One phished password opens the VPN, the mailbox and the server. It shouldn’t open anything on its own — WatchGuard AuthPoint asks for a push, code or passkey before staff reach a desktop, the VPN or a web app, with policy held in WatchGuard Cloud and a Windows Server gateway for RADIUS, LDAP and ADFS.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers WatchGuard AuthPoint — AuthPoint MFA and the Total Identity Security tier, which adds Dark Web Credential Monitoring. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A second proof beyond the password — a push, a code or a passkey — before an employee reaches a desktop, VPN or app.
What consolidation actually replaces, dimension by dimension.
| Dimension | Passwords plus a VPN token | WatchGuard AuthPoint |
|---|---|---|
| What a stolen password opens | The VPN, the mailbox and any desktop | Nothing on its own; a factor is also needed |
| Desktop and RDP sign-in | Password only, often shared on servers | Logon app asks for push, OTP or QR code |
| VPN second factor | A separate token system per gateway | RADIUS through the AuthPoint gateway |
| Phishing-resistant option | None; codes can be typed into a fake page | FIDO2 passkeys on SAML and OIDC resources |
| Leaked credentials | Found out after the breach | Dark-web alerts with Total Identity Security |
| What it is NOT | — | A directory, governance suite or Indian-hosted cloud |
The cheapest test is a pilot group: protect the VPN over RADIUS and one SAML app, enrol IT and finance, and require passkeys for the admins.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Resources, users, groups and Zero Trust policies are set in WatchGuard Cloud, the multi-tenant console partners also use for Firebox, endpoint and FireCloud.
The app approves pushes, shows one-time codes and scans QR codes; each token is bound to the phone’s device DNA, so WatchGuard says a cloned phone is refused.
A gateway on Windows Server answers RADIUS from VPNs and firewalls, syncs LDAP users and serves ADFS; up to five secondaries step in when the primary is down.
Installed on Windows or macOS, it asks for a factor at local and domain sign-in, RDP, RD Gateway and Windows UAC prompts, with offline OTP or QR codes.
Policy in WatchGuard Cloud, a token on the phone — and a Windows gateway that carries RADIUS, LDAP and ADFS on site.
WatchGuard AuthPoint puts one phone app in front of desktop, VPN and web sign-ins, managed from WatchGuard Cloud.
A push reaches the AuthPoint app with the request details, and the user approves or denies it on a token tied to that phone.
Passkeys in iCloud Keychain, Google Password Manager, Windows or a YubiKey count as full MFA on OIDC and SAML resources.
On a computer with no connection, the Logon app takes a one-time password or a QR scan, if the policy sets no location rule.
Logon apps put a second factor in front of local and domain sign-in, RDP sessions, RD Gateway and Windows elevation prompts.
The Windows Server gateway is a RADIUS server on TCP ports 9000–9003, so firewalls and VPN appliances can ask AuthPoint for MFA.
Microsoft Entra ID can hand its second factor to AuthPoint as certified External MFA, so Microsoft 365 users keep one app.
Zero Trust policies choose the factors each resource needs, with network location, geofence and time conditions per group.
An IdP portal lists SAML and OIDC apps for single sign-on, and since August 2026 one session spans both protocols.
Total Identity Security scans breach data for staff credentials, names the affected accounts and can tell users to change passwords.
WatchGuard’s 2026 short on stolen passwords, the AuthPoint SSO portal for MSPs (2024) and a geofence policy demo (2021). All from WatchGuard’s official channel.
WatchGuard’s 2026 short on why a single stolen password should never be enough to get inside.
Why WatchGuard pairs the AuthPoint single sign-on portal with MFA for partners running many tenants.
A 2021 walk-through of a geofence policy; the console has moved on, but location conditions remain.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Many MFA tools stop at the browser. AuthPoint’s Logon apps cover Windows and macOS sign-in, RDP and RD Gateway, its gateway answers RADIUS for the VPN, and SAML or OIDC apps sit behind the same push. One enrolment on the phone covers every path, which suits a small IT team.
FIDO2 passkeys reached OIDC apps early in 2026 and SAML resources in May 2026. A passkey on a phone, laptop or YubiKey counts as complete MFA, and one enrolment also unlocks FireCloud and Entra ID External MFA, so phishing-resistant sign-in can start with admins and finance.
AuthPoint lives in WatchGuard Cloud, the multi-tenant console WatchGuard partners already use for Firebox and endpoint. Since June 2026 a provider can push Logon apps through the WatchGuard Agent, and service-provider accounts can pass users down to customer accounts.
There is no list price and no Indian cloud region: tenants sit in the USA, Germany or Japan. The gateway runs only on Windows Server, and the Logon app skips Windows Core and ARM machines. It is MFA with an SSO portal, not a directory replacement or identity governance, and no analyst has rated it.
Note each VPN, RDP host, desktop fleet and SAML or OIDC app, and which directory holds the users today.
Agree the WatchGuard Cloud region with your partner and build a Windows Server for the gateway, plus a secondary.
Enrol a small group on the app, protect the VPN over RADIUS and one cloud app, and test offline codes on a laptop.
Push Logon apps through the WatchGuard Agent, then require passkeys for admins on SAML and OIDC resources.
Enrol everyone, add location and time rules per group, and decide whether dark-web checks justify the higher tier.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our Firebox already sat in WatchGuard Cloud, so pointing the SSL VPN at the AuthPoint gateway took one afternoon.”
