Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jorgeluiznim
Advisor

[EN] Harmony Email & Collaboration: An Overview

Scope note: Harmony Email & Collaboration (also called Email Security) is a cloud service managed from the Check Point Infinity Portal. This overview is written from the official Email Security Administration Guide.

Purpose

Most email security still sits in front of the mailbox as a gateway, which means it only sees what crosses the perimeter and nothing that happens inside the SaaS suite. Harmony Email & Collaboration takes a different approach: it connects to Microsoft 365, Google Workspace, Teams, Slack and the main file-sharing apps through their APIs, so it inspects internal traffic, files at rest, and user behavior, not just mail on the way in. This article explains what it protects, how it works, and the protection modes you move through when you deploy it.

Audience

  • [x] Security Engineers
  • [x] Email / Collaboration Administrators
  • [x] SOC Analysts
  • [ ] Beginners

What It Is

Check Point's Email Security (Harmony Email & Collaboration) is an API-based inline protection service that protects SaaS applications from advanced threats:

  • Zero-day threats and malware
  • Phishing
  • Account Takeover (BEC / compromised accounts)
  • Data leakage (DLP)
  • SaaS Shadow IT discovery

Because it integrates through the SaaS APIs rather than sitting only at the mail gateway, it inspects incoming, internal and outgoing traffic, and it can remove or modify a message even after delivery.


How It Works

When an email is sent, Email Security intercepts it and sends it to Check Point's ThreatCloud for analysis before the email reaches the recipient. If the verdict is malicious, the email is handled according to the configured workflow (for example, quarantine). Otherwise it is delivered. The same inspection applies to internal and outgoing mail, for both data leakage and phishing/malware, and messages can be removed or modified post-delivery when needed.

diag1-how-it-works.png

 


What It Protects

The service covers four layers of a modern collaboration suite:

Layer What is inspected Supported apps (per the guide)
Email Every message for malware, phishing and DLP, incoming, internal and outgoing; post-delivery removal/modification Microsoft 365, Gmail
File Sharing Every uploaded file for malware and against the DLP policy; threats are quarantined or vaulted OneDrive, SharePoint, Google Drive, Citrix ShareFile, Dropbox, Box
Messaging Every message for malware, DLP and phishing; every uploaded file for malware and DLP Microsoft Teams, Slack
Account Takeover (BEC) User behavior inside the environment (login and correspondence patterns) to detect a compromised account before damage is done; the account is blocked automatically or by an admin Microsoft 365

Protection Modes

You do not flip the whole suite to blocking on day one. Email Security is designed to move through modes:

Mode When it acts How it connects User impact
Monitor only After delivery, visibility only API; surfaces events, including incidents that already happened on the platform None. This is the default when you connect an app
Detect and Remediate Post-delivery API, using a Journal rule (Microsoft 365) so a copy of scoped mail is inspected; malicious mail is quarantined or modified after delivery Minimal, remediation happens behind the scenes
Prevent (Inline) / Protect (Inline) Before delivery Mail Flow rules (Transport rules) and Connectors, so the email is scanned and remediated before it reaches the mailbox Highest protection, mail is held for inspection first

diag2-protection-modes.png

 

The practical path: connect the app (it starts in Monitor only so you immediately see value with zero risk), tune the Threat Detection Policy against what you observe, then move the scope you trust to Detect and Remediate or Prevent (Inline).


Onboarding in Short

  • You connect each SaaS application through its API (an OAuth authorization; for Microsoft 365 this grants scopes such as read/write mail used for post-delivery remediation and for baselining communication patterns in Learning Mode).
  • The application activates in Monitor only with no change to the end-user experience.
  • When you move to inline protection, Email Security provisions the required Mail Flow rules, Connectors, Journal rules and groups on the tenant automatically.

Reporting and SIEM

Security events appear on the Overview page in the Check Point Portal, and Email Security can forward events to a SIEM (Splunk, Sentinel, Chronicle, S3/SQS, CrowdStrike, HTTP/TCP, and more), over HTTPS from a static regional IP. That integration is a topic on its own; the key point for an overview is that the platform is built to feed a SOC, not just quarantine mail.


Best Practices

Best Practice: start every app in Monitor only and let it baseline. The historical events it surfaces are the easiest way to prove value to stakeholders before you enforce anything.

Best Practice: move to enforcement per scope, not all at once. Promote trusted groups to Detect and Remediate or Prevent (Inline) after you have tuned the policy.

Best Practice: protect the whole suite, not just email. File sharing and messaging (Teams, Slack) are common blind spots that a gateway never sees.


Common Mistakes

Mistake Impact Solution
Treating it like a gateway (email only) File sharing, messaging and internal mail stay unprotected Connect all relevant SaaS apps, not just mail
Jumping straight to Prevent (Inline) Risk of disruption before the policy is tuned Start in Monitor only, then promote per scope
Ignoring Account Takeover Compromised accounts act from inside, past mail filtering Enable and review the BEC/ATO detections
Forgetting the SIEM feed Events stay siloed in the portal Forward events to your SIEM for correlation

FAQ

Q: Is it a gateway (MTA) or API-based? A: It is an API-based inline service. It integrates with the SaaS APIs, which is what lets it inspect internal and outgoing traffic and remediate post-delivery. It can also enforce inline (before delivery) using Mail Flow rules and connectors.

Q: Does connecting an app change the user experience immediately? A: No. Apps start in Monitor only, with no change for end users, until you move to an enforcing mode.

Q: What does it protect besides email? A: File sharing (OneDrive, SharePoint, Google Drive, ShareFile, Dropbox, Box), messaging (Teams, Slack), and Account Takeover on Microsoft 365.

Q: Where do the verdicts come from? A: Emails and files are sent to Check Point ThreatCloud for analysis, and the result drives the configured workflow.


References

  • Check Point Email Security (Harmony Email & Collaboration) Administration Guide, Introduction to Email Security (overview, how it works, supported applications)
  • Check Point Email Security Administration Guide, Getting Started (Monitor only, Detect and Remediate, Prevent (Inline), Journal rules, connectors, Mail Flow rules)
  • Check Point Email Security Administration Guide, Managing Security Events > SIEM / SOAR Integration

Revision History

Date Version Author Changes
2026-09-21 1.0 Jorge Luiz Initial version. Overview of Harmony Email & Collaboration based on the official Email Security Administration Guide

Supported Versions: Harmony Email & Collaboration (cloud service, Check Point Infinity Portal) Last Updated: 2026-09-21

 
1 Reply
Marquevis
Contributor

Good work brow!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events