- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
While this may seem like a bit of a rant, I actually want to raise awareness, get feedback from Check Point product owners, and start a discussion about what I believe is a massive security risk inside the Harmony Email & Collab product, otherwise known as Avanan.
Disclaimer: I tried to talk to Check Point directly before I decided to write this post, but received no feedback whatsoever.
The Problems:
The way the product integrates into Google Workspace is not at all based on Google Workspace APIs. The "integration" simply re-routes all emails through a Check Point owned MTA, where emails are evaluated for risks, and then routed back to Google Workspace. It's all simple SMTP MTA routing.
That in of itself is not really an issue, apart from the fact that the marketing is misleading.
The problem lies in how this is achieved:
Why do they do this? Because their "integration" is not an integration. They use the root user to log in to your Google Workspace admin console and change a bunch of settings to accomplish the re-routing of emails (technically, MTA hosts are added, routes are added, and compliance rules are added). This is, of course, automated, but the fact that a root user with disabled 2FA* has to be handed over to Check Point is a massive red flag. I am not even touching on the point that this requires an additional Google Workspace license, as that is just the icing on the cake.
Google offers a vast array of APIs for Google Workspace, and Gmail, in particular, offers proper authentication with OAUTH, etc, yet here we are.
I tried to address this issue all the way back when Check Point acquired Avanan, and I tried to address this multiple times after. This wasn't even acknowledged nor did I ever get a meaningful response - despite being a Check Point partner.
I would like to understand why Check Point is not addressing this gaping security hole, and I would also like to see some commitment to changing this in the future and enhancing the product with proper API-based integration into Google Workspace.
*Note: Upon checking the most recent version of the documentation, it is no longer mentioned that 2FA has to be disabled. It looks like Check Point is enabling 2FA for that account, but the documentation is not really clear about this.
Hi Sascha, thanks for your feedback. Following the internal discussion, I have received a reply from Gil Friedrich, VP Email Security, stating the following, quoting in full:
Finally, we will make sure the documentation is updated the documentation with the above points and the new documentation is available from here
I hope this answers your concerns. If not, please let me know again.
Hi Sascha,
Finally, you mentioned that you tried to reach out to Check Point to raise your concerns. Who did you speak to? I can hardly believe nobody got back to you on this. I will make sure someone talks to you to address your concerns. It may take a bit of time, as today is the weekend in Israel already.
I would like to make up my mind about MFA, but as I mentioned, it's not clearly addressed in the documentation. In earlier versions, customers were specifically asked to disable MFA for the account. In the current version, it asks to "allow the account to enable 2FA" - what that means is not clear. Does Check Point actually enable 2FA for that account?
I am afraid to ask, did you check it during a trial? For me it seems, the documentation says, 2FA can be enabled. Is this all purely theoretical, or do you have a specific project in mind? Please let me know offline, this will help to get you a meaningful answer.
You already have my email.
When I trialed it last, which was some time ago, I was asked to disable 2FA. As mentioned above, I have inquired about this through distributors and with Avanan staff directly in the past and was told that's just the way it is. If it has changed since, I appreciate that, but it's just one point of many in my criticism.
The core of the issue is that Check Point needs a plain-text-password root account in customers' Google Workspace tenants — a root account with maximum privileges for everything in it.
Hi Sascha, thanks for your feedback. Following the internal discussion, I have received a reply from Gil Friedrich, VP Email Security, stating the following, quoting in full:
Finally, we will make sure the documentation is updated the documentation with the above points and the new documentation is available from here
I hope this answers your concerns. If not, please let me know again.
Thanks Val, I appreciate the feedback, updated docs and improvements!
No problem, we are here to help.
Hi @_Val_,
have these changes been deployed yet? We created a new tenant about three days ago. Neither was the super user automatically disabled after onboarding, nor was 2FA enabled for it:
Thanks
The quote above say "2FA can be enabled for this account. In fact, this is our recommendation to the end-customer" Can does not mean it is defined from the start.
Auto-disabling is also covered: "Thanks for your feedback, we are going to auto-disable the account once the configuration is completed (Coming soon)"
I hope it makes sense. Also, why wouldn't you work with your local CP office? It is much easier to get help for your specific needs this way.
Please let me know if you need any assistance from my end, though
Hey Val, I thought the community forum is a good place to talk about product questions. I can talk to the local CP office instead, if you prefer that.
I missed the "coming soon" part, as I was looking at the documentation, where it doesn't state coming soon. Hence my question.
If we enable MFA on the account manually, how would the account be able to still log in?
Cheers
Hey @cryptochrome, please let me clarify what I mean.
When you want to make a general inquiry about product functionality and see what other experts think about it, yes, the community is a perfect place to do that.
However, if you have a solid project in mind, or you are in a sales cycle, it makes much more sense to work with your local SEs, they can be very helpful when it comes to getting the correct answers from the right people. I assumed it is your case. If this assumption is not correct, you can disregard the recommendation.
On top, any missing feature that you might want to add to the product can be an RFE, and here again, the local office is the correct route.
Your SE and/or TAC should also be more helpful in answering specific technical questions.
I will chaise R&D to see who can answer your new questions. Please allow me some time. There is a national holiday in Israel today, most of ppl are unavailable for an immediate chat.
No worries, it isn't urgent. Thanks!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
1 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY