Product and Support News

AuthPoint Passkeys for OIDC: Open Beta Now Available

We're excited to announce that Passkeys for OIDC in AuthPoint is now available in Open Beta, running from February 5th through February 19th.

What's new

AuthPoint now supports FIDO2 passkeys for OIDC-based resources. OIDC (OpenID Connect) is a widely-used authentication protocol that allows users to sign in to multiple applications with a single identity. With this release, users can authenticate to FireCloud, Microsoft External Authentication Methods, and any OIDC applications integrated through AuthPoint using passkeys.

Here's how it works: Users use biometrics (FaceID, TouchID, Windows Hello) or a device PIN to unlock their passkey, which then handles the authentication to the application. No passwords to remember or type.

Passkeys use both public and private key cryptography, where the private key stays on the user's device and is never transmitted and the public key is stored in AuthPoint. This cryptographic design provides phishing-resistant authentication.

Organizations are facing increased requirements for phishing-resistant MFA in compliance frameworks and cyber insurance policies. Passkeys meet these requirements while simplifying the user experience.

What partners need to know

The Passkey private keys are managed by the user's device platform: Apple iCloud Keychain, Google Password Manager, Windows WebAuthn, or hardware security keys like YubiKey. AuthPoint uses the public key to verify the cryptographic signature. Users don't need the AuthPoint mobile app to use passkeys.

When a user authenticates with a passkey, they've already satisfied MFA requirements through the combination of device possession and biometric or PIN verification. AuthPoint treats passkey authentication as complete.

Administrators control passkey availability per OIDC resource through Zero Trust Policies in WatchGuard Cloud. You can roll out passkeys gradually, test specific applications, or enforce them for high-security resources while keeping other authentication options available for different use case.

Join the beta

Access it through WatchGuard Center Code, where you'll find instructions for getting started and reference materials.

We're looking for feedback on deployment scenarios, user experience, and how you're positioning this capability with customers. You can submit your feedback directly through Center Code.

Passkeys are included with both MFA and Total Identity Security licenses at no additional cost.

For technical questions during the beta, reach out through the usual support channels.

Filed under: Authentication