About External Identities

Applies To: AuthPoint Multi-Factor Authentication, AuthPoint Total Identity Security

In AuthPoint, you can synchronize users from Active Directory, Entra ID, or a Lightweight Directory Access Protocol (LDAP) database. This is a quick way to add users to AuthPoint that you already defined on your network.

To sync users from an external user database, you must add an external identity and create one or more queries. External identities connect to external user databases to get user account information and validate passwords.

There are two types of external identities:

LDAP

Use the Lightweight Directory Access Protocol (LDAP) external identity type to sync users from Active Directory or an LDAP database.

You must add LDAP external identities to the configuration for a Gateway, and install the AuthPoint Gateway on your corporate network in a location that has Internet access and that can connect to your LDAP server. The Gateway enables communication between WatchGuard Cloud and your Active Directory or LDAP database.

Entra ID

Use the Entra ID external identity type to sync specific users and groups from an Entra ID authentication domain in WatchGuard Cloud to AuthPoint. This type of external identity does not require the AuthPoint Gateway.

For each external identity, you must specify which users to sync. There are two ways to sync users:

  • Group Sync — Select the groups you want to sync users from and AuthPoint creates a query for you.
  • Advanced Queries — Create your own queries to specify which groups or users to sync.

After you add a group sync or an advanced query, AuthPoint syncs with your external user database at the next synchronization interval and creates an AuthPoint user account for each user that is found. If your query returns more users than you have available licenses, the sync only creates as many users as your license supports.

Users that do not have a first name, user name, or email address defined in the external user database are not included in the synchronization.

AuthPoint does not store passwords for synchronized users. When a synchronized user authenticates, AuthPoint sends the LDAP credentials to the domain controller for validation. After the domain controller validates the credentials, AuthPoint manages any other authentication options specified in the authentication policies.

When you create a query to find your users (manually or with group sync), you choose whether to have AuthPoint create a mobile token for the synced users and send an email to the synced users to activate their mobile token. AuthPoint does this by default. In most cases, we recommend that you assign a token to users and send them the Token Activation email. User accounts need a token to authenticate with AuthPoint. You might choose not to do this for users that use hardware tokens for authentication, or for service accounts that bypass MFA with basic authentication.

To assign a token and send the token activation email to a user that did not have a token created for them automatically, you must resend the Token Activation email. For more information, go to Resend Activation Email.

Quarantined Users

If you move or delete a user account in your LDAP database, the status of the linked AuthPoint user account changes to Quarantined. In the users list, Quarantined user accounts display a yellow icon next to the user name.

An AuthPoint user account can also be quarantined if the external identity was deleted or other domain information changed.

Quarantined user accounts cannot authenticate until you restore or move them back to their original location in the LDAP database. For more information, see Quarantined Users.

Migrate From On-Premise Active Directory to Entra

If you have an on-prem Active Directory and want to migrate to Entra ID to use AuthPoint MFA with Microsoft 365, you can complete the steps in this section or reach out to WatchGuard Support for assistance.

The process to migrate from Active Directory to Entra ID will result in downtime, and all users will have to delete their existing mobile tokens and activate new tokens.

To migrate from on-prem Active Directory to Entra ID:

  1. If your Microsoft 365 domain is federated, you must roll back the federation and change the status from federated to managed. For detailed steps to do this, refer to the Microsoft documentation or the Rollback Instructions section of our Microsoft 365 Integration with AuthPoint for Active Directory Users integration guide.
  2. Add an authentication domain to sync users from Entra ID to Directories and Domain Services in WatchGuard Cloud. For detailed steps, go to Add an Authentication Domain to WatchGuard Cloud.
  3. Add an Entra ID external identity to AuthPoint. For detailed instructions, go to the Sync Entra ID Users to AuthPoint AuthPoint help topic. Do not sync users to AuthPoint yet.
  4. Quarantine and delete your Active Directory users from AuthPoint. To do this, we recommend that you remove the user from their AD group to give them the Quarantine status in AuthPoint, then remove the user from AuthPoint. You can also enable the Quarantined Users Cleanup setting to automatically remove AD synced users.
  5. Sync the deleted Active Directory users from Entra ID to AuthPoint. AuthPoint sends the newly synced users an email to activate a new mobile token for authentication. Users must manually delete their previous mobile tokens.
  6. Complete the steps in the Microsoft 365 Integration with AuthPoint for Entra Users integration guide to set up AuthPoint as an external authentication method for Microsoft 365.

Related Topics

Sync Users from Active Directory or LDAP

Sync Entra ID Users to AuthPoint

Test the Connection to an LDAP External Identity