WatchGuard Blog: Authentication
https://www.watchguard.com/
WatchGuard Product Update BlogenAuthPoint MFA is now available for Windows Hello
https://www.watchguard.com/wgrd-blog/authpoint-mfa-now-available-windows-hello
<p>The AuthPoint MFA Agent for Windows has been updated to include support for Windows Hello for Business. This version now offers the capability to add AuthPoint MFA methods of verification for computers and servers enrolled in Windows Hello for Business. Passwordless support from Hello includes fingerprint, face recognition, and PIN (fallback), and then users will verify their identity with Push, QR code, or OTP from AuthPoint MFA. </p>
<p>Remember that the MFA options for Windows Hello can also be combined with Policy Objects (Time Schedule, Network Locations, Geofence and Geokinetics), so you have the flexibility to configure the security level that best matches your requirements. If you need more information about Policy Objects usage, <a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/policy-objects_about.html">check here</a>.</p>
<p>Additionally, credential provider wrapping is supported to enable service providers to load SpecOps Password Policy Tool together with this version of the AuthPoint MFA Windows Logon Agent for clients that are not enrolled in Windows Hello for Business.</p>
<p>The installer is available in the Downloads page of your AuthPoint account. You can install it on new machines or upgrade existing ones using the same deploy method of the previous agent versions, manually or silently, with any software distribution tool of your preference.</p>
<p>See the <a href="http://watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/logon-app_about.html">Help Center article</a> for detailed steps to configure or install the Logon app.</p>
Mon, 24 Jul 2023 06:39:37 -0700Fabio Mansur84896 at https://www.watchguard.comNew AuthPoint product: AuthPoint Total Identity Security
https://www.watchguard.com/wgrd-blog/new-authpoint-product-authpoint-total-identity-security
<p>We are launching AuthPoint Total Identity Security, a new product bundle from the AuthPoint product line, which offers:</p>
<ul><li><strong>AuthPoint MFA</strong> – Deploy a complete multi-factor authentication solution with single sign-on (SSO) and risk-based authentication that’s easy to manage and use. AuthPoint MFA service is also available for purchase separately.</li>
<li><strong>Dark Web Monitor</strong> – Get notified when compromised credentials from monitored domains are found on the dark web and published to credentials databases.</li>
<li><strong>Corporate Password Manager</strong> – Improve password quality, reduce resets, and mitigate risk from shared or stolen passwords. Our Corporate Password Manager creates strong, complex passwords and provides the enforcement controls and shared vaults that businesses need.</li>
</ul><p>Total Identity Security enables customers to protect their users’ accounts and credentials regardless of whether they have fully adopted multi-factor authentication, plus add a new layer of protection by monitoring for potential credential exposure in the dark web for both personal and corporate accounts.</p>
<p><strong>Dark Web Monitoring</strong></p>
<p>The Dark Web Monitor is a proactive service that notifies both administrators and end-users when compromised credentials from monitored domains are found in a newly acquired credentials database that is published to the WatchGuard Dark Web service.</p>
<p><strong>Password Manager</strong></p>
<p>A corporate password manager gives companies more control over password quality, reduce the need for password resets, and can help to mitigate issues related to shared, reused, and stolen passwords.</p>
<p>With WatchGuard’s Corporate Password Manager, when users need to access their apps or systems, they can retrieve their passwords using the AuthPoint mobile app, available for iOS and Android and browser extension, available for all major browsers. This allows businesses to add non-SAML Cloud applications to the Application Portal to fill out credentials automatically (forms-based authentication) for a smooth SSO experience.</p>
<p><strong>Try it now</strong></p>
<p>Talk to your partner or go to your WatchGuard account and access the Trials page for a one-click trial experience to start using it. You can even try the AuthPoint Total Identity Security in the same account that you already have an active AuthPoint MFA license.</p>
<p>To know more about it, <a href="https://www.watchguard.com/wgrd-resource-center/docs/authpoint">click here</a>.:</p>
Thu, 13 Jul 2023 15:11:34 -0700Fabio Mansur84641 at https://www.watchguard.comNew AuthPoint Feature: Email Activation Control
https://www.watchguard.com/wgrd-blog/new-authpoint-feature-email-activation-control
<p>We are improving the token activation process by adding new configuration options for operators. The email activation control feature helps to better match the user token activation flow with customer needs, as in the following scenarios:</p>
<ul><li>Customers that are using Office with MFA and their users don’t have access to the email to activate the token. Instead, they activate through the applications portal. </li>
<li>Customers that are using hardware tokens. In this case, the activation does not require the email. </li>
<li>Customers are doing an initial setup, creating users, but will configure the resources later, so the activation email must be sent later.</li>
</ul><p>The new configuration options are available when creating a user or configuring the synchronization from Active Directory or Azure:</p>
<ul><li>Disable automatic assignment of a mobile token to new users,</li>
<li>Disable automatic activation emails to new users.</li>
</ul><p>These options combined with the capability of users to activate tokens using the single sign-on (SSO) applications portal helps admins prioritize customer needs and improves token management, as well as process optimization. We aim to improve organizations' access control processes and enhance their security mechanisms while keeping intruders at bay.</p>
Thu, 29 Jun 2023 06:59:07 -0700Fabio Mansur84221 at https://www.watchguard.comAuthPoint Push Phishing Toggle
https://www.watchguard.com/wgrd-blog/authpoint-push-phishing-toggle
<p>Phishing is a very well-known technique of social engineer attack used by hackers to access user’s and companies´ sensitive information. Phishing is usually applicable for password compromise and malware, but an emerging threat is a technique called MFA fatigue or MFA push spam. The technique consists of an attacker, that has the credential information of a user (username and password), to send a consecutive, stream of push notifications to the user’s phone, until he approves one of them.</p>
<p>To mitigate this kind of attack, we have added a push phishing toggle feature on the AuthPoint mobile app. After a push notification is received on the app, recognized as a non-legit request by the user and denied, he can choose to disable the reception of new push notifications on his mobile to avoid the push fatigue and minimizing the chance to approve incorrectly an authentication request. At any time, the user can enable again the receiving of new push notifications.</p>
<div class="align-center">
<div class="field field--name-field-media-image field--type-image field--label-hidden field__item"> <img loading="lazy" src="/sites/default/files/styles/blog_large/public/blog-images/push_toggle.PNG?itok=2cTuIwR_" width="176" height="293" alt="AuthPoint option to enable Push Phishing Toggle" class="image-style-blog-large" /></div>
</div>
<h3>Combine with authentication policies for better protection!</h3>
<p>The push phishing or push fatigue can be a relatively easy way for attackers to get access to companies’ assets. Allow a user to disable push notifications is one more tool to help companies to prevent unauthorized access. Combined with other features, like policy restriction (for example, time policy to not allow user access after working hours or during weekends and geo kinetics, to automatically deny authentications done from different locations/small time interval), AuthPoint provides options to minimize the occurrence of this kind of attack.</p>
