Use in Healthcare for VPN MFA by IT department employee
Use Cases and Deployment Scope
We use WatchGuard AuthPoint as the Multi-Factor Authentication method for connecting to Forticlient VPN so our end users can connect to our network remotely to access company resources securely.
This is used by all our end users with little to no technical expertise. I've found the set up for Authpoint to be very easy for the average person to follow, and though I've created 'guides' to walk people through the process, they typically do not need it as WatchGuard AuthPoint does an excellent job at walking people through the process alone.
Pros
- Easy to setup
- Quick to setup and use
- Works consistently
- Easy to reset token's when someone gets a new phone
- Website is secure and requires MFA to sign on
- App can enable MFA requirement to open and approve a push notification
- App is easy to use
Cons
- When adding a token, some people are confused by the 'token name'. A little blurb to say "This is just for your reference! You can make this the name of your company or the service that it provides MFA for" would be excellent.
- I've had some people express confusion about the "red bar that keeps refilling and the 6-digit number that keeps changing". Some sort of statement to explain that would be great.
- First-time use navigation - point out where the QR code scanning button is (I've managed to get a screenshot of the app to highlight it for our end users so they can find it easier).
Likelihood to Recommend
We use multiple authenticators at my company. We use WatchGuard AuthPoint just for our VPN for security purposes. The app works very well and over the past year we've only had a handful of issues with the authentication service, and these were resolved relatively quickly.
We do have to remind people to enable push notifications from the app, or have the app open when they need to use it to authenticate, otherwise they won't get the push to approve. The biggest issue I've found is that people will forget to do this and then say that the VPN isn't working - the VPN is working, it's just that they didn't get/approve the push from AuthPoint in time.
