What are the key advantages of ESET Secure Authentication?
Central console – Cloud console via ESET PROTECT Hub, or on-premises.
Login coverage – Windows login, remote desktop and VPN via RADIUS.
Authentication choice – Push, mobile OTP, FIDO and OATH hard tokens.
Offline logins – Cached one-time passwords keep Windows login working offline.
Microsoft apps – 2FA for Outlook Web App, SharePoint and Remote Desktop.
Important note – No macOS or Linux desktop login plugin.
ESA Web Console – Central management for users, components and authentication policies.
Windows Login plugin – Adds a second factor to Windows computer logins.
Remote Desktop plugin – Protects Remote Desktop Protocol sessions with a second factor.
RADIUS server – Adds 2FA to VPN and other RADIUS-based logins.
Web and SAML plugins – Cover Outlook Web App, SharePoint, AD FS and SAML services.
Important – No macOS or Linux desktop login plugin is included.
ESET Secure Authentication adds a second login factor to Windows computers, remote desktop sessions, VPN gateways and Microsoft web applications, managed centrally from a console rather than configured device by device. ESET now uses the name ESET Secure Authentication for the cloud service reached through ESET PROTECT Hub and ESET Secure Authentication On-Prem for the self-hosted deployment, which many buyers still search for under the plain product name.
Single subscription – The same subscription covers cloud and on-premises deployment
Push approval – One tap on the phone replaces typing a code
Offline authentication – Twenty cached one-time passwords by default for offline Windows logins
Existing token reuse – Imports OATH hard tokens from a PSKC file
MSP multitenancy – One cloud console manages several customer companies separately
Custom application API – REST API adds 2FA to in-house applications
Company size matters less here than two other questions: which sector you operate in, and whether you already run a directory. Sector decides whether a reporting obligation applies to you at all, and an existing Active Directory or LDAP decides how much manual user administration the rollout costs you.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | ✓ | ✓ |
| Security questionnaire from large customers | If supplier | ✓ | ✓ |
| Active Directory or LDAP in place | Sometimes | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partly |
The revised Information Security Act (ISG) obliges operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report; this has applied since 1 April 2025 and has been backed by penalties since 1 October 2025. Whether you are affected depends on your sector, not on your headcount, so a small municipal utility can be in scope while a much larger industrial supplier is not. ESET Secure Authentication supports the preventive side of that duty by protecting exactly the access paths that attackers use to walk in with valid credentials: VPN gateways, remote desktop sessions and Windows logins. It also produces an authentication log showing who authenticated where and when, which is the kind of evidence that shortens the reconstruction work when a report has to be filed. What it does not do is detect the attack, assess whether the incident crosses the reporting threshold, or generate the report itself, and it holds authentication logs for 30 days in the cloud version, which is shorter than most incident investigations need, so export them if you rely on them. This description is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management rather than any single tool. NIS 2 asks essential and important entities to implement a set of measure categories, including access control policies, cryptography, incident handling, business continuity and backup, supply chain security, basic cyber hygiene, and specifically the use of multi-factor authentication or continuous authentication solutions. ESET Secure Authentication addresses that last category directly and contributes to access control by enforcing a second factor on remote access and administrative logins. It leaves the remaining categories untouched: it performs no backup, no incident detection or handling, no vulnerability management, no supplier assessment and no awareness training. Treat it as one named measure inside a wider programme, not as a substitute for one.
Yes, for a specific and frequently asked block of questions, and not beyond it. It answers the items on multi-factor authentication for remote access, MFA for administrative and privileged accounts, second-factor protection of webmail, whether authentication is centrally managed and enforced, whether phishing-resistant methods such as FIDO are available, and whether authentication events are logged. It does not answer questions on endpoint protection, patch and vulnerability management, disk encryption, backup and restore testing, email filtering, log retention beyond 30 days in the cloud version, or single sign-on and conditional access policies. If a questionnaire keeps hitting those gaps, the cheaper route is usually to move up within the same family rather than to mix vendors: ESET PROTECT Elite already contains this multi-factor authentication component alongside endpoint protection, full disk encryption, vulnerability and patch management and XDR, which means one console, one supplier and one contract to document instead of four.