<p>Check if your mobile app has been updated to version 2.1.0 (Android or iOS) to take advantage of this new feature and learn more about AuthPoint:</p>
<p><a href="https://watchguard.widen.net/view/pdf/jjcbtlth17/eBook_Risk_Based_AuthPoint_Co-brand.pdf?t.download=true&x.share=t">Read AuthPoint Zero-Trust Framework eBook ></a></p>
<p><a href="https://watchguard.widen.net/view/pdf/2zvehyjlrf/PartnerBrief_AuthPoint?t.download=true&x.share=true&x.portal_shortcode_generated=ipkdxdyq&x.app=portals">Read AuthPoint Partner Brief ></a></p>
Thu, 11 May 2023 11:27:52 -0700Fabio Mansur82001 at https://www.watchguard.comNew AuthPoint Geokinetics Policy in WatchGuard Cloud
https://www.watchguard.com/wgrd-blog/new-authpoint-geokinetics-policy-watchguard-cloud
<p>As part of AuthPoint’s Zero-Trust Framework, a new policy is now available in WatchGuard Cloud. The goal of the Geokinetics policy is to prevent unexpected authentications from attackers that are distant from the authorized user. For example, if the user is in the U.S., and an attacker from a different geographic location tries to authenticate with the user’s credentials, this policy can block the attackers request, even if the user is subject to phishing or social engineering and is convinced by the attacker to approve a push notification or a one-time password (OTP).</p>
<h3>Empowering Your MFA Selling Strategy with AuthPoint’s Zero-Trust Framework</h3>
<p>Take advantage of advanced features like risk policies to ace more multi-factor authentication (MFA) deals. Risk policies enable you to manage authentication requirements based on your customers’ security needs. Choose to strengthen or streamline the authentication experience according to the level of risk and type of user.</p>
<p><strong>How is this policy different from other policies?</strong> The geokinetics policy compares the user’s device location on consecutive authentications and checks the distance and time between them. It can automatically block an authentication that does not match the configured parameters set by the operator.</p>
<p>Currently, the following AuthPoint policy objects are available in WatchGuard Cloud:</p>
<ul><li>IP Location</li>
<li>Geolocation</li>
<li>Time Schedule</li>
<li>Geokinetics</li>
</ul><p>Remember that the combination of the existing policies provides more flexibility and more powerful configurations, tailored to your end users’ needs.</p>
<h4>Learn more about AuthPoint</h4>
<p><a href="https://watchguard.widen.net/view/pdf/jjcbtlth17/eBook_Risk_Based_AuthPoint_Co-brand.pdf?t.download=true&x.share=t">Read AuthPoint Zero-Trust Framework eBook ></a></p>
<p><a href="https://watchguard.widen.net/view/pdf/2zvehyjlrf/PartnerBrief_AuthPoint?t.download=true&x.share=true&x.portal_shortcode_generated=ipkdxdyq&x.app=portals">Read AuthPoint Partner Brief ></a></p>
Tue, 06 Dec 2022 09:00:00 -0800Fabio Mansur73031 at https://www.watchguard.comNew AuthPoint Gateway Agent 7.1
https://www.watchguard.com/wgrd-blog/new-authpoint-gateway-agent-71
<p>A new gateway agent is available in WatchGuard Cloud. The new version addresses bug fixes, Open Source Scanning (OSS) improvements and better performance on the LDAP sync flow and on the overall gateway operations.</p>
<p>Always keep your environment with the latest AuthPoint Gateway version:</p>
<ol><li>Download the updated version in WatchGuard Cloud</li>
<li>Run the installer to upgrade your installed Gateway. For detailed instructions to update an installed Gateway, see <a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/gateway_update.html">Update an Installed Gateway </a>.</li>
</ol><p>Note: We recommend that you upgrade all your primary and secondary Gateways. The steps to upgrade a secondary Gateway are the same as the steps to upgrade a primary Gateway.</p>
<p>For more details, read the <a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/gateways.html">AuthPoint Gateways</a> Help Center article. </p>
Mon, 07 Nov 2022 10:37:36 -0800Fabio Mansur72111 at https://www.watchguard.comNew Versions Available for ADFS and RD Web AuthPoint Agents
https://www.watchguard.com/wgrd-blog/new-versions-available-adfs-and-rd-web-authpoint-agents
<p>New versions of the agents for ADFS and RD Web are now available from your AuthPoint downloads page in WatchGuard Cloud, fixing minor issues and improvements. These updates help us maintain our applications on track with the latest vulnerability prevention practices.</p>
<h3>New versions available</h3>
<ul><li>ADFS 1.2.1</li>
<li>RD Web 1.2.6<br />
</li>
</ul><h3>Recommended actions for partners and customers</h3>
<p>Although this is not a mandatory upgrade, we recommend you keep your agents always updated, not only to support new features, but also to keep up with the most stable versions with stability and performance improvements.</p>
Thu, 29 Sep 2022 10:00:00 -0700Fabio Mansur70066 at https://www.watchguard.comNew Beta alert! Take your passwords security to a new level
https://www.watchguard.com/wgrd-blog/new-beta-alert-take-your-passwords-security-new-level
<p>Lack of password management is exposing companies to credentials theft. Our AuthPoint MFA helps to mitigate issues related to user authentication, and passwords are indeed one of those factors. They need to be protected as well. To help you and your customers protect passwords, we are launching AuthPoint Total Identity Security.</p>
<p>Total Identity Security is our new authentication product that, besides all the AuthPoint capabilities you already use today (like authentication, policies, user and risk management), includes two other sets of features:</p>
<ul><li><strong>Dark Web Monitor:</strong> a tool that notifies users and administrators if their corporate credentials ended up in the dark web, through a new leaked database. This allows you to be proactive and change the password, even if it wasn’t necessarily cracked.</li>
<li><strong>Business Password Manager:</strong> a tool that allows your company to engage users on redefining their business passwords, using unique, complex and virtually impossible-to-crack passwords for each service requiring it. Integrated with the AuthPoint Mobile App and Web SSO to sites and corporate applications not natively supporting MFA. Cloud applications can be integrated into the IdP portal, so the credentials for these are filled out automatically (forms-based authentication), giving the SSO experience. It helps to:
<ul><li>Reduce credentials management costs</li>
<li>Increase user adoption of identity protection</li>
<li>Reduce exposure related to credential theft (phishing, dark web, social engineering, etc.)</li>
</ul></li>
</ul><p>And this is not the only news. To try AuthPoint Total Identity Security features, you can set trial licenses for yourself and your customers directly in WatchGuard Cloud, with our simple and integrated WatchGuard Cloud Trials Center.</p>
<p>Check the beta details in <a href="https://watchguard.centercode.com/key/TotalIdentitySecurity">Total Identity Security - Beta</a> and start taking advantage of AuthPoint Total Identity Security!</p>
Fri, 27 May 2022 09:00:00 -0700Fabio Mansur66916 at https://www.watchguard.comNew AuthPoint SAML Integration Makes Web Single Sign On (SSO) More Efficient
https://www.watchguard.com/wgrd-blog/new-authpoint-saml-integration-makes-web-single-sign-sso-more
<p>AuthPoint now offers a SAML integration that allows admins to add custom attributes directly into the generic SAML resource configuration, which provides additional integration capabilities outside of documented integrations.</p>
<p>This feature will give partners, customers and prospects a great flexibility and speed when adding new protected resources. For example, Multiple out-of-the-box optional attributes are available, such as e-mail, first name, groups, or just a fixed value.</p>
<h2>Key benefits for AuthPoint admins</h2>
<ul><li><strong>Quick and fast deployment when needed:</strong> Most SAML-based integrations can now be easily integrated, even if not tested yet by our ecosystem team</li>
<li><strong>Usability:</strong> You can now select an icon of your choice for generic SAML integrations, making it easier for users to identify and access the application</li>
</ul><h2>About AuthPoint integrations</h2>
<p>SAML is a business-oriented protocol that creates a trust relationship between the Cloud application, such as Microsoft 365, Salesforce, Tableau, and more, with an identity provider (like an MFA solution).</p>
