<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp in SaaS Security</title>
    <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279592#M19</link>
    <description>&lt;P&gt;Yeah, this is the only way I found on mobile; I found it quite complicated when thinking about a more granular view.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2026 18:30:40 GMT</pubDate>
    <dc:creator>WiliRGasparetto</dc:creator>
    <dc:date>2026-07-13T18:30:40Z</dc:date>
    <item>
      <title>Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endpoint</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279560#M15</link>
      <description>&lt;H2&gt;&lt;FONT color="#FF99CC"&gt;Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endpoint Controls&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;One of the most overlooked capabilities in Harmony Mobile is granular application control. At first glance, blocking &amp;nbsp;Facebook may seem equivalent to blocking the Social Media category on a firewall.&lt;/P&gt;
&lt;P&gt;It is not. In reality, Harmony Mobile operates at a completely different level of security posture and enforcement.&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&lt;FONT color="#FF99CC"&gt;Traditional Category-Based Blocking&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Most organizations are familiar with category-based controls.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_0-1783951630421.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34683i2A6953FA1C06B32F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_0-1783951630421.png" alt="WiliRGasparetto_0-1783951630421.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall identifies the application or URL category and decides whether to allow or deny the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_1-1783951630478.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34685iC079EBB3894036E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_1-1783951630478.png" alt="WiliRGasparetto_1-1783951630478.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This model is extremely valuable, but it focuses primarily on network traffic.&lt;/P&gt;
&lt;P&gt;It does not evaluate whether a specific mobile application installed on the device should itself become a security indicator.&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;Harmony Mobile Starts with the Application Itself&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Harmony Mobile introduces a different concept.&lt;/P&gt;
&lt;P&gt;Instead of asking:&lt;/P&gt;
&lt;P&gt;&amp;gt; Should I block the Social Media category?&lt;/P&gt;
&lt;P&gt;It asks:&lt;/P&gt;
&lt;P&gt;&amp;gt; Should this specific application be trusted on a corporate device?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This subtle difference changes the entire security model.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Administrators can create an Application Exception, identify a specific package (Android) or Bundle ID (iOS), and assign it a custom risk level.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_2-1783951630480.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34684i6C35C3E8CC90250A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_2-1783951630480.png" alt="WiliRGasparetto_2-1783951630480.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_3-1783951630480.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34687i3AEB7D8402E67F63/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_3-1783951630480.png" alt="WiliRGasparetto_3-1783951630480.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_4-1783951630481.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34686iBADFDB0A9A230464/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_4-1783951630481.png" alt="WiliRGasparetto_4-1783951630481.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_5-1783951630482.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34688iE5CBD813DA51C1CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_5-1783951630482.png" alt="WiliRGasparetto_5-1783951630482.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This decision is no longer simply a traffic policy.&lt;/P&gt;
&lt;P&gt;It becomes part of the device security posture.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;Risk Classification Instead of Simple Blocking&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Once an application is classified as High Risk, Harmony Mobile can:&lt;/P&gt;
&lt;P&gt;* notify the user;&lt;/P&gt;
&lt;P&gt;* recommend uninstalling the application;&lt;/P&gt;
&lt;P&gt;* generate security events;&lt;/P&gt;
&lt;P&gt;* increase the device risk score;&lt;/P&gt;
&lt;P&gt;* trigger Conditional Access decisions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The workflow becomes:&lt;/P&gt;
&lt;P&gt;Application Installed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ↓&lt;/P&gt;
&lt;P&gt;Application classified as High Risk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ↓&lt;/P&gt;
