per policy

A Threat Prevention file-scanning limit raised to 100 MB for all tenants, up from 10 MB

Full-scan logging for Threat Emulation, recording every file the engine evaluates

Minimum Agent version: 12.9. For more information, see Threat Prevention Security Profiles.

File Access Policy — general availability
File Access Policy, which lets administrators control file downloads by source, destination, and file type, is now generally available to all tenants.

Minimum Agent version: 12.9.

What’s Next

We’ll have new posts to share soon highlighting some new and exciting changes to Check Point SASE. Be sure to subscribe to our Product Updates blog to keep up to date with the latest changes, or read our Release Notes.

 

 

 

 

 

 

You may also like