This application has no password of its own.
Sign-in is delegated to WatchGuard AuthPoint. Your credential is never sent here — AuthPoint verifies who you are, enforces multi-factor, and returns a signed assertion that this portal trusts for the length of your session.
Sign in with AuthPoint
You will be redirected to your identity provider.
What happens when you sign in
The SAML 2.0 web browser SSO profile, end to end.
- RedirectThis portal sends an authentication request to AuthPoint.
- IdentifyYou authenticate against Active Directory through the AuthPoint Gateway.
- Second factorAuthPoint challenges you — push approval, one-time password, or a passkey.
- AssertionA signed, time-limited assertion is posted back to this portal.
- VerifyThe signature, audience and validity window are checked before any session exists.
- SessionYou land on the dashboard. No password ever reached this server.
Why this matters
The security properties a customer should take away.
| Credentials | Never handled by this application — nothing to steal from it. |
| Second factor | Enforced centrally by policy, not by each application. |
| Method | Push, OTP or passkey — changed in policy, no code change here. |
| Revocation | Disable the account once in AD and every federated app closes. |
| Assertion | Signed by the IdP, scoped to this audience, valid for minutes. |
Service provider details
The values configured on the AuthPoint side for this application.
- Entity ID
- https://saml.wgindo.com/saml/metadata
- Assertion consumer service
- https://saml.wgindo.com/saml/acs
- Binding
- HTTP-POST
- Assertion signing
- Required — unsigned assertions are rejected
- Method floor
- Any method permitted by identity provider policy