Flexible MFA methods
Push approvals, one-time codes, QR-based workflows, passkeys, and supported hardware tokens can be aligned with user and operational requirements.
Start a conversation 
Protect every sign-in
WatchGuard AuthPoint MFA protects supported cloud applications, computers, VPNs, and business resources with flexible authentication methods and centrally managed access policy.
Why it matters
Credential theft, phishing, password reuse, and automated attacks make single-factor access unsafe. AuthPoint adds an independent verification step and gives Kenmie a central way to manage enrollment, policy, recovery, and access changes.
Core capabilities
Each capability addresses a specific part of the risk while sharing useful visibility with the broader WatchGuard ecosystem.
Push approvals, one-time codes, QR-based workflows, passkeys, and supported hardware tokens can be aligned with user and operational requirements.
Supported Windows and macOS sign-ins can require AuthPoint authentication when that design fits the environment.
AuthPoint can strengthen supported Firebox VPN, wireless, and third-party RADIUS authentication workflows.
SAML and OIDC integrations extend strong authentication and single sign-on to supported business applications.
Purpose-built hardware tokens support users who cannot rely on a smartphone or require a dedicated authentication device.
WatchGuard Cloud supports policy, user lifecycle, token management, reporting, and troubleshooting across managed accounts.
Extend identity protection
Organizations that need both strong authentication and awareness of exposed workforce credentials can extend AuthPoint with dark-web credential monitoring.
The accountable layer
Technology becomes an operating security service when it is scoped, configured, monitored, maintained, and supported around the customer’s environment.
Business outcomes
Connected technologies