<p>AuthPoint provides more than 150 document integrations with third-party solutions that use the SAML protocol, including Cloud applications. However, adding a SAML integration helps meet needs that sometimes-documented integrations fail to do, due to specific attributes that some Cloud vendors require. For use cases like this one, we are giving admins the ability to build customized integrations.</p>
<p>No urgent action is required for the Cloud/SAML applications that have been configured, but admins can now switch the icon to one that better identifies the application.</p>
Wed, 16 Mar 2022 07:37:22 -0700Fabio Mansur62971 at https://www.watchguard.comNew AuthPoint policy: Geofence
https://www.watchguard.com/wgrd-blog/new-authpoint-policy-geofence
<p>Earlier this year, we launched the AuthPoint Risk Framework, a powerful and flexible way to manage authentication policies, and on our continuous path towards Zero Trust, we have added policies for Network Location (policies based on the end user´s network) and Time Schedule (based on the day and time of the authentication attempt). We are now happy to announce that we have launched the first or our geo-based policies, the Geofence.</p>
<p>With the Geofence, administrators can create rules based on the user’s location to limit exposure and block attempts that come from unauthorized areas. For example, they can choose to give sales teams access to a CRM application from anywhere in the world, except for countries where the company doesn’t offer services or has staff. A call center application could have access limited only to the country where the team is located. </p>
<h2>How Geofencing Works<strong> </strong></h2>
<p>User geolocation can be determined based on IP address origin or based on GPS, which uses device location (mobile or computer). The latter provides a more precise location. Enforcing the use of GPS can be a good idea for critical applications but requires users to accept it. </p>
<h2>Upgrade the agents</h2>
<p>To support the Geofence, the newest versions of the agents must be installed, or the existing ones must be upgraded. The most updated versions are available at WatchGuard Cloud:</p>
<ul><li>Agents for Windows 2.7.1</li>
<li>Agent for Mac 1.11.0</li>
<li>Gateway 7.0.1</li>
<li>ADFS 1.2.0</li>
<li>RD Web 1.2.4</li>
</ul><p>Remember to keep your agents and Gateway always updated, not only to support new features, but also to keep up with the most stable versions with stability and performance improvements.</p>
<p>We continue to work on adding new risk policies to provide a stronger risk-based authentication framework to AuthPoint users. Stay tuned as we prepare to release the next geo-based policies!</p>
Tue, 21 Dec 2021 05:50:46 -0800Fabio Mansur59331 at https://www.watchguard.comNew AuthPoint Gateway 7.0 Available
https://www.watchguard.com/wgrd-blog/new-authpoint-gateway-70-available
<p>The AuthPoint Gateway is an on-premise, lightweight software that runs on Windows, that provides four main functionalities:</p>
<ul><li>User and group sync with Active Directory or any LDAP service</li>
<li>User authentication with Active Directory or LDAP</li>
<li>RADIUS server interface to firewalls and remote access gateways</li>
<li>Active Directory Federation Services (ADFS) proxy to WatchGuard Cloud (WGC)</li>
</ul><p>The new version of the AuthPoint gateway has redesigned engines and advanced connection management to improve performance and availability. It’s compatible with Java Development Kits (JDK) and Amazon Corretto (log in to WatchGuard Cloud and view the AuthPoint Download section for supported versions).</p>
<p><strong>Action for Partners and Customers: </strong>Install the New Version! Install new gateway to avoid connectivity or management issues due to using outdated gateways.</p>
<p>The AuthPoint Gateway is easy to install. It just requires a connection key that is inputted during the installation. All configuration is done through the Cloud and if you are upgrading from an older version, simply execute the installer.</p>
Fri, 03 Dec 2021 09:59:52 -0800Sam Manjarres58311 at https://www.watchguard.comAuthPoint Agent for MacOS Monterey is released!
https://www.watchguard.com/wgrd-blog/authpoint-agent-macos-monterey-released
<p>We are happy to announce that a new version of the AuthPoint Agent for MacOS, supporting the new MacOS Monterey 12.0.1, is now available through WatchGuard Cloud.</p>
<p>Version 1.11.0.92 of the agent can be downloaded through the "Downloads" section of AuthPoint management. Make sure to upgrade your agent to this new version, before updating your MacOS to Monterey.</p>
<p>Thanks for your support and patience, we are working hard to make sure we can deliver new versions prior to the launch of new operating systems.</p>
<p>And if you haven't done so, please check out our AuthPoint Betas, currently with the AuthPoint Gateway 7, and our new Risk-Based authentication feature: Geofence. Just login to Centercode and join our beta program!</p>
Thu, 11 Nov 2021 04:39:38 -0800Alexandre Cagnoni57626 at https://www.watchguard.comAuthPoint Inherited Users
https://www.watchguard.com/wgrd-blog/authpoint-inherited-users
<p>As a Service Provider, you might manage dozens of customer accounts and need access to your customers' systems and environments, such as a VPN or a server. With the user inheritance feature, you can request that customer accounts inherit an AuthPoint user from your account. These inherited users can then authenticate to access the customer’s resources. User inheritance provides a number of advantages:</p>
<ul><li>More flexibility to manage your accounts</li>
<li>Your team can access customer accounts with their existing tokens</li>
<li>Centralized control of users that access customer accounts</li>
<li>Reduced license costs (inherited users don’t consume a license)</li>
</ul><p>User Inheritance currently supports child accounts, and soon delegated accounts as well. Take a look at this new powerful feature, and set up user inheritance for your analysts in less than a minute!</p>
Thu, 19 Aug 2021 06:49:44 -0700Fabio Mansur53776 at https://www.watchguard.comAuthPoint Inherited Users Beta
https://www.watchguard.com/wgrd-blog/authpoint-inherited-users-beta
<p>As a Service Provider, you might manage dozens of customer accounts and need access to your customer’s systems and environments, such as a VPN or a server. With the user inheritance feature, you can request that customer accounts inherit an AuthPoint user from your account. These inherited users can then authenticate to access the customer’s resources. User inheritance provides a number of advantages:</p>
<ul><li>More flexibility to manage your accounts</li>
<li>Your team can access customer accounts with their existing tokens</li>
<li>Centralized control of users that access customer accounts</li>
<li>Reduced license costs (inherited users don’t consume a license)</li>
</ul><p><a href="https://watchguard.centercode.com/project/article/item.html?cap=e83c23aa2700430e8ba6bdc1c36385bf&arttypeid=%7b7CD1AB80-7AE6-4ACC-A7CC-D3ABC5A8B142%7d&artid=%7bD33900F6-0547-4810-BE43-8C938337E0CE%7d">Join the beta</a> to try these features and let us know what you think!</p>
Thu, 15 Jul 2021 11:35:50 -0700Fabio Mansur53216 at https://www.watchguard.comNew AuthPoint Time Schedule Policy
https://www.watchguard.com/wgrd-blog/new-authpoint-time-schedule-policy
<p>Earlier this year, we launched the AuthPoint Risk Framework, a powerful and flexible way to manage authentication policies. We are now happy to announce that we have launched the Time Schedule as a new type of policy. The Time Schedule policy enables you to specify the dates and times when authentication policies apply to user authentications. You can configure a time schedule policy object if you want to:</p>
<ul><li>Allow authentication only during specified times, such as work hours.</li>
<li>Restrict authentication during specific times, such as non-work hours and holidays.</li>
<li>Enforce different authentication requirements at different times.</li>
<li>Use a safe network location to allow users to bypass MFA when they authenticate from the office, but only during specified times, such as work hours.</li>
