Category filter

Integrate Check Point Harmony Mobile with Hexnode UEM

Check Point Harmony Mobile is a threat defense solution designed to safeguard mobile devices against emerging cyber-attacks. It provides complete protection over corporate data across all mobile attack surfaces like operating systems, applications, and networks. Its App Protection capability detects and prevents the download of malware apps. Moreover, it blocks phishing attacks across all applications and curtails the distribution of sensitive data from infected devices to malicious botnets, enhancing data protection.

Admins can further optimize mobile device security by integrating Check Point Harmony Mobile with Hexnode UEM. This integration enhances the security capabilities of both iOS and Android devices. With this integration, admins can access device-specific threat-related information in Hexnode UEM synced by the Harmony Mobile Protect app installed on the devices.

Check Point Harmony Mobile integration with Hexnode UEM

Note:

  • Check Point Harmony Mobile integration is supported only on Ultimate and Ultra subscription plans.
  • Check Point Harmony Mobile integration is supported for iOS and Android devices.

In the Hexnode UEM console,

  1. Log in to the Hexnode portal.
  2. Navigate to Admin > Integrations and select Check Point Harmony Mobile. Check Point Harmony Mobile integrations page in the Hexnode portal
  3. Create the API key by configuring the following details:
    • Instance Name: Provide a name to identify the integration in the Hexnode portal.
    • Server address: Copy the displayed server address of your Hexnode console.
    • Expiry Date: Specify the date of expiration of the generated API Key. The expiry date cannot be set more than 1 year from the date of generating the API key.
    • Check the Notify Admin via Email on Key Expiry option to send an email to the admin when the API key expires.

    Creating an API key for integrating Check Point Harmony Mobile with Hexnode UEM

  4. Click Create. API Key generated for Check Point Harmony Mobile integration in the Hexnode portal
  5. The username and the API key will be generated.
  6. Note:


    The API key will not be visible once you click Done and exit the page.

In the Infinity Portal,

  1. Log in to the Infinity Portal.
  2. Go to Settings > Integrations.
  3. Click + Add > UEMs to create a new integration.
  4. Select Hexnode from the list of UEMs. Select Hexnode UEM from the list of UEMs in Infinity Portal
  5. Configure the following server details for Hexnode integration:
    • Display Name: Provide a name to your service in the Infinity Portal. By default, the display name is Hexnode Default.
    • Server Address: Paste the server address you copied from the Hexnode console.
    • Username: Copy and paste the username generated in the Hexnode console.
    • Password: Copy and paste the API key generated when configuring the instance in the Hexnode portal.

    Configure the server details for integration with Hexnode UEM

In the Hexnode UEM console,

  1. Click Done.
  2. Select Add Device Groups and select the device groups (consisting of the required iOS and Android devices) you want to add to this instance.
  3. Click Save. The selected device groups will be added to this instance. Add the device groups to this instance

In the Infinity Portal,

  1. Click Verify > Next.
  2. Select the device groups that are synced.
  3. In the Advanced settings, you can choose to import Personally Identifiable Information (PII) of devices that includes the device name, device number and device email. Additionally, choose to set up the interval configuration:
    • Device sync interval: Set the interval for connecting with UEM to synchronize devices. Acceptable values: 30-1440 minutes. It must be in multiples of 10 minutes.
    • Device deletion threshold: Percentage of devices allowed for deletion after UEM device sync. Set 100% for no threshold.
    • Device deletion after: The number of syncs that should elapse before the deletion of missing devices.
    • App sync interval: Harmony Mobile will start the next app synchronisation with the UEM after the specified minutes has passed. Acceptable values: 10-1440 min. It must be in multiples of 10 minutes.

    Add device groups and configure sync settings

  4. Click Verify > Next.
  5. Send tag information to Hexnode UEM to communicate the deployment status of Harmony Mobile Protect app and the risk level of the device. You can choose the following characteristics:
    • Tag device status: The device status in Harmony Mobile Protect app.
    • Tag device risk: The device risk level in Harmony Mobile Protect app.