“Field engineers log into laptops on site with no signal. The offline QR code saved us from a support call every week.”
“We made passkeys mandatory for the finance team on our SAML apps first; the rest of staff still use push for now.”
“Putting a factor on RDP and the Windows admin prompt closed the gap our auditors flagged on shared servers.”
“Run a second gateway from day one. When our only Windows server rebooted for patches, VPN logins simply stopped.”
“It works well, but I could not get a price without a partner call, and the data sits outside India.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the workforce MFA market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per user through partners; no list price.
The grid nobody publishes — how far a product reaches into on-site sign-ins (RADIUS, LDAP, desktops, offline) vs how strong its documented factors and policies are.
Windows gateway, Logon apps, Entra EAM; passkeys in 2026.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Duo, Okta Adaptive MFA, miniOrange MFA, Akamai MFA and Fortinet FortiAuthenticator — on factors, passkeys, price, policy, VPN and desktop reach, exit and India.
| Dimension | WatchGuard AuthPoint | Cisco Duo | Okta Adaptive MFA | miniOrange MFA | Akamai MFA | Fortinet FortiAuthenticator |
|---|---|---|---|---|---|---|
| What it is | Cloud MFA for partners | MFA grown into Duo IAM | MFA inside Okta suites | Pune-built MFA | Phone-as-key MFA | Fortinet auth appliance |
| Deployment | SaaS + Windows gateway | Cloud service | SaaS only | Cloud or your servers | Akamai service + gateway | Appliance or VM |
| Factor range | Push, OTP, QR, keys | Push-first, passwordless | Okta Verify and WebAuthn | More than 15 methods | FIDO2 phone, push, SMS | FortiToken, FIDO2, certs |
| Phishing-resistant | Passkeys, SAML and OIDC | FIDO2 recorded | Keys and passkeys | Passkeys in the list | Phone is the FIDO2 key | FIDO2 plus certificates |
| Pricing model | Per user, via partners | Per user, four tiers | Part of a suite | Per user, rupee tiers | Own SKU, quoted | By user capacity |
| Published entry price | No list; reseller $28.50 | Free to 10; then $3 | $14 suite or $6 add-on | From ₹180 a user | Trial, then quote | Partner quote |
| Included vs add-on | Dark web is a tier up | Device trust higher up | Depth tied to the suite | Adaptive in fuller tiers | Access products apart | Tokens extra |
| Adaptive policy | Location, time, group | Device health gates | Risk-scored step-up | Adaptive, less deep | Posture and lockout | Basic conditions |
| Directory and IdP | AD sync, Entra EAM | Any IdP behind it | Okta at the centre | Its SSO, ADFS, sync | Okta, Entra, Ping, ADFS | Its own authority |
| VPN and RADIUS | Gateway on 9000–9003 | VPN is home ground | RADIUS supported | VPN and RDP covered | PacketFence for RADIUS | Full RADIUS server |
| Desktop and RDP logon | Windows, macOS, offline | RDP and in-house apps | Windows, RDP, SSH | Windows and Mac | Windows plugin, Unix PAM | Network first |
| India data region | USA, Germany or Japan | Not documented | India tenants, 2026 | Indian vendor, on-prem | No region stated | Where you host it |
| Lock-in and exit | Re-enrol; IdP stays | Directory untouched | Leave Okta, lose MFA | Data on your servers | Second factor only | Tied to the fabric |
| Best fit | WatchGuard-run estates | VPN and RDP everywhere | Okta customers | Rupee budgets, on-prem | Keyless FIDO2 rollout | Fortinet shops |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
WatchGuard AuthPoint is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users who sign in; IT staff-hour cost). Estimates model the IT time spent on password resets, lockouts and cleaning up after compromised accounts, at an assumed 1.5 hours per user a year, with 70% of it removed by MFA on every sign-in. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. WatchGuard publishes no price for AuthPoint, keeps its SKU list behind the partner portal and sells only through partners and MSPs, who license it per user. As a rough guide, one US reseller lists $28.50 per user a year for 1 to 50 users — a US reseller figure, not a WatchGuard list price and not an Indian one. Total Identity Security, which adds Dark Web Credential Monitoring, is quoted higher. In India WatchGuard’s contact page names RoundRobin Tech Services, Mumbai, as distributor. TechBag maps your sign-in paths first, then quotes in INR with GST.
Best for MFA on desktops, VPN and web apps
Best for a broader rollout
Best when leaked passwords are a known risk
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Have you listed every VPN, RDP host, desktop group and web app that needs a factor, and how each one authenticates?
Will users come from AD or LDAP through the gateway, from Entra ID, or from WatchGuard Cloud’s own directory?
Do you have a supported Windows Server for the gateway, and a second one so RADIUS survives a reboot?
Are any machines Windows Core, ARM-based or Windows 7 and older? The Logon app does not cover those.
Which accounts must use passkeys, and do their phones, laptops or hardware keys support FIDO2 today?
Which WatchGuard Cloud region will hold your tenant, and does your policy accept data stored outside India?
Do you need Dark Web Credential Monitoring, which means Total Identity Security rather than AuthPoint MFA alone?
Does the partner quote state users, term, tier and support? Ask for INR with GST and the user band the price assumes.
List the desktops, VPNs and apps that need a second factor first, or let a TechBag advisor plan the gateway, settle the cloud region question and get a partner quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.