Check Point Harmony Email operations begin after detection. Analysts must determine whether a message was delivered, quarantined, modified, reported by a user, detected across multiple recipients, or associated with a compromised account. They may then search related messages, quarantine one item or a result set, approve or decline a restore request, add an exception, or escalate identity response. Each action changes either user access or future protection and needs a traceable reason.
Quarantine release deserves the same care as containment. Users can interact through notifications, a digest, or the End-User Portal according to configured permissions. Restore requests enter an administrative dashboard and may be handled manually, semi-automatically, or automatically after Check Point re-evaluates the message. The restored item can appear as a new message with the restoration time, and a Microsoft-quarantined item may be unavailable if Microsoft’s retention has expired.
Build the service around queues, time targets, and evidence. Define who can inspect sensitive message content, who can remove mail from many recipients, who approves an inconclusive restore, who owns compromised-account response, and who communicates with users. Feed confirmed events to the incident process or SIEM as appropriate, then use monthly operational measurements to reduce noise without creating broad allow rules.
Key decisions at a glance
- Triage security events from message, sender, recipient, verdict, workflow, delivery, related recipients, and user-report evidence before taking a high-impact action.
- Manual quarantine can remove a reported message from every recipient mailbox, so analysts must confirm scope, authority, and recovery options before bulk action.
- Require authentication for notification links because automated email scanners can otherwise activate an unauthenticated restore URL.
- Select manual, semi-automatic, or automatic restore handling from documented risk tolerance, an inconclusive verdict should not be treated as equivalent to clean without approval.
- Tune policy from measured false positives, restore outcomes, repeat senders, user reports, response time, and exception usage while preserving incident evidence and privacy.
Triage events with a repeatable evidence and decision record
Start every queue item with a stable event reference and a restricted case record. Capture detection time, SaaS application, mail direction, sender and recipient classes, verdict, detection reason, policy and workflow, delivery state, subject only when necessary, attachment or URL indicators, user-report status, related-recipient count, and actions already taken. Avoid pasting full message bodies or personal data into general tickets, use the portal’s controlled entity view and a case system approved for sensitive evidence.
Use the Events page, Mail Explorer, and custom queries to establish scope. Search for related sender, domain, subject pattern, message identifiers, attachment hashes, URLs, recipients, and time windows that are justified by the case. Validate whether the event is a single message, a campaign, a compromised partner, an internal account anomaly, or a benign workflow. Add a concise analyst note that explains evidence, uncertainty, decision, and next owner rather than merely changing the event state.
Separate mail containment from identity response. A phishing email can require broader search and quarantine, while a compromised account may require blocking the user, resetting credentials, revoking sessions, and investigating mailbox changes through the identity incident process. Assign one incident commander when multiple teams are involved. If event forwarding is enabled, verify that the SIEM receives supported events over the configured encrypted path and that analysts can correlate the external alert back to the portal record.
- Capture event, policy, workflow, delivery, scope, user-report, and related-message evidence in a restricted case.
- Use Mail Explorer and custom queries with justified indicators to determine campaign and recipient scope.
- Record the analyst’s evidence, uncertainty, containment choice, and next owner before closing a queue item.
- Coordinate mailbox containment, identity remediation, endpoint response, legal review, and user communications under one case owner.
Control manual quarantine and bulk actions by blast radius
An analyst can quarantine from an event or an email profile, and custom-query results can support bulk action. Check Point says quarantine removes the message from the user mailbox and moves it to the designated quarantine mailbox. The current guide also warns that quarantining a user-reported phishing message with multiple recipients removes it from all recipient mailboxes. Display the proposed recipient count, validate the query, obtain the required approval, and save a sanitized result summary before executing a campaign-wide action.
Choose the containment action from observed state. A delivered malicious campaign may require immediate broad quarantine, while an inconclusive business message may warrant a narrower hold and sender verification. Confirm which recipients still have access, whether the item has attachments or links that demand endpoint investigation, and whether a user forwarded or copied the content elsewhere. Quarantine is not proof that no user interacted with the original message.
Plan reversal before containment. Define who can release a message, what evidence supports release, how recipients will be notified, and what happens if the original platform no longer retains the item. Default manual-quarantine notifications may be disabled, so do not assume users understand why mail disappeared. The case record should link the removal, any restore request, the final verdict, the release decision, and any exception or policy change that followed.
- Preview search criteria and recipient count before a query-based or user-report-wide quarantine action.
- Require stronger approval as the recipient population, business sensitivity, or verdict uncertainty increases.
- Investigate clicks, attachment execution, forwarding, and mailbox rules because quarantine cannot reverse user interaction.
- Link containment, user notification, restore, final verdict, and tuning decisions in one auditable case chain.
Authenticate notification links and govern restore-request automation
Require authentication for actions launched from email notifications. Check Point warns that security scanners may activate an unauthenticated restore link while inspecting a notification. Configure the authentication requirement and a reasonable browser-cookie lifetime, test the intended identity-provider flow, and verify that an unauthorized user or a link scanner cannot release a message. Treat the notification template as a security surface, avoiding unnecessary message content and clearly identifying the support route.
Choose manual, semi-automatic, or automatic handling deliberately. Restore requests are re-evaluated and classified as clean, phishing, or inconclusive. Manual mode sends all outcomes for administrator review. The documented semi-automatic pattern restores clean mail, sends inconclusive mail for review, and declines phishing. Automatic mode can restore clean and inconclusive items while declining phishing. Organizations that cannot accept automatic release of uncertainty should not adopt the most permissive preset simply to reduce queue volume.
