Scope note: Harmony Email & Collaboration (also called Email Security) is a cloud service managed from the Check Point Infinity Portal. This overview is written from the official Email Security Administration Guide.
Purpose
Most email security still sits in front of the mailbox as a gateway, which means it only sees what crosses the perimeter and nothing that happens inside the SaaS suite. Harmony Email & Collaboration takes a different approach: it connects to Microsoft 365, Google Workspace, Teams, Slack and the main file-sharing apps through their APIs, so it inspects internal traffic, files at rest, and user behavior, not just mail on the way in. This article explains what it protects, how it works, and the protection modes you move through when you deploy it.
Audience
- [x] Security Engineers
- [x] Email / Collaboration Administrators
- [x] SOC Analysts
- [ ] Beginners
What It Is
Check Point's Email Security (Harmony Email & Collaboration) is an API-based inline protection service that protects SaaS applications from advanced threats:
- Zero-day threats and malware
- Phishing
- Account Takeover (BEC / compromised accounts)
- Data leakage (DLP)
- SaaS Shadow IT discovery
Because it integrates through the SaaS APIs rather than sitting only at the mail gateway, it inspects incoming, internal and outgoing traffic, and it can remove or modify a message even after delivery.
How It Works
When an email is sent, Email Security intercepts it and sends it to Check Point's ThreatCloud for analysis before the email reaches the recipient. If the verdict is malicious, the email is handled according to the configured workflow (for example, quarantine). Otherwise it is delivered. The same inspection applies to internal and outgoing mail, for both data leakage and phishing/malware, and messages can be removed or modified post-delivery when needed.

What It Protects
The service covers four layers of a modern collaboration suite:
| Layer |
What is inspected |
Supported apps (per the guide) |
| Email |
Every message for malware, phishing and DLP, incoming, internal and outgoing; post-delivery removal/modification |
Microsoft 365, Gmail |
| File Sharing |
Every uploaded file for malware and against the DLP policy; threats are quarantined or vaulted |
OneDrive, SharePoint, Google Drive, Citrix ShareFile, Dropbox, Box |
| Messaging |
Every message for malware, DLP and phishing; every uploaded file for malware and DLP |
Microsoft Teams, Slack |
| Account Takeover (BEC) |
User behavior inside the environment (login and correspondence patterns) to detect a compromised account before damage is done; the account is blocked automatically or by an admin |
Microsoft 365 |
Protection Modes
You do not flip the whole suite to blocking on day one. Email Security is designed to move through modes:
| Mode |
When it acts |
How it connects |
User impact |
| Monitor only |
After delivery, visibility only |
API; surfaces events, including incidents that already happened on the platform |
None. This is the default when you connect an app |
| Detect and Remediate |
Post-delivery |
API, using a Journal rule (Microsoft 365) so a copy of scoped mail is inspected; malicious mail is quarantined or modified after delivery |
Minimal, remediation happens behind the scenes |
| Prevent (Inline) / Protect (Inline) |
Before delivery |
Mail Flow rules (Transport rules) and Connectors, so the email is scanned and remediated before it reaches the mailbox |
Highest protection, mail is held for inspection first |

The practical path: connect the app (it starts in Monitor only so you immediately see value with zero risk), tune the Threat Detection Policy against what you observe, then move the scope you trust to Detect and Remediate or Prevent (Inline).
Onboarding in Short
- You connect each SaaS application through its API (an OAuth authorization; for Microsoft 365 this grants scopes such as read/write mail used for post-delivery remediation and for baselining communication patterns in Learning Mode).
- The application activates in Monitor only with no change to the end-user experience.
- When you move to inline protection, Email Security provisions the required Mail Flow rules, Connectors, Journal rules and groups on the tenant automatically.
Reporting and SIEM
Security events appear on the Overview page in the Check Point Portal, and Email Security can forward events to a SIEM (Splunk, Sentinel, Chronicle, S3/SQS, CrowdStrike, HTTP/TCP, and more), over HTTPS from a static regional IP. That integration is a topic on its own; the key point for an overview is that the platform is built to feed a SOC, not just quarantine mail.
Best Practices
Best Practice: start every app in Monitor only and let it baseline. The historical events it surfaces are the easiest way to prove value to stakeholders before you enforce anything.
Best Practice: move to enforcement per scope, not all at once. Promote trusted groups to Detect and Remediate or Prevent (Inline) after you have tuned the policy.
Best Practice: protect the whole suite, not just email. File sharing and messaging (Teams, Slack) are common blind spots that a gateway never sees.
Common Mistakes
| Mistake |
Impact |
Solution |
| Treating it like a gateway (email only) |
File sharing, messaging and internal mail stay unprotected |
Connect all relevant SaaS apps, not just mail |
| Jumping straight to Prevent (Inline) |
Risk of disruption before the policy is tuned |
Start in Monitor only, then promote per scope |
| Ignoring Account Takeover |
Compromised accounts act from inside, past mail filtering |
Enable and review the BEC/ATO detections |
| Forgetting the SIEM feed |
Events stay siloed in the portal |
Forward events to your SIEM for correlation |
FAQ
Q: Is it a gateway (MTA) or API-based? A: It is an API-based inline service. It integrates with the SaaS APIs, which is what lets it inspect internal and outgoing traffic and remediate post-delivery. It can also enforce inline (before delivery) using Mail Flow rules and connectors.
Q: Does connecting an app change the user experience immediately? A: No. Apps start in Monitor only, with no change for end users, until you move to an enforcing mode.
Q: What does it protect besides email? A: File sharing (OneDrive, SharePoint, Google Drive, ShareFile, Dropbox, Box), messaging (Teams, Slack), and Account Takeover on Microsoft 365.
Q: Where do the verdicts come from? A: Emails and files are sent to Check Point ThreatCloud for analysis, and the result drives the configured workflow.
References
- Check Point Email Security (Harmony Email & Collaboration) Administration Guide, Introduction to Email Security (overview, how it works, supported applications)
- Check Point Email Security Administration Guide, Getting Started (Monitor only, Detect and Remediate, Prevent (Inline), Journal rules, connectors, Mail Flow rules)
- Check Point Email Security Administration Guide, Managing Security Events > SIEM / SOAR Integration
Revision History
| Date |
Version |
Author |
Changes |
| 2026-09-21 |
1.0 |
Jorge Luiz |
Initial version. Overview of Harmony Email & Collaboration based on the official Email Security Administration Guide |
Supported Versions: Harmony Email & Collaboration (cloud service, Check Point Infinity Portal) Last Updated: 2026-09-21