</ul><p>We continue to work on adding new risk policies to provide a stronger risk-based authentication framework to AuthPoint users. Stay tuned as we prepare to release geo-based policies next!</p>
Fri, 04 Jun 2021 08:51:28 -0700Fabio Mansur52301 at https://www.watchguard.comNew AuthPoint Time Schedule Policy Beta
https://www.watchguard.com/wgrd-blog/new-authpoint-time-schedule-policy-beta
<p>Earlier this year, we launched the AuthPoint Risk Framework, a powerful and flexible way to manage authentication policies. The latest AuthPoint beta focuses on time-based policy objects, which enable you to specify the dates and times when authentication policies apply to user authentications. You might configure a time schedule policy object if you want to:</p>
<ul><li>Allow authentication only during specified times, such as work hours.</li>
<li>Restrict authentication during specific times, such as non-work hours and holidays.</li>
<li>Enforce different authentication requirements at different times.</li>
<li>Use a safe network location to allow users to bypass MFA when they authenticate from the office, but only during specified times, such as work hours.</li>
</ul><p><a href="https://watchguard.centercode.com/project/article/item.html?cap=e83c23aa2700430e8ba6bdc1c36385bf&arttypeid=%7b2493170b-835b-40be-a265-8f9d00fe470e%7d&artid=%7bF87FFEC5-CC15-4D34-B40E-2B0F79A85494%7d">Join the beta</a> to try these features and let us know what you think!</p>
Tue, 27 Apr 2021 11:49:23 -0700Fabio Mansur50191 at https://www.watchguard.comReleased: New AuthPoint Self Service Portal Feature
https://www.watchguard.com/wgrd-blog/released-new-authpoint-self-service-portal-features
<p>We are excited to announce that the Self-Service Portal feature is now available in AuthPoint!</p>
<p>This feature gives the users autonomy to activate their own tokens, both mobile and hardware, by accessing their company’s IdP portal. Users that are enrolling for the first time and still do not have an active token, can activate it as part of the login flow on the IdP portal. Users that are already enrolled and have an active token can also activate a new mobile or hardware token after they have logged into the –MFA protected- IdP portal. A key benefit for the operators is that they don’t need to associate and activate the hardware token for the users, simply ship it to the user, and he will be able to associate and activate it for himself in one single operation on the IdP portal. This simplifies logistics and the management of the tokens, as well as reduce support calls. Partners that prefer to manage tokens on their own, can opt to disable this feature and continue controlling the activations without the Self-Service capabilities.</p>
Mon, 26 Apr 2021 13:05:19 -0700Fabio Mansur50131 at https://www.watchguard.comNew wizard available - import hardware tokens
https://www.watchguard.com/wgrd-blog/new-wizard-available-import-hardware-tokens
<p>We are happy to announce the release of a new wizard on AuthPoint. The wizards provide a simple, step by step guide, to be followed by administrators to configure the MFA on their environment.</p>
<p>The new wizard guides the administrator through the steps necessary to <strong>import hardware tokens</strong> into AuthPoint, for both WatchGuard and third party.</p>
<p>Remember that the following operations are also available through Wizards:</p>
<ul><li>Get Started with AuthPoint – guides the administrator through a first, basic configuration, that allows him to have a user performing authentications on a matter of minutes.</li>
<li>Configure MFA for a VPN – guides the administrator through the steps necessary to setup the MFA for a VPN (for SSL VPN or MSCHAPv2).</li>
<li>Sync Users from Active Directory – guides the administrator through the steps necessary to configure the integration with the Active Directory and perform user synchronization from it.</li>
<li>Configure MFA for Computers and Servers – guides the administrator through the steps necessary to setup the MFA for user’s machines or servers (both Windows and mac).</li>
</ul><p>For new Subscriber accounts, the Get Started Wizard also shows up automatically as a checklist, so an administrator that is not familiar with AuthPoint can be guided since his first step on the tool.</p>
<p>You can read more details about it on the <a href="https://www.watchguard.com/help/docs/help-center/en-US/index_CSH.html#13039">Help Center</a>.</p>
Fri, 26 Mar 2021 09:11:58 -0700Fabio Mansur49491 at https://www.watchguard.comNew AuthPoint Self-Service Portal Beta
https://www.watchguard.com/wgrd-blog/new-authpoint-self-service-portal-beta
<p>We are excited to announce that the Self-Service Portal feature is now available to beta test!</p>
<p>This feature gives the users autonomy to activate their own tokens, both mobile and hardware, by accessing their company’s IdP portal. Users that are enrolling for the first time and still do not have an active token, can activate it as part of the login flow on the IdP portal. Users that are already enrolled and have an active token can also activate a new mobile or hardware token after they have logged into the –MFA protected- IdP portal. A key benefit for the operators is that they don’t need to associate and activate the hardware token for the users, simply ship it to the user, and he will be able to associate and activate it for himself in one single operation on the IdP portal. This simplifies logistics and the management of the tokens, as well as reduce support calls.</p>
<p><a href="https://watchguard.centercode.com/project/article/item.html?cap=e83c23aa2700430e8ba6bdc1c36385bf&arttypeid=%7b2493170b-835b-40be-a265-8f9d00fe470e%7d&artid=%7bF87FFEC5-CC15-4D34-B40E-2B0F79A85494%7d">Join the beta</a> to try these features and let us know what you think!</p>
Fri, 19 Mar 2021 07:48:54 -0700Fabio Mansur49446 at https://www.watchguard.comReleased: AuthPoint Agent for macOS – Big Sur
https://www.watchguard.com/wgrd-blog/released-authpoint-agent-macos-big-sur
<p>We are happy to announce the release of a new version of the AuthPoint Agent for macOS.</p>
<p>This version has compatibility with the new Big Sur operating system, allowing Big Sur users to have MFA protection on both startup of the machine and after blocking it.</p>
<p><strong>Keep your machines always updated with the latest version of the Agent for mac.</strong></p>
<p>For the machines that are already configured with the agent, you can simply download the installer from the AuthPoint Downloads page in WatchGuard Cloud and apply the installer on the machines. <a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/logon-app_about.html">Read this Help Center article</a> for more details.</p>
<p>If the agent for mac is not installed on your computer, go through this checklist before you install it:</p>
<ul><li>You have an AuthPoint user with an active token</li>
<li>The user name you use to log on to the computer matches your AuthPoint user name</li>
<li>You have added a Logon app resource in the AuthPoint management UI</li>
<li>You have assigned an access policy for the Logon app resource to your AuthPoint group</li>
<li>You can restart the computer after you install the Logon app</li>
<li>Your computer must be connected to the Internet before you log on for the first time</li>
</ul>Fri, 19 Mar 2021 07:46:57 -0700Fabio Mansur49441 at https://www.watchguard.comNew AuthPoint Risk Framework
https://www.watchguard.com/wgrd-blog/new-authpoint-risk-framework
<p>We are happy to announce that we have launched the new AuthPoint Risk Framework in WatchGuard Cloud. The improved authentication policy management allows for more granularity and flexibility when creating rules for your users and resources.</p>
<p>You also have now the option to create a policy to deny authentications under certain conditions or for specific groups or resources.</p>
<p>Network Locations (formerly Safe Locations) is the first risk feature available and we are working on adding additional policies throughout 2021, including: time policies, device risk, computer risk, as well as geolocation policies.</p>
<p>Main Changes You’ll See in WatchGuard Cloud:</p>
<ul><li>Access policies are now authentication policies</li>
<li>You configure authentication policies separately from groups</li>
<li>Each authentication policy can apply to multiple groups and resources</li>
