FireCloud Authentication Settings

Applies To: FireCloud Internet Access, FireCloud Total Access

To configure FireCloud, you must set up an identity provider. An identity provider is an external system that you use to manage and authenticate your FireCloud users and groups. This is how FireCloud knows which users and groups are authorized, and how the users are authenticated when they connect to FireCloud.

Before You Begin

There are two ways to use AuthPoint MFA with FireCloud:

  • WatchGuard Cloud Directory — You can set up the WatchGuard Cloud Directory as your FireCloud identity provider. This method is easier, but it only supports AuthPoint MFA for users that you have added to the WatchGuard Cloud Directory.
  • AuthPoint SAML — You can set up AuthPoint as a SAML identity provider for FireCloud. This method supports MFA for all of your AuthPoint users.

Configure an Identity Provider in FireCloud

Before you can configure FireCloud policies, you must set up an identity provider to authenticate your FireCloud users and groups. You can use any identity provider that supports SAML, such as AuthPoint, Microsoft Entra ID (Azure Active Directory), or Okta.

To configure an identity provider in FireCloud:

  1. Log in to WatchGuard Cloud and select Configure > FireCloud.
  2. Select the type of identity provider to use and enter the required information:
  3. Click Save.

Provide FireCloud Information to Your Identity Provider (SAML Only)

If you configure a SAML identity provider, FireCloud generates a certificate that you can provide to your identity provider. This certificate gives your identity provider the information required to identify FireCloud and makes sure that your identity provider responds only to valid authentication requests sent by FireCloud. You can download this certificate from the FireCloud Authentication page.

Screenshot of the FireCloud authentication page with the FireCloud certificate.

We recommend that you import the FireCloud certificate to your identity provider and enable signature verification.

Your identity provider might have a different name for signature verification. For example, Okta calls this setting SAML Signed Request and Entra ID calls it Verification Certificates.

If you select to use AuthPoint as an identity provider, you must also create a SAML resource in AuthPoint for FireCloud, then add the SAML resource to your existing Zero Trust authentication policies or add new Zero Trust authentication policies for the SAML resource.

Control Access to FireCloud

If you connected FireCloud to an identity provider that has more users than will use FireCloud, you can control access to FireCloud so that only some users can connect to the service and consume a user license. To do this, you disable the default FireCloud access rule and configure access rules for only the user groups that you want to have access to FireCloud. Users that do not have an access rule cannot connect to the FireCloud service and consume a license.

You can also provide the FireCloud connection manager to only the end-users that you want to use the service.

Edit FireCloud Authentication Settings or Change Identity Provider

If you change your FireCloud identity provider, FireCloud deletes all your access rules because they no longer have any groups associated with them. FireCloud prompts you for confirmation before this happens.

The default access rule is not affected.

To edit the settings for your identity provider, or to change to a new identity provider, from WatchGuard Cloud:

  1. Select Configure > FireCloud.
  2. From the navigation menu, select Authentication.

Screenshot of the FireCloud authentication page with the optino to edit authentication settings highlighted.

  1. Click Edit Authentication Settings.
  2. Make your changes, then click Save.

Related Topics

Quick Start — Set Up FireCloud