Delegated Token
To complete the required actions during automatic onboarding, such as creating groups and assigning a Global Admin role to the Check Point application, Email Security uses a delegated token from the authorizing user who approved the permissions.
If you choose to disconnect Email Security from Microsoft 365, Email Security executes the reverse actions, including deleting groups and disassociating roles. To do that, the Check Point Azure application must periodically refresh and maintain a valid delegated token.
The system initiates the refresh action on behalf of the authorizing user, and you can observe these activities in your Microsoft 365 audit log:
-
Periodic logins by the Check Point application on behalf of the user to refresh the token.
-
Failed login attempts in case the user no longer exists or the password has changed.
Note:These failed logins do not affect security or email delivery. However, when disconnecting Email Security from Microsoft 365, manual actions are necessary to eliminate its footprint.
To resolve this issue, re-authorize the Microsoft 365 application with the same or another Microsoft administrator credentials.
Click Security Settings > SaaS Applications.
Click Configure for Office 365 Mail.
Click Re-Authorize Check Point Office 365 Email App.
Follow the onscreen instructions and authorize the Microsoft 365 application.