<li>You can now configure policies to deny authentications</li>
<li>You can now configure policy objects, such as network locations (previously called safe locations) separately from groups</li>
<li>You can now add users to more than one group</li>
<li>You can now sync groups from Active Directory and Azure Active Directory</li>
</ul><p>Your existing policies have been automatically converted to the new policy system, so AuthPoint users or admins don’t need to migrate or integrate anything to start using the new risk framework.</p>
<p>To learn more about the new AuthPoint Risk Framework, watch <a href="https://www.watchguard.com/help/video-tutorials/Authentication_Policies/index.html" target="_new">this video</a>, which addresses all you need to know to understand the new structure and UI.</p>
<p>You can also read the <a href="https://watchguard.widen.net/view/pdf/4nmzg01xaj/FAQ_AuthPoint_Risk_Framework.pdf?t.download=true&x.share=t" target="_new">FAQ</a> for more information. Don’t see a question that should be posted in the FAQ? Email me at <a href="mailto:[email protected]">[email protected]</a></p>
Fri, 05 Feb 2021 10:01:51 -0800Fabio Mansur48906 at https://www.watchguard.comNew AuthPoint Wizards: Making MFA as Simple as Possible
https://www.watchguard.com/wgrd-blog/new-authpoint-wizards-making-mfa-simple-possible
<p>We are happy to announce the release of Wizards on AuthPoint. The Wizards provide a simple, step by step guide, to be followed by administrators to configure the MFA on their environment.</p>
<p>The following operations are available through Wizards:</p>
<p>Get Started with AuthPoint – guides the administrator through a first, basic configuration, that allows him to have a user performing authentications on a matter of minutes.</p>
<ul><li>Create a group</li>
<li>Create a user</li>
<li>Activate token</li>
<li>Set up the IdP portal</li>
<li>Log in to the IdP portal to test MFA</li>
</ul><p>Configure MFA for a VPN – guides the administrator through the steps necessary to setup the MFA for a VPN (for SSL VPN or MSCHAPv2).</p>
<ul><li>Create a RADIUS client resource</li>
<li>Configure and install the AuthPoint Gateway</li>
<li>Set an access policy</li>
</ul><p>Sync Users from Active Directory – guides the administrator through the steps necessary to configure the integration with the Active Directory and perform user synchronization from it.</p>
<ul><li>Create an external identity</li>
<li>Configure and install the AuthPoint Gateway</li>
<li>Create a group sync to sync users and groups from Active Directory</li>
</ul><p>For new Subscriber accounts, the Get Started Wizard also shows up automatically as a checklist, so an administrator that is not familiar with AuthPoint can be guided since his first step on the tool.</p>
<p>You can read more details about it on the <a href="https://www.watchguard.com/help/docs/help-center/en-US/index_CSH.html#13039">Help Center</a>.</p>
<p>Keep an eye on updates about it, as these are the first Wizards and others will be added to simplify the configuration of other features.</p>
Thu, 24 Sep 2020 11:59:20 -0700Fabio Mansur45321 at https://www.watchguard.comAuthPoint is Now Available as Monthly Subscription
https://www.watchguard.com/wgrd-blog/authpoint-now-available-monthly-subscription
<p>Starting this week, we are excited to offer our partners and customers AuthPoint as a monthly subscription in the WatchGuard FlexPay program.</p>
<p>WatchGuard FlexPay enables partners to purchase products according to their business needs. The FlexPay program includes all our payment options: pre-paid annual licenses, pay-as-you-go MSSP Points, and monthly subscriptions. </p>
<p>The AuthPoint Subscription is invoiced monthly based on usage. As a software product, it is easy to enable and manage both through the distributor marketplace and in WatchGuard Cloud. The steps for partners to enable are simple:</p>
<ol><li>Place an order on a distributor marketplace for an AuthPoint Subscription License that is a $0 SKU and complete checkout</li>
<li>Add/manage AuthPoint users in WatchGuard Cloud at next login (the license will already be auto activated with no allocation limit)</li>
<li>WatchGuard will issue invoices through the distributor on the 1st of each month for the total active Subscription users across the partner's cloud account hierarchy</li>
</ol><p>Currently, AuthPoint monthly subscriptions are available in the U.S. through SYNNEX. We are working with our distribution partners around the world to bring this option to broader geographic markets. </p>
<div style="padding:56.25% 0 0 0;position:relative;">
<iframe src="https://player.vimeo.com/video/847159543?badge=0&autopause=0&player_id=0&app_id=58479/embed" allow="autoplay; fullscreen; picture-in-picture" allowfullscreen="" frameborder="0" style="position:absolute;top:0;left:0;width:100%;height:100%;"></iframe></div>
<h2>What makes AuthPoint Subscriptions stand out?</h2>
<p><strong>Maximum Flexibility</strong></p>
<ul><li>Add a Subscription License for free with no upfront cost, available to all resellers</li>
<li>Only pay each month for total active Subscription users</li>
<li>Pay per single user<br />
</li>
</ul><p><strong>No Minimum Term Commitment</strong></p>
<ul><li>Pay-as-you-go based on monthly usage</li>
<li>No other vendor offers a standalone MFA product with no commitment monthly billing <br />
</li>
</ul><p><strong>Onboard and Manage with Ease</strong></p>
<ul><li>No more manual activation or allocation administration </li>
<li>The Subscription License coexists with all other license types including term, points, trials, NFR and these licenses will always be used up first</li>
<li>No pro-ration, newly added users get immediate free product access until counted at next invoice date</li>
<li>Auto renews each month<br />
</li>
</ul><p><strong>Freedom to Self-Serve</strong></p>
<ul><li>Need more users? MSPs and Subscribers can both add users anytime</li>
<li>MSPs have additional control to set limits on customer usage on the allocation page</li>
</ul><p> </p>
<p><strong>For more information check out the </strong><a href="https://watchguard.widen.net/view/pdf/uzv6tshlgg/authpoint_monthly_subscriptions_faq.pdf?t.download=true&x.share=t">FAQ</a> and <a href="https://watchguard.widen.net/view/pdf/f1jaotf67q/authpoint-subscription-guide.pdf?t.download=true&x.share=t">Step by Step Order Guide</a></p>
Fri, 11 Sep 2020 11:58:25 -0700Sharon Li44906 at https://www.watchguard.comNew version of the Agent for Windows is available!
https://www.watchguard.com/wgrd-blog/new-version-agent-windows-available
<p>We are happy to announce the release of a new version of the AuthPoint Agent for Windows.</p>
<p>This version improves the treatment of the MFA, specially for RDP connection scenarios, and enhances the user experience by allowing to automatically send a push notification to users during the login process. This makes the authentication experience more convenient, allowing users to simply type the username and password and approve the push notification using the mobile AuthPoint token. Users can configure or disable this feature.</p>
<h2>Keep your machines always updated with the latest version of the Agent for Windows</h2>
<p>For the machines that are already configured with the agent, you can simply download the installer from the AuthPoint Downloads page in WatchGuard Cloud and apply the installer on the machines. Remember that you can also install it using some distribution tool and command line interface. <a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/logon-app_about.html">Read this Help Center article</a> for more details.</p>
<p>If the agent for Windows is not installed on your computer, go through this checklist before you install it:</p>
<ul><li>You have an AuthPoint user with an active token</li>
<li>The user name you use to log on to the computer matches your AuthPoint user name</li>
<li>You have added a Logon app resource in the AuthPoint management UI</li>
<li>You have assigned an access policy for the Logon app resource to your AuthPoint group</li>
<li>You can restart the computer after you install the Logon app</li>
<li>Your computer must be connected to the Internet before you log on for the first time</li>
</ul><p> </p>
Thu, 10 Sep 2020 11:16:04 -0700Fabio Mansur44931 at https://www.watchguard.comThe Dark Web Scan is in WatchGuard Cloud!
