Overview
The Check Point Harmony Email integration enables AirMDR to collect and analyze Harmony Email & Collaboration security events using REST APIs. This helps SOC teams investigate email-based threats such as phishing, malware, suspicious URLs, DLP violations, spam, and shadow IT activity.Supported Versions
Authentication
Check Point Harmony Email usesΒ Client IDΒ andΒ Client SecretΒ to generate an API access token. The access token is then used in theΒAuthorizationΒ header for API requests.
Pre-requisites
Users must have Administrator access to theΒ Check Point Infinity Portal.Ability to create and manageΒ API Keys (Client ID & Client Secret).AirMDR Remote Agent installed and active (if required by deployment model).
Configure Check Point Harmony Email (API Key Generation)
Access Infinity Portal
- Log in to theΒ Check Point Infinity Portal
- Navigate to:
AccountΒ Settings β API Keys.
Create a New API Key
- ClickΒ New
- SelectΒ New Account API Key
- In theΒ Create a New API KeyΒ window:
- ChooseΒ Email & Collaboration as the service.
Generate Credentials
- Enter aΒ Description:
For example:ΒAirMDR - Harmony Email IntegrationΒ - Select anΒ Expiration DateΒ (recommended as per policy).
- Assign appropriateΒ role/permissionsΒ (if prompted).
Generate Credentials
- ClickΒ Create
- Copy and securely store:
- Client ID
- Client Secret (Secret Key)
- Authentication URL (if displayed)
Identify Region and Base URL
Determine Tenant Region
- Identify your tenant region from the Infinity Portal URL
- Use the region where your Check Point Harmony Email tenant is hosted.
For Example:us.portal.checkpoint.comΒ β USA region
Map Region to Base URL (For reference)
Map Region to Base URL (For reference)
Validate API Authentication
Use the following sample request to verify that the Client ID and Client Secret are working:Example POST Request using cURL:
Example POST Request using cURL:
Response Sample
Response Sample
Configure Check Point Harmony Email in AirMDR Integrations Dashboard
- Navigate to AirMDR, provide the credentials and click Login
- Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select Integrations.
- Use the search option, enter the keyword βCheck Point Harmony Emailβ, select the Connections tab, and click + Create button.
- Enter an unique name to the Instance (e.g.,
your org name-Check Point Harmony Email) to easily identify the user connection by AirMDR. - Enter the application credentials like Client ID, and Client Secret in the Authentication Details field params, and click Save.
Skills provided by this Integration
Additional Information
π§° Error Handling
π§° Error Handling
π Managing or Deleting the API Key
π Managing or Deleting the API Key
Identify the Key
- Ensure the API key isΒ no longer in useΒ by AirMDR or any other integration
Delete the API Key
- InΒ Settings β API Keys, locate the target key
- Click theΒ DeleteΒ option (trash icon or action menu)
- Confirm the deletion when prompted
Post-Deletion Validation
After deleting or rotating an API key:- Verify AirMDR integration status:
- Should not show authentication errors
- Check logs for failures:
- Confirm new key is functioning correctly
π Security & Access Best Practices
π Security & Access Best Practices
- Use aΒ dedicated API keyΒ exclusively for AirMDR integration
- StoreΒ Client Secret securelyΒ (avoid plaintext in scripts, logs, or shared documents)
π Support & Maintenance
π Support & Maintenance
- π§ Contact AirMDR Support through your designated support channel.
- π Rotate credentials regularly.
- π Reconnect in AirMDR when secrets are changed.