Define approvers and service levels for each verdict, sender class, recipient group, and business process. Verify the requester, inspect the event and re-evaluation evidence, check whether the message remains retained, and document the decision. Tell support teams that a restored item may arrive as a new message with the current restore time rather than its original received time, preventing unnecessary duplicate or missing-message investigations after a legitimate release.
- Require user authentication for notification actions and test against automated link-scanning behavior.
- Select restore automation by clean, phishing, and inconclusive risk rather than administrator workload alone.
- Route uncertain or high-impact requests to named approvers with evidence, time targets, and escalation.
- Set user expectations for retention limits and the timestamp behavior of a message returned from quarantine.
Measure user experience and tune without weakening broad protections
Design the digest and End-User Portal from the permissions policy. Decide which quarantined categories users can see, whether they may request restoration or restore without approval, how group-recipient requests work, and which messages belong in a digest. Use plain language for verdicts and support contacts, but do not train users to release messages automatically. Test with a normal employee, shared-mailbox operator, group recipient, executive assistant, and accessibility user.
Track queue age, response and restore time, request approval and decline rates, re-evaluated verdicts, repeated false-positive senders, repeated campaigns, messages removed per action, user-report precision, alert delivery, expired-retention failures, authentication failures, and exception creation. Segment by workflow and mail direction so one noisy marketing source does not obscure a malicious internal pattern. Keep denominators and collection definitions stable enough to compare periods.
Use a monthly tuning meeting to convert evidence into a bounded change. Close obsolete exceptions, narrow overbroad entries, adjust a specific workflow or notification, update an upstream MTA record, fix a reporting or SIEM gap, and retrain analysts where decision notes are weak. Test the changed rule with both the original sample and a protected negative control, monitor the rollout, and preserve the prior configuration for rollback. Improvement should reduce repeat work while keeping uncertain messages subject to appropriate review.
- Test digest and portal permissions across normal, shared, group, delegated, and accessibility scenarios.
- Measure queue, restore, verdict, campaign, authentication, retention, alert, and exception outcomes with stable definitions.
- Base each tuning change on observed cases and apply the narrowest rule, workflow, or communication correction.
- Retest original and negative-control messages, observe production results, and retain a rollback-ready prior configuration.
Vendor documentation and ALLMSP resources
- Check Point managing security events
- Check Point Events page
- Check Point manual quarantine
- Check Point quarantine restore requests
- Check Point automatic restore handling
- Check Point authentication for email notifications
- Check Point admin quarantine release
- Check Point SIEM and SOAR integration
- ALLMSP Check Point Harmony Email archive
- ALLMSP business software support
- ALLMSP managed IT services
- ALLMSP data backup and recovery
- Contact ALLMSP
Frequently Asked Questions
Where should Harmony Email analysts start an investigation?
Start with the Events page and a restricted case record containing the event reference, SaaS application, mail direction, verdict, detection reason, policy workflow, delivery state, affected recipients, user reports, and previous actions. Use Mail Explorer or a custom query to establish related-message scope before containment.
Can Check Point Harmony Email quarantine a message after delivery?
Yes. An analyst can manually quarantine through an event or email profile, and bulk actions can follow a custom query. Quarantine removes the message from the user mailbox and moves it to the designated quarantine mailbox. Investigate user interaction because removal does not undo a click, download, or forward.
What happens when an analyst quarantines a reported message sent to many people?
Check Point states that quarantining a user-reported phishing email with multiple recipients removes it from every recipient mailbox. Preview the affected population, confirm authority and evidence, preserve a sanitized query result, and have a release and communication plan before executing a high-blast-radius action.
Should Harmony Email notification links require authentication?
Yes. Check Point warns that automated email-security scanners can mistakenly trigger an unauthenticated restore link. Require authentication for notification actions, choose a defensible cookie lifetime, test the identity flow, and verify that an unauthorized user or scanner cannot release quarantined mail.
What is the difference between manual and semi-automatic restore handling?
Manual handling sends clean, inconclusive, and phishing re-evaluations to an administrator. The documented semi-automatic pattern restores clean messages, sends inconclusive cases for review, and declines phishing. Choose by risk, regulatory needs, sender class, and business impact rather than queue volume alone.
Does automatic restore handling release inconclusive messages?
The current automatic preset can approve clean and inconclusive re-evaluations while declining phishing. If the organization cannot accept automatic release of an uncertain verdict, configure manual review for inconclusive requests or use a more conservative workflow with named approvers and escalation.
Why can a restored quarantined email appear out of order?
Check Point documents that a restored item may return as a new message with the restoration time instead of the original received time. Tell users and help-desk staff to search around the restore time and connect the returned item to its case before opening a duplicate-delivery investigation.
Can every Microsoft-quarantined message still be restored?
Not necessarily. A restore can fail when Microsoft no longer retains the quarantined item. Define request time targets, explain retention limits, preserve the event and decision record, and use an approved alternative recovery source only when policy and legal requirements permit it.
What should a Harmony Email quarantine digest allow users to do?
That depends on configured end-user permissions and organizational risk. Decide which categories are visible, whether users can request a restore or self-release, how group messages behave, and whether authentication is mandatory. Test normal, shared, delegated, group, and accessibility scenarios before broad use.
Which metrics should drive Harmony Email tuning?
Track queue age, response and restore time, approvals, declines, re-evaluated verdicts, repeated false positives, campaign size, user-report quality, alert delivery, retention failures, authentication failures, and exception usage. Apply the narrowest evidence-backed change and retest both the original sample and a protected negative control.
























































