WGIndo Secure Portal
SAML 2.0 demo
Identity provider connected
Federated access

This application has no password of its own.

Sign-in is delegated to WatchGuard AuthPoint. Your credential is never sent here — AuthPoint verifies who you are, enforces multi-factor, and returns a signed assertion that this portal trusts for the length of your session.

Sign in with AuthPoint You will be redirected to your identity provider.

What happens when you sign in

The SAML 2.0 web browser SSO profile, end to end.

  1. RedirectThis portal sends an authentication request to AuthPoint.
  2. IdentifyYou authenticate against Active Directory through the AuthPoint Gateway.
  3. Second factorAuthPoint challenges you — push approval, one-time password, or a passkey.
  4. AssertionA signed, time-limited assertion is posted back to this portal.
  5. VerifyThe signature, audience and validity window are checked before any session exists.
  6. SessionYou land on the dashboard. No password ever reached this server.

Why this matters

The security properties a customer should take away.

CredentialsNever handled by this application — nothing to steal from it.
Second factorEnforced centrally by policy, not by each application.
MethodPush, OTP or passkey — changed in policy, no code change here.
RevocationDisable the account once in AD and every federated app closes.
AssertionSigned by the IdP, scoped to this audience, valid for minutes.

Service provider details

The values configured on the AuthPoint side for this application.

Entity ID
https://saml.wgindo.com/saml/metadata
Assertion consumer service
https://saml.wgindo.com/saml/acs
Binding
HTTP-POST
Assertion signing
Required — unsigned assertions are rejected
Method floor
Any method permitted by identity provider policy