Symantec Endpoint Protection Arm64 Work File

Symantec Endpoint Protection (SEP) provides native support for ARM64 architecture on both Windows and macOS, though there are specific management and feature limitations to note as of early 2026. Windows on ARM64 Support

SEP is compatible with ARM64-based devices running Windows 11 (builds 21H2, 22H2, and later). Broadcom support portal Management Requirements : ARM64 devices cannot be managed by an on-premises Symantec Endpoint Protection Manager (SEPM) . Instead, you must use: Symantec Endpoint Security (SES) Cloud Console

: Full cloud management for ARM64 agents (version 14.3 or later). : Standalone installations are also supported. Feature Limitations

: While most core protections are active, several advanced features are currently unsupported on Windows ARM64: Custom Application Behavior Threat Defense for Active Directory (AD) Web and Cloud Access Protection Exploit Protection Application Control Legacy Browser Protection (for older IE/Firefox versions) Broadcom support portal macOS ARM64 (Apple Silicon) Support

Broadcom provides native support for Apple’s M-series chips through the Symantec Agent for Mac. Broadcom support portal Minimum Supported Version SEP 14.3 RU2 or later SEP 14.3 RU5 or later SEP 14.3 RU8 or later Apple M4 / M5 SEP 14.3 RU9 or later Key Capabilities

: Recent versions for macOS (14.3 RU1+) include behavioral analysis to identify unknown threats and full visibility via the Integrated Cyber Defense Manager (ICDm) cloud console. Deployment Note

: Users must manually authorize the Symantec kernel extension in System Settings > Privacy & Security after installation for the agent to function fully. Broadcom support portal Performance and Known Issues Cloud Management

: For all ARM64 deployments, Broadcom recommends the cloud-only management approach to reduce infrastructure overhead and ensure unified threat visibility across modern hardware. VNC Connectivity

: A known issue exists where screen sharing or VNC connectivity may be lost on macOS 11.4 and 12 (ARM) if Vulnerability Protections are toggled. General Performance

: While older versions of SEP were criticized for high resource usage, recent ARM64 native agents are optimized for the architecture's power efficiency and multi-core performance. Broadcom TechDocs specific hardware requirements

for the cloud-managed agent on your preferred operating system? Known Issues in Symantec Endpoint Security

Symantec Endpoint Protection (SEP) provides native support for Windows ARM64 devices as of version 14.3 RU7, though with specific management and feature restrictions compared to standard x86/x64 systems. Key Requirements for ARM64 Support

Operating System: Supported on Windows 11 GA builds (21H2, 22H2).

Management Console: ARM64 devices cannot be managed via the on-premises Symantec Endpoint Protection Manager (SEPM). You must use either: Symantec Endpoint Security (SES) cloud console. Unmanaged (self-managed) client packages. symantec endpoint protection arm64 work

Prerequisites: Native installation requires specific Microsoft Visual C++ Redistributables (2022 and 2015-2022) for the ARM64 architecture. Supported vs. Unsupported Features

Most standard protection features are functional on ARM64, but several legacy and advanced policies are currently unsupported: Supported Features Unsupported Features (ARM64) Core Anti-malware & Scans Custom Application Behavior Network Threat Protection Threat Defense for Active Directory Device Control Application Control Exploit Protection LiveUpdate (Native Updates) Legacy Browser Protection (IE/Firefox) Implementation Considerations

Deployment: When downloading the client from the SES cloud console, you must explicitly select the Windows ARM architecture to ensure the correct package is generated.

Performance: Native ARM64 support avoids the performance overhead of x86 emulation, ensuring the security agent operates efficiently on Snapdragon-based Windows laptops.

Updates: Devices can be configured for Peer Content Distribution, allowing ARM64 agents to share virus definitions and behavioral rules within the network to save bandwidth.

For detailed technical specs or to download the latest builds, visit the Broadcom TechDocs portal. Known Issues in Symantec Endpoint Security

Symantec Endpoint Protection ARM64 Support and Implementation

Symantec Endpoint Protection (SEP) and Symantec Endpoint Security (SES) have evolved to support the ARM64 architecture

, primarily focusing on Windows on ARM devices (such as the Microsoft Surface Pro X and Surface Pro 9) and Apple silicon (M1, M2, M3, and M4 processors). 1. Core Architecture Support

Broadcom introduced official support for Windows ARM devices starting with Symantec Endpoint Protection 14.3 RU7 Windows on ARM

: Support is available for Windows 11 GA builds (21H2, 22H2, and later) on Qualcomm Snapdragon ARM processors. Apple Silicon

: Support for macOS on ARM (Apple M-series) began earlier, with M1 support in 14.3 RU2 and subsequent updates for M2 (RU5) and M3 (RU8). 2. Management and Deployment Requirements

A critical distinction in ARM64 support is the management infrastructure. No On-Premises SEPM Support 📌 Final advice for IT admins

: The on-premises Symantec Endpoint Protection Manager (SEPM) manage ARM64 devices directly. Management Options Cloud-Managed : Devices must be managed via the Symantec Endpoint Security (SES) cloud console (Integrated Cyber Defense Manager - ICDm).