https://www.watchguard.com/wgrd-blog/dark-web-scan-watchguard-cloud
<p>We are excited to announce that the Dark Web Scan is live in <strong>WatchGuard Cloud</strong> and available on Subscribers and Service Provider accounts. With this new tool, partners and end users can perform searches based on email addresses and domain names to see which accounts have been exposed on the dark web during known data breaches.</p>
<p>The Dark Web Scan will allow partners to generate and send personalized reports. This can be a great conversation starter with customers about the importance of identity and credential theft protection, as well as the need for multi-factor authentication. After all, who knows when an employee will be part of a new breach? </p>
<p><strong>As a Partner with a Service Provider account, you will be able to:</strong></p>
<ul><li>Scan any email address</li>
<li>Scan any company domain, except for public ones (google.com, msn.com, yahoo.com, etc.)</li>
<li>Send personalized dark web reports to authorized domain admins and users</li>
</ul><p><strong>As a Customer with a Subscriber Account, you will be able to:</strong></p>
<ul><li>Scan any email address</li>
<li>Scan company domain associated with user account <br />
</li>
</ul><h2>The Threat of the Dark Web Is Real </h2>
<p>This new feature is a free scanning service and sales tool that can be used to raise awareness among existing and potential customers with data from real breaches involving their company domains and employee credentials. If an employee credential was exposed in the Dark Web, MFA is what can save the company from a breach. And AuthPoint's push-based authentication can even warn users if someone tries to use their stolen credentials.</p>
<h3><strong>Learn more about the Dark Web Scan with these helpful links</strong></h3>
<ul><li><a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/WG-Cloud/sub_dark_web_scan.html?Highlight=dark%20web">Help Center article</a></li>
<li><a href="https://watchguardsupport.secure.force.com/publicKB?type=Article&SFDCID=kA10H000000bol3SAA&lang=en_US">What public domains does Dark Web Scan not scan?</a><br />
</li>
</ul><h3><strong>Frequently Asked Questions</strong></h3>
<p>Make sure to read our complete <a href="https://www.watchguard.com/darkweb-faq">FAQ</a> for any doubt about the service that is being offered for free, to our partners and customers.</p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
Thu, 13 Aug 2020 05:18:28 -0700Alexandre Cagnoni44711 at https://www.watchguard.comYou asked for them: AuthPoint Hardware Tokens
https://www.watchguard.com/wgrd-blog/you-asked-them-authpoint-hardware-tokens
<p>We are excited to share the news that our MFA solution portfolio continues to expand and now partners can offer AuthPoint Hardware Tokens to interested customers! Hardware tokens can be used by businesses as an alternative to the mobile token to authenticate into protected resources.</p>
<p><strong>Common Use Cases</strong></p>
<ul><li>Although mobile-based authentication is more popular and in many cases more secure, there are many scenarios where hardware tokens are required or preferred.</li>
<li>Accessing locations where authentication is required, but mobile use is restricted, like hospitals</li>
<li>Tough environments, like mines or oil platforms</li>
<li>Companies with policies that limit or restrict the use of personal mobile devices for security purposes</li>
</ul><p>
<strong>Cool things to know about AuthPoint Hardware Tokens </strong> </p>
<ul><li>There is no seed file with AuthPoint hardware tokens. The hardware tokens are produced in our own factory and added to WatchGuard Cloud directly. This is a secure process that protects the token from becoming compromised (<a href="https://arstechnica.com/information-technology/2011/06/rsa-finally-comes-clean-securid-is-compromised/">see what happened to RSA in 2011</a>). </li>
<li>All tokens are programmed and finalized in the WatchGuard factory. No 3rd party company has access to our firmware or secrets.</li>
<li>Token secrets are transmitted directly from the WatchGuard factory network (physically separated from the corporate network) to the Cloud. No human in the middle has access to it.</li>
<li>Our devices are made in Brazil, in WatchGuard premises.</li>
<li>Less than 0.1% of RMA - Return Merchandise Authorization (return because of defects)</li>
<li>No activation is needed. Just add them to one or more AuthPoint tenants, using the Hardware Token menu option</li>
<li>3 years warranty starts only first time after you add them to a user, so you don’t have to worry about having some extra ones in your stock</li>
<li>Life expectancy of more than 7 years, when in constant use</li>
</ul><p>
<strong>New Product Page</strong><br />
We have added a new page under the Multi-Factor Authentication product section of the website. Visit the <a href="https://www.watchguard.com/wgrd-products/authpoint/hardware-tokens">Hardware Token page</a> to learn more.</p>
<p><strong>Ordering Hardware Tokens</strong> <br />
AuthPoint Hardware Tokens are available to order now. They have a fixed price and are sold in 10 tokens boxes. </p>
<p> </p>
<p>Check out the FAQ and datasheet at the Partner Portal!</p>
<p> </p>
<p> </p>
Wed, 05 Aug 2020 10:42:03 -0700Alexandre Cagnoni44606 at https://www.watchguard.comNew with AuthPoint: Beta version of the Agent for macOS
https://www.watchguard.com/wgrd-blog/new-authpoint-beta-version-agent-macos
<p>We are excited to announce that an updated version of the AuthPoint agent for macOS is now available to beta test! We’ve redesigned the new agent for macOS to provide more features and make the authentication process easier. This version has two main new features:</p>
<ul type="disc"><li><strong>Automatic Push Notifications</strong>: AuthPoint users can configure automatic Push notifications which will be trigger after typing username and password to access an application. This can be convenient to some users who will prefer to skip the “Send Push” step, but it can also be disabled.</li>
<li><strong>Login Access for Non-AuthPoint Users</strong>: Non-AuthPoint users can now login to macOS applications without requesting MFA. This feature already exists on the Agent for Windows (platforms? Environments? We need a word here) and has now been implemented for macOS. This feature is particularly useful for Service Providers that need to access customers’ machines to provide support. The configuration and behavior are exactly the same as we have for Windows and there are no risks associated with this benefit.</li>
</ul><p>Remember that the Agent for macOS also supports macOS Catalina.</p>
<p>TRY IT! <a href="https://watchguard.centercode.com/key/AgentForMacV1-9">Join the beta</a> to try these features and let us know what you think!</p>Thu, 21 May 2020 14:02:34 -0700Fabio Mansur42096 at https://www.watchguard.comNew Pull Authentication Feature: Push Notifications Will Never Be Late Again
https://www.watchguard.com/wgrd-blog/new-pull-authentication-feature-push-notifications-will-never-be-late-again
<p><img alt="WatchGuard AuthPoint pull authentication screen" src="/sites/default/files/pullnotif.png" style="float: left; padding: .5rem 1.5rem .5rem 0;" /></p>
<p>Your push message didn’t arrive? Don’t worry, a new version of the AuthPoint App for Android and iOS is now available for download with the new “Pull Authentication” feature.</p>
<p>AuthPoint’s Push authentication is what makes our solution one of the most secure and user-friendly MFA options in the market. This feature provides complete information about the user, their location and device, which adds increased levels of security when approving or denying access to applications. This technology is also more secure and reliable than SMS authentication because the communication is fully encrypted in the app.</p>
<p>But as with any other notification solution, we depend on Google Cloud Messaging or Apple Push Notification Service to deliver Push-based authentication messages. While we know that notifications normally arrive in less than 3 seconds, there are times when it takes longer, which affects the user experience of our AuthPoint users<a> </a>– but we have no control over the third-party services.</p>
<p>We are happy to introduce the new “Pull Authentication” feature. If your Push message doesn’t arrive in a few seconds, just open your AuthPoint App or click on “Check for pending notifications” on your phone, and we will retrieve the notification from AuthPoint in WatchGuard Cloud to make sure you don’t miss notifications. No more delays and no more waiting!</p>
<p><em>Note: The Pull Authentication feature is supported in versions 1.13.0 and beyond.</em></p>
Tue, 28 Apr 2020 09:50:45 -0700Alexandre Cagnoni41531 at https://www.watchguard.comNew AuthPoint Gateway Beta with Two Features WatchGuard Partners and Customers Asked For!
