For sure.
W
We use autopilot-managed devices via MS Intune (EntraID-registered), which are sent to employees. After their first login (via EntraID authentication), applications are deployed through MS Intune.
To deploy the Harmony client in MS Intune, we use the UEM integration provided by Check Point (see the screenshot in my first post). Once the initial client is installed, the deployment policy takes over, though there is currently no option to automatically configure a VPN site.
Using the MSI deployment (suggested by Leasly) isn't feasible, as we would need to update the package every time a new agent version is released. Since an external service provider manages this service, our Security department requires the flexibility to quickly choose which version is deployed. This is why we prefer using the deployment policy.
Everything else is too maintenance-intensive
CCES / CCSA / CCSE