: You can use "self-managed" or unmanaged installation packages for standalone protection. 3. Feature Availability for Windows ARM

While the ARM64 agent provides core security, some legacy or specialized features are not supported on this architecture. Supported Features Unsupported Features Antimalware & Malware Protection Application Control Behavioral Analysis & Adaptive Protection Custom Application Behavior Firewall & Intrusion Prevention (IPS) Web and Cloud Access Protection Endpoint Detection and Response (EDR) Exploit Protection (Legacy) Host Integrity Threat Defense for Active Directory Memory Exploit Mitigation Granular Device Control (Allow/Deny only) 4. Implementation Steps

To deploy Symantec to an ARM64 environment, follow these requirements: Obtain Correct Package : Download the specific Windows ARM architecture

installer from the SES cloud console or the "Full_Installation" download of SEP for unmanaged use. Environment Check

: Ensure the target device is running a compatible Windows 11 ARM build or a supported macOS version. : If moving from on-premises, use SEP 14.3 RU5 build 8282 or later as the bridge version for migration to the cloud console. or help navigating the SES Cloud Console to generate these ARM64 packages?

Symantec Endpoint Protection and ARM64 Compatibility As ARM64 architecture continues to expand from mobile devices into professional laptops like the Microsoft Surface Pro and Apple’s M-series Macs, enterprise security must adapt. Symantec Endpoint Protection (SEP) now provides specific support for ARM64 across Windows, macOS, and Linux, though management requirements vary by platform. Windows ARM64 Support

Symantec supports Windows 11 on ARM64 processors (such as the Snapdragon X Elite) with specific version and management constraints.

Management Requirements: ARM64 endpoints cannot be managed by an on-premises Symantec Endpoint Protection Manager (SEPM). They must be managed via the Symantec Endpoint Security (SES) Cloud Console or remain unmanaged.

Operating Systems: Support includes Windows 11 GA builds (21H2 through 25H2).

Feature Limitations: While most core protections work, certain advanced features like Custom Application Behavior, Threat Defense for AD, and Exploit Protection are currently unsupported on Windows ARM architecture. Apple Silicon (macOS ARM64)

Symantec has robust support for Apple’s M1, M2, M3, and M4 chips.

Symantec Endpoint Protection (SEP) supports Windows 11 ARM64 devices starting with version 14.3 RU7. While it provides core protection, there are specific management requirements and feature limitations for this architecture. Management Requirements Do not push SEP x64 via management console

Cloud or Unmanaged Only: ARM64 support is restricted to cloud-managed (Symantec Endpoint Security / ICDm) or unmanaged (self-managed) clients.

No On-Premises SEPM: Currently, there is no support for managing ARM64 endpoints via the on-premises Symantec Endpoint Protection Manager (SEPM). Operating System & Platform Support

Windows: Specifically requires Windows 11 (builds 21H2, 22H2, and later).

macOS: Apple Silicon (M1/M2/M3) is supported starting from 14.3 RU3.

Linux: ARM64 support for Linux agents (e.g., Amazon Linux 2023) is planned for the SEP 16 release cycle in 2026. Feature Limitations on ARM64

Most standard security features are functional, but the following are not supported on Windows ARM64 platforms: Application Control and Custom Application Behavior. Exploit Protection. Threat Defense for AD. Web and Cloud Access Protection.

Legacy Browser Protection for older Internet Explorer or Firefox-based engines. Installation Tips

Cloud-Managed: Select the Windows ARM architecture option when downloading the installation package from the SES Cloud console.

Unmanaged: The ARM64 package is included in the Full_Installation download of SEP.

Apple Silicon: Ensure Rosetta 2 is installed before attempting to install the Mac agent if using older versions.

💡 Key Takeaway: If you need to secure ARM64 devices today, you must use the cloud-based management console, as the traditional on-prem manager cannot yet handle these clients. If you'd like, I can help you with: Step-by-step guides for cloud console deployment Detailed lists of supported Windows 11 ARM64 builds Troubleshooting specific installation error codes

Note: As of mid-2026, Broadcom (the owner of Symantec) has a specific, limited support model for ARM64, which differs significantly from x86/x64.


📌 Final advice for IT admins


6. Alternative & Future Outlook

Appropriate Use Cases:

Current status (practical summary)

When to Use SEP on ARM64 (And When to Run Away)