https://www.watchguard.com/wgrd-blog/new-authpoint-gateway-beta-two-features-watchguard-partners-and-customers-asked
<h3><strong>High VPN Authentication Performance</strong></h3>
<p>The new AuthPoint Gateway now has a redesigned RADIUS component to support instances when a higher number of employees are using multi-factor authentication at the same time.</p>
<p>As businesses shifted to a remote environment, the volume of VPN connections increased dramatically, and which could cause some delays especially during peak hours where a larger-than-usual number of users try to connect into their networks (between 8:00-9:00 AM local time).</p>
<p>This improvement should provide a faster VPN authentication experience to all AuthPoint users at any time.</p>
<h3><strong>Support for Java 11 and AWS Corretto 11</strong></h3>
<p>Remember when we only supported Oracle Java 8 at an extra cost? The new AuthPoint Gateway now also supports both Java 11 and AWS Corretto 11, a free distribution version of OpenJDK 11, compatible with Java SE standard (learn more at <a href="https://aws.amazon.com/corretto/">https://aws.amazon.com/corretto/</a>).</p>
<p>You don’t have to be an AWS customer to download it, so AuthPoint users can have the latest Java-compatible version at no extra cost.</p>
<p>Please make sure to join our new Beta at <a href="https://watchguard.centercode.com">https://watchguard.centercode.com</a>. If you already have an account, you should have received an invitation. If you don’t have an account, visit the link above to sign up.</p>
Tue, 28 Apr 2020 09:18:31 -0700Alexandre Cagnoni41551 at https://www.watchguard.comAuthPoint Support for MSCHAPv2 / IKEv2 VPNs Is Now Available!
https://www.watchguard.com/wgrd-blog/authpoint-support-mschapv2-ikev2-vpns-now-available
<p>We are happy to announce that AuthPoint Gateway v5.3.1 was just launched, adding support for RADIUS MSCHAPv2 authentications to Active Directory. This means that you can now create IKEv2 VPNs, authenticating users to Active Directory, using AuthPoint as your MFA solution.</p>
<p>Why IKEv2?</p>
<ul><li>IKEv2 is the most secure VPN option available today</li>
<li>It is natively available on Windows, macOS, and iOS, and it is easily used among Android users with apps such as StrongSwan</li>
<li>For Firebox customers, being IPSec-based, IKEv2 can take advantage of crypto acceleration available on Firebox appliances, providing better performance than SSL or L2TP</li>
</ul><p>You can take a look at the basic configuration needed at:</p>
<p><a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/resources_radius.html">https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/authpoint/resources_radius.html</a></p>
<p>And here you can find the integration guide with Firebox, including Microsoft NPS configuration:</p>
<p><a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/AuthPoint/firebox-ikev2-vpn-radius_authpoint.html">https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/AuthPoint/firebox-ikev2-vpn-radius_authpoint.html</a></p>
<p>It’s important to notice that IKEv2/MSCHAPv2 multi-factor authentication will only work with push-based authentication. Time-based OTPs cannot be used, since the typed in password plus OTP would be hashed together, so AuthPoint wouldn’t be able to retrieve the OTP part from the password.</p>
<p>Thanks for all that participated in our Beta Program!</p>
<p> </p>
Fri, 13 Mar 2020 11:24:10 -0700Alexandre Cagnoni40781 at https://www.watchguard.comAuthPoint Beta program is more active than ever!
https://www.watchguard.com/wgrd-blog/authpoint-beta-program-more-active-ever
<p>New features and functionalities are being revealed with our AuthPoint Beta Program. Check out some of those:</p>
<ul><li><strong>AuthPoint Authentication APIs</strong> Beta ended and is now publicly available, and for no additional cost in your AuthPoint license! See how easy it is to integrate AuthPoint’s MFA technology with your web portal or home applications</li>
</ul><ul><li><strong>AuthPoint Agent for MacOS v1.7</strong> Beta started this week, and it now supports Catalina. Check it out!</li>
</ul><ul><li><strong>AuthPoint Agent for Windows </strong>Beta is getting a new refresh in the next few days. It provides easier distribution and optional login without MFA for defined users</li>
</ul><ul><li><strong>Azure AD Sync and Authentication</strong> Beta is running. Keep an eye on how to configure Office365 with native Azure AD users, integrated with AuthPoint. Coming out soon!</li>
</ul><p>We will be soon starting as well the AuthPoint Branding Beta, so you can add your logo to your managed accounts.</p>
<p>And check out the new AuthPoint feature that allows you to verify a caller’s identity by sending them a Push, making sure you are talking to the right person!</p>
<p class="text-center"><img src="/sites/default/files/2020-01/blog-AuthPointLogonApp.png" /></p>
<p class="text-center"><img src="/sites/default/files/2020-01/blog-AzureADSync.png" /></p>
<p class="text-center"><img src="/sites/default/files/2020-01/blog-UserVerification.png" /></p>
Fri, 10 Jan 2020 11:53:28 -0800Alexandre Cagnoni39561 at https://www.watchguard.comParticipate in the AuthPoint Authentication API Beta Test!
https://www.watchguard.com/wgrd-blog/participate-authpoint-authentication-api-beta-test
<p>We are excited to announce that the AuthPoint Authentication API is now available to beta test! The Authentication API is a new service that you can use to add the protection of AuthPoint multi-factor authentication (MFA) directly into your custom applications, using RESTful API calls.</p>
<p>Would you like to quickly add MFA to your Web portal? Maybe add Push, QR Code or OTP (one-time password) authentication into your home developed application?</p>
<p>With the AuthPoint Authentication API, you will be able to:</p>
<ul><li>Authenticate a user with a time-based OTP</li>
<li>Generate a customized authentication request to your users as a push notification</li>
<li>Poll for the push status: push notification received and authentication request approved, denied or pending</li>
<li>Generate a QR Code challenge and validate the response</li>
<li>Validate the user’s password with AuthPoint or separately on your application</li>
<li>And much more!</li>
</ul><p>To get started, click <a href="https://watchguard.centercode.com/key/AuthenticationAPIBeta">here </a>to visit our beta management site. You’ll find instructions on how to enable API access for your account and start using the Authentication API.</p>
<p>We look forward to hearing any suggestions or feedback you can give us.</p>
<p>Thanks for helping us to make AuthPoint a great product!</p>
Fri, 22 Nov 2019 09:57:57 -0800Alexandre Cagnoni39061 at https://www.watchguard.comNew AuthPoint Features
https://www.watchguard.com/wgrd-blog/new-authpoint-features
<p>AuthPoint capabilities continuously improve, and a host of new features were recently added that make our MFA solution even more flexible, easy to manage, and secure. The latest enhancements include:</p>
<ul><li><strong>AuthPoint Gateway HA</strong> - Gives customers full high availability (HA) of on-premises services such as RADIUS and AD authentication. With this feature, users can have one primary gateway and up to 5 other gateways in the location of their choice. If the first goes down, the next one will take over automatically ensuring high availability for authentication services.</li>
<li><strong>Backup and Restore for Mobile 3rd party Tokens</strong> – With this feature, users can now add their own personal mobile tokens (e.g. social media, personal DropBox account) to the AuthPoint app and back up these 3rd party personal tokens. For example, if a user gets a new phone or loses a phone, no problem; the tokens will be easy to restore in their new device.</li>
<li><strong>Advanced Search for Users </strong>– Advanced search for AuthPoint enhances user management capabilities by enabling better, easier search functionality. Account administrators can now search logs using a variety of attributes; for example, if you want to list all users that haven't activated their tokens yet or users that, status of users, users with blocked tokens, by group, users in quarantine, and more.</li>
<li><strong>Advanced Search on the Hardware Token Screen</strong> -This feature enables admins to search using hardware token attributes such as status, serial number, activation and creation date, and user information. This is especially useful for companies distributing a larger number of hardware tokens to users.</li>
<li><strong>AuthPoint Push Tracking </strong>- Unlike many other solutions in the market, AuthPoint offers push tracking. This allows admins to track the status of a push. For example, if a user complains that he/she did not receive a push, the admin can look in the audit logs to see the status of the push.</li>
<li><strong>New AuthPoint Integrations:</strong> Concur redirection, Meraki Dashboard, KnowBe4, LogMeIn, OneLogin, Zoho, Citrix ShareFile, GitLab, Rakurakuseisan, Zendesk</li>
</ul>Tue, 15 Oct 2019 05:28:42 -0700Alexandre Cagnoni38006 at https://www.watchguard.comAuthPoint Gateway HA Beta is now Available
https://www.watchguard.com/wgrd-blog/authpoint-gateway-ha-beta-now-available
<p><strong>AuthPoint Gateway version 5 with High Availability support is now available to beta test!</strong></p>
<p>This new version supports two main features:</p>
<p>You can now configure and install secondary Gateways to provide high availability for LDAP user authentication. If your primary Gateway is not available, AuthPoint automatically sends LDAP user authentications through the secondary Gateway until the primary Gateway becomes available again. You can have the primary Gateway and up to 5 additional secondary Gateways.</p>
<p>
For RADIUS client resources, you can now choose to send the Active Directory group for the attribute 11 (Filter-ID) value in RADIUS responses. This enables you to apply firewall policies based on the user’s AD group.</p>
<p>To get started, visit our beta management site at watchguard.centercode.com. You’ll find instructions on how to install the Gateway and start using the new features.</p>
<p>We look forward to hearing any suggestions or feedback you can give us to help make the Gateway even better!</p>
<p>Thanks for helping us to make AuthPoint a great product!</p>
Thu, 15 Aug 2019 13:59:09 -0700Alexandre Cagnoni36941 at https://www.watchguard.comAuthPoint Agent for RD Web is here!
