> Source: [sk182659](https://support.checkpoint.com/results/sk/sk182659)

# sk182659 - Harmony Endpoint Onboarding Best Practices

| Property | Value |
|----------|-------|
| Solution ID | sk182659 |
| Date Created | 2024-09-13 |
| Last Modified | 2025-09-17 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud |

## Solution

### Introduction

Deploying of the Harmony Endpoint security solution requires careful planning. This article outlines a straightforward and the most effective approach to ensure an easy implementation of the Harmony Endpoint security solution.

### Planning

Effective onboarding starts with understanding the organization's needs. Collect the following information before proceeding:

* Total number of servers and workstations
* Types of server roles and their numbers
* Types of operating systems
* Hardware resources
* Teams and environments
* History of difficulties with previous onboarding or the product in the organization
* Previous history of cyber attacks on the organization
* Key takeaways

### Onboarding Harmony Endpoint

1. Set up the management server.
2. Prepare the pilot group for deployment.
3. Deploy Endpoint Security Clients and configure the policies.
   1. Deploy initial capabilities on the pilot group.
   2. Configure the Endpoint Policy for the deployed capabilities.
   3. Analyze the logs and forensics.
   4. Optimize the endpoint security solution and settings
   5. Promote the security to the Prevent mode and analyze.
   6. Deploy the capabilities to the production environment.
4. Repeat Step 3 for all the capabilities until all the required capabilities are deployed.

Click Here to Show the Entire Article

### Step (1) : Setting up the Security Management Server {#step1}

Show / Hide this section  
> Harmony Endpoint Management Server is a one-stop solution to manage policies, deployments of Endpoint Security clients, analyze security events, and to configure the Harmony Endpoint Security Client based on the organizational needs and preferences.   
>
> **To get started with Harmony Endpoint:**
>
> 1. [Create an account in Infinity Portal.](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Creating_Account.htm)
> 2. Assign Global roles and Specific Service roles for users. For specific roles available and description, see [Specific Service Roles](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Specific-Service-Roles.htm).
> 3. [Access the Harmony Endpoint Administrator Portal.](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Registering-to-Harmony-Endpoint.htm)
> 4. License the product. For more information, see [Managing Licenses](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP-HB/Managing-Licenses.htm).
> 5. [Enable Two-Factor Authentication (2FA)](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/2FA-Authentication.htm).
> 6. Update the client uninstallation password. For more information, see [Agent Uninstall Password](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Installation_and_Upgrade_Settings.htm#Agent_Uninstall_Password).
> 7. Create virtual groups of users, systems, and servers as per the requirement. For more information, see [Managing Virtual Groups](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Managing-Virtual-Groups.htm).

### Step (2) : Preparing the pilot group for deployment {#step2}

Show / Hide this section  
>
> #### Overview
>
> The pilot group is a representative sample of the organization's IT environment. Initial deployment on the pilot group allows for analysis before full production deployment.
>
> #### To prepare the pilot group for deployment:
>
> 1. Ensure the pilot group includes systems and servers from each role and area of the organization.
> 2. [Uninstall the Third-Party Anti-Virus Software Products](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Uninstalling-Third-Party-Antivirus-Software-Products.htm).
> 3. If required, save policies and exclusions from previous security solutions to replicate them in Harmony Endpoint.
> 4. If required, create virtual groups for the users and systems designated as pilot group. For more information, see [Managing Virtual Groups](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Managing-Virtual-Groups.htm).

### Step (3) : Deploying Endpoint Security Clients and configuring policies {#step3}

#### Step (3.1) : Deploying capabilities on the pilot group {#step3.1}

Show / Hide this section  
> 1. Log in to Infinity Portal and access the Harmony Endpoint Administrator portal.
> 2. Go to **Policy** \> **Deployment Policy** \> **Software deployment**.
> 3. Configure the software deployment policy. For detailed procedure, see [Deploying Endpoint Clients](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Deploying-Endpoint-Clients.htm).
>    1. Deploy and configure capabilities in the following order to minimize complexity:
>       * **Stage 1:** Anti-Malware
>       * **Stage 2:** Anti-Bot, Anti-Ransomware, Behavioral Guard, Forensics, Threat Emulation, Anti-Exploit
>       * **Stage 3:** Media Encryption, Port Protection, Firewall, Application Control
>       * **Stage 4:** Full Disk Encryption, Remote Access VPN, Compliance
>
>       **Note:** Ensure the following steps are performed on each stages individually in the respective hierarchy.

