Skip to content

Check Point Harmony Email & Collaboration Setup Beta

Check Point Harmony Email & Collaboration (formerly Avanan) is a cloud email security platform. Once connected, Junto can search the security events Check Point has raised for a client, look up inspected and quarantined emails, review pending restore requests, and, with approval, quarantine or release messages and manage anti-phishing exception rules.

Prerequisites

  • A Check Point Infinity Portal account with the Harmony Email & Collaboration service, or a legacy Avanan SmartAPI key issued by Avanan Support.
  • Admin or Owner role in Junto.

How Configurations Work

API keys for Harmony Email & Collaboration are regional. Each configuration in Junto holds one key for one platform and region, and the tenants discovered through that key can only be mapped to companies under that configuration. If you manage tenants in more than one region, add one configuration per region.

Step 1: Create an API Key

  1. Sign in to the Check Point Infinity Portal.
  2. Go to Global Settings > API Keys and create a new API key.
  3. Select the Harmony Email & Collaboration service.
  4. Copy the Client ID and Access key. The access key is shown only once.

Avanan SmartAPI (legacy)

If your tenants are still on the legacy Avanan platform, request an App ID and Secret key from Avanan Support. Keys are issued per region.

Step 2: Configure in Junto

  1. In Junto, go to Settings > Integrations > Check Point Harmony Email & Collaboration.
  2. Click Add configuration.
  3. Fill in the form:
FieldDescription
Display nameA label for this configuration, such as US tenants.
PlatformCheck Point Infinity Portal or Avanan SmartAPI (legacy).
RegionThe region the key was issued for: United States, Europe, United Kingdom, Canada, Australia, or India.
Client ID / App IDFrom Step 1.
Access key / Secret keyFrom Step 1. Encrypted on save.
ActiveTurn off to pause the configuration without deleting it.
  1. Click Create.
  2. On the new configuration card, click Test connection. Junto verifies the key and loads the list of tenants it can see. The card shows the count under Known tenant scopes.

Platform and region are fixed

You cannot change a configuration's platform or region after creating it. Add a new configuration instead. You can update the credentials at any time with Edit.

Step 3: Map Tenants to Companies

The agent only works with tenants that are mapped to a Junto company.

  1. Click Map tenants to companies at the top of the settings page.
  2. Tenants are grouped by configuration. For each tenant, choose the matching Junto company. Click Auto-map on a configuration to match tenants to companies by name; exact matches are applied immediately, and close matches are shown as suggestions to confirm or dismiss.
  3. Click Save mappings.

Each tenant maps to one company, and each company can hold one tenant. A company can only be mapped under one regional configuration.

If the dialog shows "No tenants found", run Test connection on an active configuration to load its tenants first.

What the Agent Can Do

Read tools run without approval. Every tool that changes something in a tenant requires approval, and the approval shows the company, the affected items, and their current state before anything is sent.

Security Events

ToolDescriptionRisk Level
List Tenant ScopesList the mapped tenants and their platform and region, to confirm which clients have email security dataLow
Search Security EventsSearch phishing, malware, DLP, anomaly, malicious URL click, and alert events by type, state, severity, source, date, or descriptionLow
Get Security EventView one event in full, including the verdict, actions already taken, and actions still availableLow
Summarize Security EventsCount events over a date window by type, severity, state, source, or day, with a per-company breakdown and a previous-period comparisonLow
Check Action StatusCheck whether a quarantine, restore, or decline action has finishedLow

Emails

ToolDescriptionRisk Level
Search EmailsSearch inspected emails by subject, sender, recipient, date, and quarantine stateLow
Get EmailView one email's headers, links, attachments, quarantine and restore flags, and the per-engine security verdictsLow
Summarize EmailsCount inspected emails over a date window by verdict, quarantine state, mail platform, or dayLow

Quarantine Actions

ToolDescriptionRisk Level
Quarantine EmailsPull the emails behind one or more events out of user mailboxesMedium
Restore EmailsRelease quarantined emails back to user mailboxes, including approving an end-user restore requestHigh
Decline Restore RequestsReject end-user restore requests and keep the messages in quarantine, with an optional reasonMedium

Anti-Phishing Exceptions

ToolDescriptionRisk Level
List ExceptionsList a tenant's allow-list, block-list, and spam allow-list rulesLow
Get ExceptionView exactly what one rule matchesLow
Create Anti-Phishing ExceptionAdd an allow-list rule for a legitimate sender, a block-list rule, or a spam allow-list ruleHigh
Update Anti-Phishing ExceptionChange a rule's matchers, matching mode, SPF handling, or comment. The approval shows the complete rule that will resultHigh
Delete Anti-Phishing ExceptionPermanently remove a ruleHigh

TIP

Quarantine, restore, and decline actions run asynchronously in Check Point. The agent checks the action status and confirms the result on the event before reporting it as done.

Example Questions

  • "What did Check Point catch for Acme Corp this week?"
  • "Did anyone at Contoso receive an email from billing@example.com?"
  • "Why was the invoice email to Sam quarantined?"
  • "Are there any pending restore requests for Acme Corp?"
  • "Is vendor.com already allow-listed for Contoso?"
  • "How many phishing attempts did Acme Corp get this month compared to last month?"

Troubleshooting

  • Connection fails -- Check the Client ID and Access key (or App ID and Secret key), and confirm the region matches where the key was issued. For Infinity Portal keys, make sure the key was created for the Harmony Email & Collaboration service.
  • Known tenant scopes shows 0 -- Run Test connection again. If it still shows 0, the key does not have access to any tenants in that region.
  • A company's email data isn't available to the agent -- The company's tenant is not mapped. Open Map tenants to companies and check that the tenant has a company selected and the mappings are saved.
  • A company can't be selected in the mapping dialog -- It is already mapped to a tenant, possibly under a different regional configuration. Each company can hold one tenant.
  • Tools disappeared after pausing a configuration -- Turning off Active hides that configuration's tenants and tools until it is turned back on. Existing mappings are kept.