https://www.watchguard.com/wgrd-blog/authpoint-agent-rd-web-here
<p>We’re excited to announce that the AuthPoint agent for RD Web is now available!</p>
<p class="text-center"><img src="/sites/default/files/rdweb3.gif" alt="WatchGuard Cloud UI screenshot showing new RD Web menu item" /></p>
<p>This agent allows users to enforce MFA when connecting to remote applications using Microsoft Remote Desktop Web Access application (RD Web). It integrates with the AuthPoint Web SSO functionality, so if you login into AuthPoint's IdP, you will automatically login to RD Web as well. It also supports safe locations, allowing users to configure dedicated locations in which MFA is not required to access those remote applications.</p>
<p>It’s quick to set up. Simply follow the installation and configuration instructions in the Help Center to get started.</p>
<p>And just as a reminder, connections to computers and servers using RDP or RD Gateway can still be protected by our new AuthPoint Agent for Windows!</p>
Wed, 07 Aug 2019 09:37:30 -0700Alexandre Cagnoni36891 at https://www.watchguard.comAuthPoint Agent for RD Web Beta and Agent for Windows update
https://www.watchguard.com/wgrd-blog/authpoint-agent-rd-web-beta-and-agent-windows-update
<p>The AuthPoint Agent for RD Web is entering its second week of Beta! Have you tried it yet?</p>
<p><strong>What is it?</strong> The AuthPoint agent for RD Web allows users to enforce MFA when connecting to remote applications using Microsoft’s remote desktop web application (RD Web). It also supports safe locations, allowing users to configure dedicated locations in which MFA is not required to access those remote applications.</p>
<p><strong>How can you help?</strong> Sign up to Centercode, and join our Beta: <a href="https://watchguard.centercode.com/key/RDWeb">https://watchguard.centercode.com/key/RDWeb</a>.</p>
<p>As a reminder, the AuthPoint Agent for Windows v2.0 Beta is still running, with great feedback from partners. On the week of June 17th we should have a final update before GA, with the following changes:</p>
<ul><li>Fix to improve Internet detection, and reduce the time to switch to offline mode</li>
<li>Support for 3rd party hardware tokens (it's coming!!!)</li>
<li>Small fixes</li>
</ul><p>Thanks!</p>
Mon, 10 Jun 2019 11:40:22 -0700Alexandre Cagnoni35631 at https://www.watchguard.comAuthPoint Agent for Windows v2.0 Beta is here!
https://www.watchguard.com/wgrd-blog/authpoint-agent-windows-v20-beta-here
<h2>AuthPoint Agent for Windows is getting a new look and feel!</h2>
<p><strong>What does this change?</strong><br />
This beta kicks off the release of the redesigned version of the AuthPoint Agent for Windows, which will have the same look and feel as the agent for MacOS. When Windows users log in, AuthPoint sign-in options (e.g. push) will appear on a new screen after the user enters in a username and password. This is different from the current Windows logon in which the sign-in options appear on the same screen as the Windows logon screen. </p>
<p><img src="/sites/default/files/authpointagentforwindows2.jpg" alt="AuthPoint Agent for Windows v2.0 screenshot" /></p>
<p><strong>Exciting new features with the new Agent!</strong></p>
<ul><li>
<p>Support for RDP connections using the Remote Desktop Connection application</p>
</li>
<li>
<p>Support for RDgateway connections</p>
</li>
<li>
<p>Safe Locations support: give users better usability by allowing them to automatically bypass MFA if they are connected to a protected network - your Safe Location!</p>
</li>
</ul><p><strong><a href="https://watchguard.centercode.com">Sign up</a> to participate in the AuthPoint Beta program today if you are not already in the program. </strong></p>
<p><strong>WatchGuard Beta Testing</strong><br />
By being a WatchGuard Beta tester, you get to see products in early stages of development, and your feedback will influence this release and the course of future products. Broad participation in our Beta programs also helps us to deliver high quality final releases. There are open Beta programs across 5 different product areas at the moment. You can always find out more at our <a href="https://www.watchguard.com/wgrd-support/beta-program">Beta program page</a>. If you've never joined a WatchGuard Beta program, this is a great time to jump in!</p>
Wed, 15 May 2019 09:21:59 -0700Alexandre Cagnoni35306 at https://www.watchguard.comAuthPoint – WatchGuard Cloud’s MFA Service is Here!
https://www.watchguard.com/wgrd-blog/authpoint-watchguard-clouds-mfa-service-here
<p>Passwords are not as effective as they used to be, with employees simplifying or mishandling them and hackers demonstrating more ways to steal them. AuthPoint multi-factor authentication (MFA) makes password strength irrelevant, providing additional proof of identity when accessing applications and services such as:</p>
<ul><li>Remote Access and VPN</li>
<li>Cloud Applications</li>
<li>Windows Login</li>
</ul><p><br /></p>
<p>How? The AuthPoint mobile app on your smartphone will show you who is trying to authenticate, what application, and from where, so you can easily approve or deny with a single tap on the screen.<br />
Even when your phone is not connected, you can use the app with offline authentication methods, such as with a secure QR Code or one-time passwords (OTPs). Make the AuthPoint app your one stop for authentication by adding your personal social media tokens instead of installing multiple token apps.</p>
<p>Not only is AuthPoint easy for users, but network administrators will also appreciate that management is available from our new, beautiful WatchGuard Cloud platform. Simply login, activate your licenses, and you are ready to:</p>
<ul><li>Quickly provision users by synchronizing with your Active Directory or LDAP base and sending them activation instructions</li>
<li>Configure any firewall for AuthPoint authentication, using RADIUS protocol</li>
<li>Add Web Single Sign-On (SSO) capabilities to your Cloud applications</li>
<li>Protect your Windows machines with push-message authentication, and offline authentication</li>
</ul><p><br /></p>
<p>With AuthPoint, companies can now enjoy a multi-factor authentication (MFA) solution that is simple, intuitive, and secure.</p>
<p>Learn more at <a href="/wgrd-products/authpoint-multi-factor-authentication">www.watchguard.com/authpoint</a></p>
Thu, 26 Jul 2018 11:07:43 -0700Alexandre Cagnoni26066 at https://www.watchguard.com