    Send tag information to Hexnode UEM

  6. Click Verify > Next.
  7. Ignore the generated token and select Finish to complete Hexnode integration with Check Point Harmony Mobile.

The integration of Check Point Harmony Mobile with Hexnode UEM will be available on the page.
Integration completed between Hexnode UEM and Check Point Harmony Mobile

Register the devices using the Harmony Mobile Protect app

Get the device registration credentials from the Infinity Portal:

  1. On the Infinity Portal, go to Devices. This page displays all the devices synced from Hexnode UEM.
  2. Enable the checkbox of the synced device.
  3. Go to the More actions dropdown and select Registration code.
    Scan the registration code for the device
  4. The registration credentials will be generated for the device.
    The registration credentials are generated for the device

Add the Harmony Mobile Protect app for Android and iOS devices to the Hexnode app inventory and deploy the app to the device groups added to the instance. After successfully installing the application, proceed with completing the device’s registration from the Infinity Portal.

Method 1: Scan the QR code

You can register devices on the Infinity Portal by scanning the QR code.

  1. Launch the app.
  2. Grant the necessary app permissions.
  3. Click the QR code scanner and scan the QR code generated in the Infinity Portal.
    Scan the QR code using the QR code scanner to register the device
  4. Grant the Location and Background activity security settings as per the requirements. The policies configured in the Infinity Portal will get downloaded and the app will start scanning the device for any threats.

Method 2: Enter the registration credentials

You can register devices by entering the device registration credentials appearing in the Infinity Portal to the app.

  1. Launch the app.
  2. Grant the necessary app permissions.
  3. Click the Register with credentials option:
    • Server Address: Enter the server address generated in the Infinity Portal.
    • Registration Key: Enter the registration code generated in the Infinity Portal.

    Enter the server address and registration code to register the device

  4. Click Login. The policies configured in the Infinity Portal will get downloaded and the app will start scanning the device for any threats.

On the Infinity Portal, click the Refresh button to update and retrieve the device’s details and status.
Device is registered to the Infinity portal

How to check the device risk status and app status on Hexnode UEM?

You can check the Harmony Mobile Protect app status and the Harmony Mobile device risk status on the device details page.

  1. On the Hexnode portal, navigate to Manage > Devices.
  2. Click on a device.
  3. From Actions, select Scan Device.
  4. You can check whether the scan is successful from the Action History.
  5. Upon successful scan, reload the page to view the changes.
  6. Go to the Device Info sub-tab.
  7. You will find two new fields:
  • Harmony Mobile Protect app status: Provides the status of the app installed on the devices.
Field value Definition
Provisioned The app is not installed on the device.
Active The app is installed and activated on the device.
Inactive The device has not contacted Check Point Harmony Mobile for a certain number of days. (The number of days is configured in the Infinity Portal. Navigate to Policy > Global > Devices > Connectivity Settings. You can set the number of days from 1 to 45.)
  • Harmony Mobile device risk status: Provides the risk status of the device.
Field value Definition
None No risk detected by the app.
Low Low risk detected by the app.
Medium Medium risk detected by the app.
High High risk detected by the app.

Check the Check Point Harmony Protect app status and device risk status

Managing the Check Point Harmony Mobile instance on the Hexnode portal

To view the details of the Check Point Harmony Mobile instance in the Hexnode portal, navigate to Admin > Integrations > Configured Integrations and select the instance. Here, you can see a complete list of all the device groups associated with the instance and generate a device risk status report in PDF or CSV format. The report consists of device’s Name, Group Name, Group Type, Harmony Mobile Protect Status, and Risk Status.

Check Point Harmony integration summary

You can delete the device group by clicking on its corresponding trash icon. Once deleted, you will no longer be able to view the risk status of the devices associated with the group from the Hexnode portal.

Click on the Actions button to Reset or Delete the instance from the Hexnode portal. By resetting the integration instance, the associated API key and configurations will be reset. A new API key will be generated, which can be used to re-configure the integration. By deleting the integration instance, the associated API key and configurations will be permanently deleted from Hexnode UEM.

  • Hexnode Integrations