TrustRadius: an HG Insights company

WatchGuard AuthPoint

Score9 out of 10

441 Reviews and Ratings

What is WatchGuard AuthPoint?

WatchGuard AuthPoint protects workforce logins to desktops, VPNs, and cloud applications, from Windows and macOS sign-in to Microsoft 365 and third-party SaaS. It runs on WatchGuard Cloud, the same console that manages WatchGuard network and endpoint security. An MSP or an IT team can cover identity without adding another vendor to the stack.

When MFA alone is not enough
Day-to-day authentication runs through the AuthPoint mobile app, with push, QR code, or one-time password. QR and OTP work when the device has no network connection. Push notifications and passcodes can still be intercepted, or approved by a tired user. FIDO2 passkeys close that gap: a passkey works on the real login page and fails on a fake one. Each token is bound to the device that registered it, a mechanism WatchGuard calls Device DNA, so a copied token stops working. When someone floods a user with approval requests, ThreatSync, the correlation layer built into WatchGuard Cloud, detects the push abuse and can block the user or the source IP.

Where it applies
Windows and macOS logon, VPN and firewall access, and an SSO portal, with documented integrations for more than 130 third-party products across SAML, OIDC, and RADIUS. A WatchGuard firewall is not required: published integration guides cover Fortinet, SonicWall, Sophos, Palo Alto Networks, Cisco, and Check Point, among others. Passwordless sign-in with Windows Hello and macOS Touch ID is supported, and MFA can be required when a user elevates to administrator rights. Hardware tokens are available for users who cannot use a phone.

Microsoft environments
AuthPoint acts as external MFA for Microsoft Entra ID. That is the one capability that requires an Entra ID P1 license. Everything else runs on any Microsoft 365 plan. Deployment does not depend on how a customer licenses Microsoft.

User directories
Users synchronize from Active Directory, Microsoft Entra ID, or LDAP. A built-in cloud directory covers customers running none of the three, which is often the case in smaller organizations.

Managed alongside network and endpoint security
AuthPoint is multi-tenant from the first login, so a service provider adds a customer without standing up a separate instance. Identity events feed ThreatSync alongside network and endpoint data, so a suspicious login is seen next to what happened on the device and on the network.

What it costs
AuthPoint is priced per user, not per feature or per token, and WatchGuard sets no minimum user count. A 20-person firm and a 5,000-user enterprise get the same authentication set, so security does not depend on which tier a customer can afford. Subscription licensing removes the allocation step entirely: WatchGuard bills monthly through the distributor for active users, and a provider can set a limit on any managed account. A 30-day trial is available, and the authentication service carries a 99.99% uptime SLA.

Two license options
AuthPoint Multi-Factor Authentication covers authentication. AuthPoint Total Identity Security includes everything in the MFA product and adds Dark Web Credential Monitoring, which flags corporate and personal credentials found in breach data before an attacker uses them. An account runs on one license or the other.

Compliance
AuthPoint is delivered from WatchGuard Cloud, which is ISO/IEC 27001:2022 certified. FIDO2 passkeys meet AAL2 under NIST SP 800-63-4, the standard's authenticator assurance levels, and hardware-bound passkeys meet AAL3 for privileged users.
Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Screenshots

Screenshot of The AuthPoint console in WatchGuard Cloud: users, groups, protected resources, and blocked tokens at a glance.
Screenshot of Authentication activity across every protected resource: successful and failed logins, denied push notifications, and which users are active.
Screenshot of New users are set up by scanning a QR code from a welcome email. No manual token distribution.
Screenshot of The AuthPoint mobile app on first run. Users activate their token in a couple of taps.
Screenshot of The app holds every token a user needs, including third-party accounts like Microsoft and Google.
Screenshot of Approving a login with a push notification, the method most users rely on day to day.
Screenshot of Signing in with a FIDO2 passkey, which only works on the genuine login page.
Screenshot of QR code sign-in, which works even when the phone has no network connection.
Screenshot of The SSO portal, where users reach all their applications after a single sign-in.
Screenshot of Setting up AuthPoint as external MFA for Microsoft Entra ID.
Screenshot of Turning on Dark Web Credential Monitoring and choosing who gets notified when a breach is detected.
Screenshot of Dark Web Credential Monitoring flags which users have credentials in breach data, across every managed account.
Screenshot of The alert an administrator receives: which service was breached, what was exposed, and what to do about it.

1 / 13

Screenshot of The AuthPoint console in WatchGuard Cloud: users, groups, protected resources, and blocked tokens at a glance.

Technical Details

Technical Details
Deployment TypesSaaS
Mobile ApplicationApple iOS, Android, Mobile Web, Any smart phone, Any smart phone, Any smart phone
Supported CountriesNorth America, Latin America, Europe, Middle East, Africa, Asia Pacific
Supported LanguagesEnglish, Spanish, Brazilian Portuguese, Portuguese, German, Dutch, French, Italian, Japanese, Simplified Chinese, Traditional Chinese, Korean, Thai

FAQs

What are WatchGuard AuthPoint's top competitors?
Cisco Duo, Microsoft Entra ID, and Google Authenticator are common alternatives for WatchGuard AuthPoint.