Skip to main content

Email Protection Service: Activating Check Point Email Protection

This guide walks you through activating / switching from Guardz in-house email protection to Check Point Email Protection (formerly Avanan).

⚠️ Running into issues during activation? See the Check Point Email Activation Troubleshooting article for a step-by-step decision tree covering the most common activation failures, error messages, and post-activation issues.

Please note:

  • Once switched, you cannot go back to the Guardz email protection

  • The migration needs to be performed for each customer individually

  • Activation supports only Google Chrome and Microsoft Edge.
    If activation fails or redirects to the Avanan login page, confirm using one of these browsers. Other browsers (like Firefox, Safari, or Brave) may block session cookies and cause the activation to fail.

  • Allow and block lists (excluding files) will be migrated automatically

  • For Google Workspace environments, ensure that one unallocated user license is available before starting activation — Check Point uses it to create the cloud-sec-av service account. This can be a Google Cloud Identity Free license; a paid Workspace seat is no longer required solely for this service user. The license cannot be assigned to an existing user and must remain active in Google as long as the service is in use (the user can be set to 'inactive' in Guardz). To verify availability before starting, go to Google Admin Console → Billing → Subscriptions and confirm at least one license shows as unallocated. If no license is available, an error will appear as follows:

Step 1: Open Email Protection Settings

  • Log in to Guardz platform

  • Navigate to ‘Security Controls’ and open the ‘Email Protection’ section

  • Locate the option for Check Point Email Protection

Step 2: Activate the Service

  • Click 'Activate'.

  • Review the information and click 'Activate' again. This click creates the following objects on Check Point side:

    • The MSP account (if does not exist yet)

    • The tenant for the relevant account

  • This process may take a couple of minutes to proceed to the next step.

Step 3: Select the Operation Mode

  • Choose whether to activate the service in 'Protect' or 'Monitor Only' mode

  • Refer to this article to learn more about the differences between the modes

Step 4: Protect (Authorize) the Tenant

  • Click the 'Authorize' button to kick off the process

  • Proceed with the consent process (granting the admin permissions).

  • If you are not an admin of the organization you are activating, use the Copy Link button to copy the authorization link and share it with the relevant admin so they can grant the required permissions.

  • Please note that at the end of this process, you will be prompted with a login screen for the Check Point portal. No further action is required in the Check Point portal at this stage. You can return to the Guardz portal to continue the activation process.

Step 5: Send Test Emails:

  • In low-traffic mailboxes, the Check Point onboarding process may be delayed. To accelerate completion, generate test email traffic by sending several emails to protected users.

  • Click on the 'Looks Good' button to exit the activation screen.

Step 6: Wait for Full Activation

  • Once steps #4 and #5 are successfully completed, the service automatically initiates the enablement process. The process continues in the background until activation is fully completed, with a loading spinner indicating that this is still in progress.

    • Admins may track the process also via Guardz platform. The Email Protection status will display as: Initiating → Learning → Active

    • During 'Learning Mode', the system calibrates its Anti-Phishing engine by analyzing up to 13 months of email metadata to understand communication patterns and detect upstream MTAs. Additional information can be found here

    • Additionally, during this stage all active Guardz users and shared mailboxes are automatically synced into the new tenant (new users will be added, and deactivated/suspended users will be removed automatically)

  • Once the status shows 'Active' (this process may take up to 3-5 days), your organization is fully protected by Check Point Email Protection

Once the status shows Active, the Portal Access option becomes available under Security Controls → Email Protection. Admins can then submit console access requests for users who need to access the Check Point portal.

✅ No manual per-user deployment needed: Once activation is complete, email protection is automatically applied to all active users in the customer's directory — you do not need to deploy it individually to each user. New users added after activation are synced and protected automatically. Shared mailboxes are also enrolled automatically during the activation process. If you want to verify which users are covered, review the user list under the customer's Users tab in Guardz.

Step 7: Review your Onboarded Customers

  • Select the ‘All Customers’ View

  • Navigate to ‘Security Controls’ tab and open the ‘Email Protection’ section

  • Review the status and type of each activated service for every customer


What’s Next?

Proceed to ‘Check Point Email Protection: Management, Configuring & Policies Handling’ article to handle the service settings. If you encountered any issues during activation, refer to the Check Point Email Activation Troubleshooting article.

Did this answer your question?