The decisive difference is who runs the authentication server: in the cloud version ESET hosts and maintains it and you reach the console through ESET PROTECT Hub, while On-Prem you install and patch it on your own Windows server. That single choice pulls three consequences with it. The cloud version is the only one with multitenancy for managed service providers, but it drops Sites for grouping, keeps logs for 30 days instead of as long as your storage allows, and accepts only RADIUS clients that validate the first factor themselves. Older VPN concentrators and appliances that hand the whole credential to the RADIUS server therefore still require the on-premises deployment. Both deployments run on the same subscription, so this is an architecture decision rather than a purchasing one.
| Difference | ESET Secure Authentication | ESET Secure Authentication On-Prem |
|---|---|---|
| Console hosting | ESET PROTECT Hub | Your own server |
| Updates and maintenance | Handled by ESET | Your IT team |
| Multitenancy for MSPs | ✓ | ✕ |
| Sites for grouping | ✕ | ✓ |
| RADIUS clients without first-factor check | ✕ | ✓ |
| Log retention | 30 days | Limited by storage |
| Directory synchronisation | Via sync agent | Full AD and LDAP sync |
The desktop login plugin covers Windows only, so macOS and Linux workstations cannot be given a second factor at the local login; those systems can only be reached indirectly if they authenticate through RADIUS or a SAML identity provider. Web application protection is aimed at on-premises Microsoft products, specifically Outlook Web App and the Exchange Admin Center on Exchange 2013 through 2019 and Subscription Edition, SharePoint, Dynamics CRM and Remote Desktop Web Access; Outlook and comparable mail clients cannot be protected because of the RPC over HTTPS protocol they use, and Microsoft 365 is reached only indirectly through AD FS or the SAML identity provider connector. Hard tokens are supported as long as they are OATH-compliant and importable as a PSKC file, but ESET does not sell tokens, so that is a separate procurement. SMS delivery of one-time passwords is not included by default and needs SMS credits or your own SMS gateway, and ESET notes that SMS delivery depends on local telecommunications operators and cannot be guaranteed, which matters if you have staff working abroad. Only one FIDO authenticator can be registered per user, which rules out the common practice of enrolling a backup security key.
Yes, for Windows login. In offline mode the client caches 20 one-time passwords by default, and only event-based methods work: hard tokens, event-based OTPs from the mobile app, and FIDO. The cache refills automatically after the next successful online login, and the component also retries roughly ten minutes after an offline login and hourly after that.
The cloud console runs through ESET PROTECT Hub, which ESET operates on Microsoft Azure with the physical data centre location exclusively inside the European Union, and backups are kept in the European Union as well. For Swiss buyers this is an EU location rather than a Swiss one, which is usually acceptable but is worth confirming against your own data location policy.
It depends on the tier. Multi-factor authentication is already contained in ESET PROTECT Elite, while lower tiers such as Entry, Advanced and Complete do not include it and can be extended with ESET Secure Authentication as an add-on module without moving the whole organisation to a higher tier.
Yes. The ESA Authentication Server exposes a REST-based API, and the documentation for it is published by the console itself at the console address followed by /apidoc. This is the usual route for adding a second factor to an in-house web application or an internal tool that has no RADIUS or SAML support.
Adds MFA to Windows logins, remote desktop and VPN via RADIUS. Push, mobile OTP, FIDO and hard tokens; no macOS or Linux login plugin.
ESET Secure Authentication, ESET, ESET PROTECT, ESET Secure Authentication On-Prem, multi-factor authentication, two-factor authentication, push authentication, VPN login protection, RADIUS
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies