Check Pointintermediate

How to Deploy Harmony Mobile to iOS and Android Devices

Complete guide to deploying Check Point Harmony Mobile Protect app to iOS and Android devices using MDM, UEM, or manual enrollment.

16 min readUpdated January 2025

Want us to handle this for you?

Get expert help →

Check Point Harmony Mobile provides comprehensive mobile threat defense (MTD) for iOS and Android devices, protecting against malware, network attacks, and OS vulnerabilities. This guide covers deploying the Harmony Mobile Protect app across your organization using various enrollment methods.

Prerequisites

Before deploying Harmony Mobile, ensure you have:

  • Check Point Infinity Portal account with Harmony Mobile license
  • Mobile devices meeting minimum requirements (iOS 15.0+ or Android 11.0+)
  • MDM/UEM solution (optional but recommended for enterprise deployment)
  • Network access for devices to reach Check Point cloud services
  • User communication plan for enrollment notifications

Understanding Deployment Methods

Harmony Mobile supports multiple deployment approaches:

MethodBest ForUser InteractionComplexity
Zero-Touch (MDM)Enterprise with MDMNoneMedium
MDM with Manual ActivationMixed environmentsMinimalMedium
Email InvitationBYOD environmentsModerateLow
QR Code/ManualSmall deploymentsFullLow

Step 1: Access Harmony Mobile Dashboard

  1. Sign in to https://portal.checkpoint.com
  2. Click the Menu icon in the top left
  3. Under Harmony, click Mobile
  4. The Harmony Mobile dashboard opens

Step 2: Configure Initial Settings

Set Up Your Organization

  1. Go to Settings in the left menu
  2. Click General Settings
  3. Configure:
    • Organization Name: Your company name
    • Contact Email: Admin email for notifications
    • Time Zone: Your organization's time zone
  4. Click Save

Configure Device Management Integration

  1. Go to Settings > Device Management
  2. Select your MDM/UEM solution from the dropdown:
    • Microsoft Intune
    • VMware Workspace ONE
    • BlackBerry UEM
    • MobileIron
    • Jamf Pro
    • ManageEngine MDM Plus
    • Hexnode UEM
  3. Follow the integration wizard for your selected MDM

Step 3: Deploy to iOS Devices

Option A: Zero-Touch Deployment with MDM

For Microsoft Intune:

  1. Configure Intune Integration

    • In Harmony Mobile, go to Settings > Device Management
    • Select Microsoft Intune from the MDM dropdown
    • Click Configure and sign in with Azure AD admin credentials
    • Grant required permissions
  2. Add Harmony Mobile App to Intune

    • In Microsoft Endpoint Manager admin center
    • Go to Apps > iOS/iPadOS > Add
    • Select iOS store app
    • Search for "Harmony Mobile Protect"
    • Assign to your device groups
  3. Create App Configuration Policy

    • Go to Apps > App configuration policies > Add
    • Select Managed devices and iOS/iPadOS
    • Select the Harmony Mobile Protect app
    • Add configuration settings:
      <dict>
        <key>server</key>
        <string>your-tenant.checkpoint.com</string>
        <key>activationToken</key>
        <string>YOUR_ACTIVATION_TOKEN</string>
      </dict>
      
    • Assign to the same device groups
  4. Deploy VPN Profile for Zero-Touch

    • Create a VPN configuration profile
    • Select Check Point Capsule VPN as the connection type
    • Configure with Harmony Mobile server details
    • This enables automatic activation without user interaction

Option B: Manual Enrollment for iOS

  1. Generate Registration Credentials

    • In Harmony Mobile dashboard, go to Devices
    • Click Add Device > iOS
    • Choose Email invitation or QR code
    • Enter user email address (for email method)
  2. User Installation Steps

    • User receives email with registration link
    • User downloads "Harmony Mobile Protect" from App Store
    • User opens the app and either:
      • Scans the QR code, or
      • Enters server address and registration code
    • User grants required permissions:
      • VPN configuration
      • Notifications
      • Local network access (optional)
  3. Verify Activation

    • Device appears in Harmony Mobile dashboard
    • Status changes from "User Notified" to "Active"
    • Initial security scan completes automatically

Step 4: Deploy to Android Devices

Option A: Zero-Touch Deployment with MDM

Important: Android Enterprise is mandatory for Zero-Touch deployment on Android.

For Microsoft Intune:

  1. Enable Android Enterprise

    • Ensure Android Enterprise is configured in Intune
    • Devices must be enrolled as Work Profile or Fully Managed
  2. Add Harmony Mobile App

    • In Endpoint Manager, go to Apps > Android
    • Click Add > Managed Google Play app
    • Search for "Harmony Mobile Protect"
    • Approve and assign to device groups
  3. Create Managed Configuration

    • Go to Apps > App configuration policies
    • Click Add > Managed devices
    • Select Android Enterprise
    • Configure settings:
      KeyValue
      serveryour-tenant.checkpoint.com
      activationTokenYOUR_TOKEN
      autoActivationtrue
  4. Configure Permissions

    • Grant required runtime permissions via MDM:
      • Device administrator
      • Accessibility service
      • VPN connection
      • Notification access

Option B: Manual Enrollment for Android

  1. Generate Registration Credentials

    • In Harmony Mobile dashboard, go to Devices
    • Click Add Device > Android
    • Choose your preferred method:
      • Email invitation
      • QR code
      • Manual entry
  2. User Installation Steps

    • User downloads "Harmony Mobile Protect" from Google Play
    • User opens the app
    • User activates using one of these methods:

    QR Code Method:

    • Tap the QR code scanner icon
    • Scan the QR code from the admin portal or email

    Manual Entry Method:

    • Enter the server address
    • Enter the registration code
    • Tap Activate
  3. Grant Required Permissions

    • User approves VPN connection
    • User enables Device Administrator (if required by policy)
    • User grants Accessibility service access (for advanced protection)
    • User enables Notification access (optional)
  4. Complete Activation

    • App performs initial device scan
    • Device appears as "Active" in dashboard
    • Threat protection is now enabled

Step 5: Configure HTTPS Inspection (Optional)

For advanced network protection, configure HTTPS inspection:

Generate CA Certificate

  1. In Harmony Mobile, go to Policy > Network Protection
  2. Under HTTPS Settings, enable HTTPS Inspection
  3. Under Inspection CA, select Central CA for UEM Deployment
  4. Click Generate CA Certificate
  5. Download the certificate file

Deploy CA Certificate via MDM

For iOS:

  1. Create a Certificate profile in your MDM
  2. Upload the Check Point CA certificate
  3. Configure as a trusted root certificate
  4. Deploy to managed devices

For Android:

  1. Create a Certificate profile for Android Enterprise
  2. Upload the Check Point CA certificate
  3. Configure for VPN authentication
  4. Deploy to work profile devices

Step 6: Create Device Groups

Organize devices for policy management:

  1. Go to Devices in Harmony Mobile dashboard
  2. Click Groups > Create Group
  3. Enter a group name (e.g., "Executive Devices", "Sales Team")
  4. Add devices to the group:
    • Select devices individually, or
    • Import from MDM groups, or
    • Use dynamic rules based on device attributes
  5. Click Save

Step 7: Verify Deployment

Check Device Status

  1. Go to Devices in the dashboard
  2. Review the device list:
    • Active: Device is protected and communicating
    • User Notified: Invitation sent, awaiting installation
    • Inactive: Device hasn't communicated recently
    • At Risk: Device has active security issues

Review Initial Scan Results

  1. Click on a device to view details
  2. Check Security Status:
    • Protected: No threats detected
    • At Risk: Active threats or vulnerabilities
  3. Review any detected issues in the Events tab

Test Threat Detection

  1. Trigger a test detection (safe testing):
    • Visit a known test phishing URL (e.g., Check Point's test page)
    • Attempt to connect to an unsecured WiFi network
  2. Verify the threat appears in the device's event log
  3. Confirm notification was sent to the user (if configured)

Troubleshooting Common Issues

App Won't Activate

Symptoms: Registration code rejected or activation fails.

Solutions:

  1. Verify the registration code hasn't expired (typically 7 days)
  2. Check device meets minimum OS requirements
  3. Ensure internet connectivity is available
  4. For MDM deployment, verify managed configuration is correct
  5. Generate a new registration code and retry

Device Shows as Inactive

Symptoms: Device was active but now shows inactive status.

Solutions:

  1. Check device has internet connectivity
  2. Verify the Harmony Mobile app is running (not force-stopped)
  3. Check battery optimization isn't killing the app
  4. Ensure VPN permissions are still granted
  5. Resend activation from the dashboard

VPN Won't Connect

Symptoms: Network protection features not working, VPN fails to establish.

Solutions:

  1. Verify VPN permissions are granted in device settings
  2. Check for conflicting VPN apps or profiles
  3. Ensure the CA certificate is properly installed (for HTTPS inspection)
  4. Verify network allows VPN connections
  5. Try switching between WiFi and cellular to test

MDM Integration Issues

Symptoms: Zero-touch deployment not working, app not auto-activating.

Solutions:

  1. Verify MDM integration is properly configured in Harmony Mobile
  2. Check activation token is correct in app configuration policy
  3. Ensure device is properly enrolled in MDM
  4. For Android, confirm Android Enterprise is enabled
  5. Review MDM logs for deployment errors

Best Practices

  1. Pilot before full deployment: Test with a small group first
  2. Communicate with users: Explain the app's purpose and benefits
  3. Use groups for policy management: Organize by department or risk level
  4. Enable gradual protection: Start with monitoring, then enable blocking
  5. Monitor compliance: Track deployment progress and address inactive devices
  6. Keep apps updated: Enable automatic updates in MDM
  7. Document exceptions: Track any devices that can't be enrolled and reasons

Next Steps

After deploying Harmony Mobile:

  1. Configure threat defense policies: Set up protection rules for network, app, and OS threats
  2. Enable conditional access: Integrate with MDM for compliance-based access control
  3. Set up alerts: Configure notifications for security events
  4. Review dashboards: Monitor threat trends across your mobile fleet
  5. Train users: Educate employees on responding to security alerts

Additional Resources


Need help securing your mobile workforce? Inventive HQ offers comprehensive mobile security solutions and MDM integration services. Contact us for expert deployment assistance.

Frequently Asked Questions

Find answers to common questions

For iOS devices, Harmony Mobile Protect requires iOS 15.0 or later (macOS 12.0 for Mac with Apple M1 chip). For Android devices, version 11.x or higher is required. Both platforms need an active internet connection for threat intelligence updates and cloud communication.

Need Professional IT & Security Help?

Our team of experts is ready to help protect and optimize your technology infrastructure.