Passly from ID Agent, a Kaseya company and the service that replaces the former AuthAnvil, is an identity and access management (IAM) platform providing two-factor authentication, single sign-on (SSO) and password management.
N/A
WatchGuard AuthPoint
Score 8.9 out of 10
N/A
AuthPoint Total Identity Security provides businesses with a solution to protect user accounts and credentials. With
multi-factor authentication and dark web credential
monitoring, AuthPoint mitigates the risks associated with workforce credential
attacks. AuthPoint adds an extra layer of security by monitoring for
potential credential exposure in the dark web for both personal and corporate
accounts.
If you have a skilled IT support team (whether in-house or outsourced) that is familiar with Kaseya's applications and has a good relationship with the vendor, it may be a good fit. It "checks the box" for 2FA, but there are much simpler solutions out there today that can get the same job done with less complexity and, in many cases, at a lower cost.
It is well suited to businesses with a mix of employees who work in the office and remotely. You can view how often they log in with the device. The authenticator app allows you to log in while the device is offline. I have been using AuthPoint with my business for 6 years and am happy.
Works well with the free Authpoint client and the OpenVPN clinet.
Token management is simple and hosted completely in the cloud to reduce overall complexity
Setup was simple and and staighforward
Suppports several authentication methods we have used both RADIUS and SAML effectively, but ADFS, IDP, RDWeb, and RESTful API, and other custom apps are supported.
Geofencing for RDP has been very useful as it is independant of our firewall geofencing. This is quite useful for organizations like us who do not Geofence at at the firewall level so as to provide global access to resources on the DMZ.
We frequently have people locked out because they type their one-time password into the QR code entry box. I wish we could choose to default to a one-time password for the organization. It would be even nicer if the OTP worked in the QR code box.
Being in the IT department, I have to set up many computers, which means I have to use Authpoint codes all the time. I wish there was a way to press a button at the top of the app and instantly refresh your codes. It takes forever when I'm signing into 20 different computers in a row because I have to wait for a new code to generate before I can sign into the next computer.
Today to ensure our ISO 27001 certification it is important that we maintain this solution. Today it is part of the way any employee within the organization works, we no longer have any other way of working and it is the simplest way to ensure that access to the workstation is done with MFA.
After initial setup, it practically runs itself. Onboarding new users is fast and easy as it should be. The AuthPoint mobile app is small and simple to use. The only reason I do not give it a 10 is that I frequently get complaints from end users that the AuthPoint app is "constantly downloading". In fact, it's not downloading anything and that what the users are seeing in the app is a timer for the 6-digit code that changes every minute.
They are very helpful with helping us with any issues. There are a lot of helpful guides online if you get lost. Kaseya is also good about not bugging you with notifications. Kaseya offers easy to access to support options. Overall I have not had to contact them over a lot of issues. The software rarely broke or was down for maintenance.
WatchGuard support is always quick and reliable. They have urgency levels that you are able to select when creating your support ticket, and they respond in accordance to the severity that you have set. I have never had an issue with getting someone on the phone in the same business day, even for very low priority issues.
It was an Onsite demo at the ditributor with the benefits of Watchguard Authpoint. Was very nice to see the abilities of the product. This Demo was a few years back, since then Authpoint changed allot. It is very nice for partners that you can get this demo without any aditional cost.
We use the online training for all our employees. There are both sales and technical trainings available and there even is a technical certification. You can use this for the Watchguard Partner Program which can give you aditional benefits. Every now and then you have a webinar that discusses multiple Watchguard products.
the first time it takes more effort. It is helpful to already understand how each authentication type works. Then it's much easier to understand the MFA solution that you implement. It is useful to check the release notes from time to time and update the key parts of the Watchguard Authpoint. Authpoint Gateway, Logon App, RDWeb... Also, it's useful to set up notifications when something goes wrong or sometimes check the statistics of how many requests are being approved/denied, etc.
I selected Passly at first as it would allow for a single sign on with azure to Kaseya VSA. Kaseya has made access to different products very different. VSA does not have single sign on with Azure where as Vorex/BMS does. This is a feature that Kaseya should make unified accross all applications.
I would slot Authpoint (as a product) as better than ESET but not Duo. ESET has the same limitations as Watchguard in the OTP support. It also is an on-prem installed console rather than a cloud, which increases cost and maintenance requirements. The duo now supports standard OTP for admin accounts, so it can be managed by a team. Duo support however leaves a lot to be desired and gives Watchguard the edge
Our end uses found this product very easy to use. Using one overview session, I have not had to follow up with users to access the product.
Once deployed, other users in our environment heard about the ease of use. We then had a 25% increase in requests for the product.
This product has added to the overall satisfaction of users having to work offsite, attend conferences and other travel while still being able to stay connected to their work product.