&lt;P&gt;Device Risk increases&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ↓&lt;/P&gt;
&lt;P&gt;Conditional Access evaluates the device&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ↓&lt;/P&gt;
&lt;P&gt;Corporate access may be restricted&lt;/P&gt;
&lt;P&gt;This is fundamentally different from simply denying HTTP sessions at the perimeter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;&lt;EM&gt;Blocking Application Traffic&lt;/EM&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;When On-Device Network Protection (ONP) is enabled, Harmony Mobile can also prevent the application from communicating with the Internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_6-1783951630556.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34689iAC02F755CC5CCB3B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_6-1783951630556.png" alt="WiliRGasparetto_6-1783951630556.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The application may remain installed, but its network communication is blocked directly on the device.&lt;/P&gt;
&lt;P&gt;However, there is an important limitation.&lt;/P&gt;
&lt;P&gt;The user may still access the same service through a web browser.&lt;/P&gt;
&lt;P&gt;That leads to the second protection method.&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;Blocking Both the Application and the Browser&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Harmony Mobile can also block the application's infrastructure itself.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_7-1783951630617.png" style="width: 578px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34690i9B2EC3FA317DD00C/image-dimensions/578x315?v=v2" width="578" height="315" role="button" title="WiliRGasparetto_7-1783951630617.png" alt="WiliRGasparetto_7-1783951630617.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Administrators import the domains, URLs and IP addresses used by the application.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#FF99CC"&gt;Now the protection flow becomes:&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WiliRGasparetto_8-1783951630679.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34691i1E512E6F53C1F5FD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WiliRGasparetto_8-1783951630679.png" alt="WiliRGasparetto_8-1783951630679.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This approach protects both Android and iOS devices and blocks access regardless of whether users launch the native application or a web browser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Conditional Access Changes the Conversation&lt;/P&gt;
&lt;P&gt;The real value appears when this capability is integrated with &amp;nbsp;Conditional Access.&lt;/P&gt;
&lt;P&gt;Instead of only blocking TikTok, organizations can say:&lt;/P&gt;
&lt;P&gt;If TikTok is installed,&lt;/P&gt;
&lt;P&gt;this device is now High Risk,&lt;/P&gt;
&lt;P&gt;therefore it cannot access:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Corporate VPN&lt;/LI&gt;
&lt;LI&gt;SaaS applications&lt;/LI&gt;
&lt;LI&gt;Internal portals&lt;/LI&gt;
&lt;LI&gt;Administrative interfaces&lt;/LI&gt;
&lt;LI&gt;Identity providers&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The security decision moves from:&lt;/P&gt;
&lt;P&gt;&amp;gt; Block the application.&lt;/P&gt;
&lt;P&gt;to&lt;/P&gt;
&lt;P&gt;&amp;gt; Restrict corporate access because the device no longer meets the organization's security posture.&lt;/P&gt;
&lt;P&gt;This is a much more mature Zero Trust approach.&lt;/P&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;Granular Blocking vs Category Blocking&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Blocking the Social Media&amp;nbsp;category often creates unnecessary business impact.&lt;/P&gt;
&lt;P&gt;Many organizations legitimately use:&lt;/P&gt;
&lt;P&gt;* LinkedIn&lt;/P&gt;
&lt;P&gt;* Microsoft Communities&lt;/P&gt;
&lt;P&gt;* YouTube&lt;/P&gt;
&lt;P&gt;* X&lt;/P&gt;
&lt;P&gt;* Facebook Business&lt;/P&gt;
&lt;P&gt;* Marketing platforms&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;A category-based policy may block all of them.&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Granular application control allows administrators to block only the specific application that represents unacceptable risk.&lt;/P&gt;
&lt;P&gt;Social Media Category&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ↓&lt;/P&gt;
&lt;P&gt;Allowed:&lt;/P&gt;
&lt;P&gt;LinkedIn&lt;/P&gt;
&lt;P&gt;YouTube&lt;/P&gt;
&lt;P&gt;X&lt;/P&gt;
&lt;P&gt;Blocked:&lt;/P&gt;
&lt;P&gt;TikTok&lt;/P&gt;
&lt;P&gt;This significantly reduces false positives while improving security precision.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;How This Differs from Firewall and Endpoint Security&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each technology operates at a different layer.&lt;/P&gt;
&lt;P&gt;Firewall&lt;/P&gt;