#### Step (3.2) : Configuring the Endpoint Policy for the deployed capabilities. {#step3.2}

Show / Hide this section  
> 1. If required, create different rule bases for different environments of systems and servers in the organization as required.  
>
>    |-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
>    | **Note:** The priority of the rules are based on the sequence of the rule base from top to bottom. For example, if an Endpoint Security client is assigned with Rule Base 1 and Rule Base 2, the rules in the Rule Base 1 is prioritized over the rules in the Rule Base 2. |
>
> 2. Configure the settings and policies for the deployed capabilities. For detailed procedure, see [Configuring the Endpoint Policy](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Configuring-Endpoint-Policy.htm).  
>
>    |--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
>    | **Notes:** * For initial onboarding, set the policy mode to **Detect** for all the capabilities except Anti-Malware. For more information, [Policy Mode](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Configuring-Threat-Prevention-Policy.htm#PolicyMode). * For Anti-Malware capability always set the policy mode to **Prevent**. |
>
> 3. Install and update the policies on the Endpoint Security Clients.

#### Step (3.3) : Analyzing the logs and forensics {#step3.3}

Show / Hide this section  
> After deploying each capability on the pilot group endpoints, analyze the security events by reviewing the logs and forensic data captured by the Harmony Endpoint.
>
> **Note:** Recommended time for analysis is two days.  
>
> Analyze the logs and forensics data for:
>
> * Attacks
> * Restriction
> * Security events and signatures
> * Resource Performance consumption - Diagnostics.
>
> For information on logs, see [Harmony Endpoint Logs](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Logs-menu.htm).
>
> For information on forensic reports, see [Forensics Data](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Sending-Forensics-Data.htm).

#### Step (3.4) : Optimizing the endpoint security solution and settings {#step3.4}

Show / Hide this section  
> The Endpoint policies must be configured differently for different environments and platforms in an organization for specific needs and preferences.
>
> Configure Harmony Endpoint based on organizational needs identified through logs and forensic data analysis. Common configurations include:
>
> * Add required exclusions. Avoid exclusions that could pose a security threat.
> * To reduce resource consumption for the Anti-Malware capability, select **Skip File** for **Riskware Treatment** .  
>   **Note:** This can improve the performance of the Anti-Malware component but reduces security, as clients might not get a reputation status that shows an item to be zero-day malware.
> * Add exclusions to the applications for riskware.  
>   **Note:** An application that isn't inherently malicious, but if exploited could jeopardize the environment.
> * Optimize the Harmony Endpoint for servers and profiles. For detailed procedure, see [Optimizing the Harmony Endpoint Security Client for Servers and Profiles](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Optimizing-Endpoint-for-Servers.htm).

#### Step (3.5) : Promoting the policy mode to Prevent {#step3.5}

Show / Hide this section  
> Once the Harmony Endpoint is stabilized with all the configuration settings and exclusions change the policy mode to **Prevent**.
>
> **To elevate the policy mode for production capacity:**
>
> 1. Change the policy mode to **Prevent** for the added capabilities. For more information, [Policy Mode](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Configuring-Threat-Prevention-Policy.htm#PolicyMode).
>
>    **Note:** The policy mode for Anti-Malware capability must be in Prevent mode even during the initial deployment.
> 2. Review the logs, diagnostics and forensic data.
>
>    **Note:** Recommended time for analysis is two days.
> 3. If required, make necessary changes to policies and add exclusions.

#### Step (3.6) : Deploying the capabilities to the production environment {#step3.6}

Show / Hide this section  
> Note:   
>
> After successful testing of the Harmony Endpoint solution in the pilot group. deploy Harmony Endpoint to the production environment in the following order:
>
> 1. User devices.
> 2. Workstations.
> 3. Servers.
>
> |-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | **Notes:** * It is recommended to deploy each capabilities individually, one at a time, for each group separately. * If required, optimize the Harmony Endpoint for servers and profiles. For detailed procedure, see [Optimizing the Harmony Endpoint Security Client for Servers and Profiles](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Optimizing-Endpoint-for-Servers.htm). |

#### Step (4) : Repeat Step 3 for all the required capabilities.

Show / Hide this section  
> Continue with deploying other capabilities, repeating Steps 3.1 through 3.6 until all the required capabilities are deployed.
>
> |----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | **Note:** It is recommended to deploy the capabilities in the following sequence in stages: * **Stage 1**: Anti-Malware * **Stage 2**: Anti-Bot, Anti-Ransomware, Behavioral Guard, Forensics, Threat Emulation, Anti-Exploit * **Stage 3**: Media Encryption, Port Protection, Firewall, Application Control * **Stage 4**: Full Disk Encryption, Remote Access VPN, Compliance |

List of reference document for procedures and best practices:

* [sk154052 - Harmony Endpoint (former SandBlast Agent) Best Practice Configuration](https://support.checkpoint.com/results/sk/sk154052)
* [sk153713 - Harmony Endpoint Security Client - Learning Mode To Best Practice](https://support.checkpoint.com/results/sk/sk153713)
* [sk153714 - Harmony Endpoint Learning Mode Configuration](https://support.checkpoint.com/results/sk/sk153714)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
