AuthPoint MFA and Windows Logon with on-prem Active Directory User Authentication.

The Logon app adds MFA when users sign in to a computer or server. It also protects RDP and RD Gateway. To use MFA, you must create a Logon app resource in AuthPoint and install the Logon app on every computer or server you want to protect. The Logon app also works for RDP/RDS hosts. When logging in, users enter their normal username and password, then complete MFA (push, OTP, or QR code).

Also check WatchGuard AuthPoint MFA Logon setup guide.

In WatchGuard Cloud, go to Configure > Directories and Domain Services
Click Add Authentication Domain.

Choose WatchGuard Cloud Directory, then click Next.

Confirm that you want to create the directory.

Create a Group

AuthPoint uses groups to control which resources users can access. You must create at least one group before adding users.

  • On the Directories and Domain Services page, click your WatchGuard Cloud Directory.
  • Open the Groups tab.
  • Click Add Group.
  • Enter a Group Name and click Save.
    • The group now appears in both the Cloud Directory and AuthPoint.

Prepare Active Directory

  • In your AD server, create example a AuthPoint-Users group.
  • Add all users who need Windows MFA logon access to this group.
  • Make sure every user has a valid email address in their AD account.
    o This email is used to send the AuthPoint mobile token activation message.

Install the AuthPoint Gateway
The AuthPoint Gateway syncs user information between AD and AuthPoint.
It is only used for syncing users — not for RADIUS or LDAP authentication.

  • In AuthPoint Cloud:
    • Go to Gateway
    • Click Add Gateway
    • Enter a name and click Save
    • Open the Gateway tile and click Registration Key
    • Click Save
  • Go to Downloads → Gateway Installer and download the installer.
  • Run the installer on any server that:
    • Has Internet access.
    • Can reach your AD/LDAP server.
    • In this example, the Gateway is installed on the Domain Controller.
    • Install Java before installing the Gateway.
      • Recommended: Amazon Corretto 11 or 21
  • Paste the Registration Key into the installer.
  • Click Install, then Finish.
  • In AuthPoint Cloud, check the Gateway status icon.
    • Green means the Gateway is online and working.

Add an LDAP External Identity
To sync AD users, you must add an LDAP external identity and create queries.

  • In AuthPoint Cloud, go to External Identities.
  • Click Add External Identity.
  • Select LDAP Configuration.
  • Enter a name.
  • In LDAP Search Base, enter your domain in LDAP format.
    • Example: domain kita.local → DC=kita,DC=local
  • Enter the System Account and Passphrase.
  • Enter your AD domain name.
  • Enter the server address (IP of your AD server).
  • Choose LDAPS (636) or LDAP (389).
  • Leave the other settings as default.

Connect the External Identity to the Gateway

  • Go to Gateway.
  • Click your Gateway name.
  • In the LDAP section, select the external identity you created.
  • Click Save.

To test the connection:

  • Go to External Identities.
  • Click the menu next to your LDAP identity.
  • Select Check Connection.

Configure Group Sync

  • Select External Identities and from the navigation menu, select Group Sync.
  • Click Add New Group Sync.
  • In LDAP Groups to Sync Users From, select the AD group.
  • Check Create new synchronized group.
  • In Select an AuthPoint Group to Add Users To, choose the group you created earlier in Directories and Domain Services.
  • If you do not want AuthPoint to automatically create mobile tokens or send activation emails, clear those checkboxes.

Notes About Group Design

There is no “correct” or “incorrect” method. It depends on:

  • How your AD groups are organized
  • Whether you want to create new AD groups
  • Which resources you want to protect with MFA

Start the Synchronization

  • Select External Identities and from the navigation menu, select Start Synchronization.

Your AD users will now appear in the AuthPoint Users list as LDAP type. Depending on your Group Sync settings, users may belong to one or more AuthPoint groups.

If you left the default Automatically create a mobile token for this user enabled the user also receives email messages to activate a token in the AuthPoint mobile app.
If you cleared the Automatically create a mobile token for this user, go to the AuthPoint Users list choose the user and click the three dots menu and select Add New Token.


Open the Activation email and click the link in the email. This takes you to the Welcome to AuthPoint web page. If you have not done so, download and install the AuthPoint mobile app on your phone from Apple App Store or Google Play Store.

  • If you opened the web page on your phone, tap the Activate button. This opens the AuthPoint app and activates your token.
  • If you opened the web page on your computer, open the AuthPoint app on your phone and tap Activate in the app, then point the camera on your phone at the QR code on your computer screen.

You can see the token on the AuthPoint Users page.

Test that the users get a Push notification to the AuthPoint MFA app.

Add Logon App resource in AuthPoint

  • In WatchGuard Cloud, go to Resources.
  • Click Add Resource.
  • From the Type list, select Logon App.
  • In Name, type a descriptive name for this resource.
  • (Optional) In the Support Message text box, type a message to show on the logon screen
  • Check WatchGuard Agent installs and manages this resource.
    You can now use the WatchGuard Agent to deploy and manage the AuthPoint Logon app on Windows and Mac computers. This makes the Logon app easier to deploy, and it enables the Logon app to automatically download and install updates (previously, updated versions of the Logon app had to be installed manually).

Configure Zero Trust Authentication Policies

  • Go to WG Cloud > Configure > Zero Trust.
  • Click Add Policy.
  • Enter a name for the policy.
  • In the Target section, choose the groups this policy applies to.
  • You can select more than one group.
  • In this example, select the Windows Logon MFA group you created earlier.
  • In the Resources section, select the Logon App resource.
  • In the Action section, choose Allow.
  • Select Password, Push, QR Code and One-Time Password.
  • Click Save.

Deploy the AuthPoint Logon App with the WatchGuard Agent

You can now use the WatchGuard Agent to deploy and manage the AuthPoint Logon app on Windows and Mac computers. This makes the Logon app easier to deploy, and it enables the Logon app to automatically download and install updates (previously, updated versions of the Logon app had to be installed manually).

  • Go to WatchGuard Cloud Configure > AuthPoint > Downlods or WatchGuard Cloud Monitor > Endpoints
  • select Add Endpoint and Download the WatchGuard Agent installer for Windows.
  • Install the WatchGuard Agent.
  • After the WatchGuard Agent is installed, you must configure the agent to deploy the Logon app. 
    For more information, go to Configure WatchGuard Agent Deployment in WatchGuard Cloud.
  • When you deploy the Logon app with the WatchGuard Agent, you do not need to get the configuration file for the Logon app (the WatchGuard Agent pulls that from AuthPoint directly)
  • The WatchGuard Agent installs the Logon app by default unless the agent deployment behavior is configured to not install the Logon app in the Agent Deployment settings.
  • To edit the Agent Deployment, Go to Configure > Agent Deployment > Edit Deployment

To logon to the Windows machine, first use your normal Windows Username & Password credentials,
then choose the MFA option. Push Notification is default.

Test also the QR Code and One-Time Password. When the Windows machine is offline (no internet) you need to use these two options.

Leave a Reply

Your email address will not be published. Required fields are marked *

Close