&lt;P&gt;* Controls network sessions.&lt;/P&gt;
&lt;P&gt;* Identifies applications crossing the gateway.&lt;/P&gt;
&lt;P&gt;* Applies Application Control and URL Filtering.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Harmony Endpoint&lt;/P&gt;
&lt;P&gt;* Protects Windows and macOS endpoints.&lt;/P&gt;
&lt;P&gt;* Focuses on malware prevention, EDR, anti-ransomware and host protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Harmony Mobile&lt;/P&gt;
&lt;P&gt;* Evaluates the installed mobile application itself.&lt;/P&gt;
&lt;P&gt;* Assigns application risk.&lt;/P&gt;
&lt;P&gt;* Protects network traffic directly on the device.&lt;/P&gt;
&lt;P&gt;* Integrates application risk with Conditional Access.&lt;/P&gt;
&lt;P&gt;* Maintains visibility even when devices are outside the corporate network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This makes Harmony Mobile especially valuable for:&lt;/P&gt;
&lt;P&gt;* BYOD environments;&lt;/P&gt;
&lt;P&gt;* remote workers;&lt;/P&gt;
&lt;P&gt;* mobile users on public Wi-Fi;&lt;/P&gt;
&lt;P&gt;* devices connected through cellular networks;&lt;/P&gt;
&lt;P&gt;* Zero Trust access models.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT size="5" color="#FF99CC"&gt;Final Thoughts&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;The real innovation is not simply blocking an application.&lt;/P&gt;
&lt;P&gt;It is transforming a specific application into a security signal that influences device trust and corporate access decisions.&lt;/P&gt;
&lt;P&gt;Instead of asking:&lt;/P&gt;
&lt;P&gt;&amp;gt; Should we block Social Media?&lt;/P&gt;
&lt;P&gt;Organizations can now ask:&lt;/P&gt;
&lt;P&gt;&amp;gt; Should this specific application be allowed to coexist with corporate identities, sensitive data and privileged access?&lt;/P&gt;
&lt;P&gt;That is a far more mature approach to mobile security.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2026 01:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279560#M15</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-07-15T01:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279584#M16</link>
      <description>&lt;P&gt;Endpoint does offer Application Control, FYI (as in restricting which apps can run).&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 16:05:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279584#M16</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-07-13T16:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279590#M17</link>
      <description>&lt;P&gt;Is there another way besides the one where you enter the application ID? Because if there is, let me know I don't know it, hehe.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 18:14:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279590#M17</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-07-13T18:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279591#M18</link>
      <description>&lt;P&gt;I'm not as familiar with the specifics of how Application Control on Endpoint is configured.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 18:28:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279591#M18</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-07-13T18:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279592#M19</link>
      <description>&lt;P&gt;Yeah, this is the only way I found on mobile; I found it quite complicated when thinking about a more granular view.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 18:30:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279592#M19</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-07-13T18:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279596#M20</link>
      <description>&lt;P&gt;which I just tested with my friend&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85528"&gt;@jorgeluiznim&lt;/a&gt;&amp;nbsp; in production using ID.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bloqueio.png" style="width: 930px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34693i1CF82AC4D2CFABD6/image-size/large?v=v2&amp;amp;px=999" role="button" title="bloqueio.png" alt="bloqueio.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Even though it was specific, it blocked all productivity apps.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bloqueios app.png" style="width: 307px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34694i84BA25397CB966CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="bloqueios app.png" alt="bloqueios app.png" /&gt;&lt;/span&gt;&lt;BR /&gt;This makes it very complicated to create more granular rules, since the category is "productivity"; creating the necessary exceptions to this block would require an enormous amount of effort.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="categoria.png" style="width: 637px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34695i0895882B8DFC4702/image-size/large?v=v2&amp;amp;px=999" role="button" title="categoria.png" alt="categoria.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 12:12:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279596#M20</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-07-14T12:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279603#M21</link>
      <description>&lt;P&gt;Great write-up,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96099"&gt;@WiliRGasparetto&lt;/a&gt;&amp;nbsp; and thanks for the mention &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; Since I was the "Jorge" testing this in production, let me add what we hit and how I've come to think about the granularity gap.&lt;/P&gt;&lt;P&gt;The three layers people mix up&lt;BR /&gt;When someone says "block an app" in Harmony Mobile, they're usually touching one of three different things under Policy → Application, and only one is truly per-app:&lt;/P&gt;&lt;P&gt;Application Categories – risk/traffic block by store category (Social, Productivity…). Category-wide by design.&lt;BR /&gt;Application Exceptions – the only per-app control: pin a specific Package Name (Android) / Bundle ID (iOS) and override its risk level (High / No Risk / Ask for user approval).&lt;BR /&gt;Block Application Traffic – the actual enforcement switch, but it works by risk level ("block everything at High or above"), not per app.&lt;BR /&gt;So "granular blocking" is really a combo: Exceptions to make one app High, then Block Application Traffic at High so only that app is caught. On paper, surgical.&lt;/P&gt;&lt;P&gt;What actually happened in my test&lt;BR /&gt;In practice, the moment the goal was a real hard-block, the enforcement landed on the whole Productivity category — exactly the pain you described. Once you want an actual block instead of just a risk signal, you're pushed back toward category/risk-level logic, and carving out exceptions for everything else in "Productivity" is a huge amount of work for one blocked app.&lt;/P&gt;&lt;P&gt;The platform caveat that bites hardest (iOS)&lt;BR /&gt;The part I'd flag loudest: per-app traffic enforcement is documented as Android-only (ONP in Full Inspection). On iOS, pinning an app to High via Exceptions raises device risk and alerts the user — it doesn't stop the app by itself. To turn that signal into a real block you need Conditional Access and/or a UEM. So on a standalone iPhone, "block this one app" isn't really a thing yet — the device-risk → Conditional Access path you described is the correct mental model, not app termination.&lt;/P&gt;&lt;P&gt;Where I think it needs to go (and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; point)&lt;BR /&gt;PhoneBoy's spot-on that Endpoint's Application Control restricts which apps can run — that's exactly the parity mobile is missing. Harmony Mobile already solved the hard part: it inventories installed apps with package/Bundle ID, version, hash and behavior, and it already keeps a per-app exceptions list. The distance between "I can see and score this app" and "block this app in one click" feels small, at least on Android.&lt;/P&gt;&lt;P&gt;Community wishlist to +1:&lt;/P&gt;&lt;P&gt;A one-click Block Application action from Forensics → Applications that wires up the exception + traffic block for you.&lt;BR /&gt;A real Allow/Deny list per app (the Endpoint Application Control model, on mobile).&lt;BR /&gt;A UI hint when you add an iOS app to Exceptions: "on iOS this generates risk/alert; effective blocking needs Conditional Access/UEM" — so nobody thinks they blocked something they didn't.&lt;BR /&gt;The real value, as you said, isn't the block itself — it's turning a specific app into a trust signal. I just think we're one UX layer away from that being genuinely granular on the enforcement side too.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 21:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279603#M21</guid>
      <dc:creator>jorgeluiznim</dc:creator>
      <dc:date>2026-07-13T21:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279646#M22</link>
      <description>&lt;P&gt;Excellent points raised, Jorge as always, you’re elevating the discussion to a higher level.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 12:14:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279646#M22</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-07-14T12:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Mobile: Why Granular Application Blocking Is Different from Traditional Firewall or Endp</title>
      <link>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279682#M23</link>
      <description>&lt;P&gt;I was referring to your explanation of Endpoint above, not specifically how it's done on Mobile&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 15:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SaaS-Security/Harmony-Mobile-Why-Granular-Application-Blocking-Is-Different/m-p/279682#M23</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-07-14T15:19:50Z</dc:date>
    </item>
  </channel>
</rss>

