<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in ESET Secure Authentication?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>ESA Web Console</strong> – Central management for users, components and authentication policies.<br /> <strong>Windows Login plugin</strong> – Adds a second factor to Windows computer logins.<br /> <strong>Remote Desktop plugin</strong> – Protects Remote Desktop Protocol sessions with a second factor.<br /> <strong>RADIUS server</strong> – Adds 2FA to VPN and other RADIUS-based logins.<br /> <strong>Web and SAML plugins</strong> – Cover Outlook Web App, SharePoint, AD FS and SAML services.<br /> <strong>Important</strong> – No macOS or Linux desktop login plugin is included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of ESET Secure Authentication?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">ESET Secure Authentication adds a second login factor to Windows computers, remote desktop sessions, VPN gateways and Microsoft web applications, managed centrally from a console rather than configured device by device. ESET now uses the name ESET Secure Authentication for the cloud service reached through ESET PROTECT Hub and ESET Secure Authentication On-Prem for the self-hosted deployment, which many buyers still search for under the plain product name.<br /><br /> <strong>Single subscription</strong> – The same subscription covers cloud and on-premises deployment<br /> <strong>Push approval</strong> – One tap on the phone replaces typing a code<br /> <strong>Offline authentication</strong> – Twenty cached one-time passwords by default for offline Windows logins<br /> <strong>Existing token reuse</strong> – Imports OATH hard tokens from a PSKC file<br /> <strong>MSP multitenancy</strong> – One cloud console manages several customer companies separately<br /> <strong>Custom application API</strong> – REST API adds 2FA to in-house applications</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="vpn-protection-myths"><strong>What Does a VPN Protect Against and What Doesn't It? Debunking the Most Common Myths</strong><br />Explains which risks a VPN tunnel actually removes and which ones remain at the login itself.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is ESET Secure Authentication suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Company size matters less here than two other questions: which sector you operate in, and whether you already run a directory. Sector decides whether a reporting obligation applies to you at all, and an existing Active Directory or LDAP decides how much manual user administration the rollout costs you.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">If supplier</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Active Directory or LDAP in place</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partly</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ESET Secure Authentication meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The revised Information Security Act (ISG) obliges operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report; this has applied since 1 April 2025 and has been backed by penalties since 1 October 2025. Whether you are affected depends on your sector, not on your headcount, so a small municipal utility can be in scope while a much larger industrial supplier is not. ESET Secure Authentication supports the preventive side of that duty by protecting exactly the access paths that attackers use to walk in with valid credentials: VPN gateways, remote desktop sessions and Windows logins. It also produces an authentication log showing who authenticated where and when, which is the kind of evidence that shortens the reconstruction work when a report has to be filed. What it does not do is detect the attack, assess whether the incident crosses the reporting threshold, or generate the report itself, and it holds authentication logs for 30 days in the cloud version, which is shorter than most incident investigations need, so export them if you rely on them. This description is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ESET Secure Authentication meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management rather than any single tool. NIS 2 asks essential and important entities to implement a set of measure categories, including access control policies, cryptography, incident handling, business continuity and backup, supply chain security, basic cyber hygiene, and specifically the use of multi-factor authentication or continuous authentication solutions. ESET Secure Authentication addresses that last category directly and contributes to access control by enforcing a second factor on remote access and administrative logins. It leaves the remaining categories untouched: it performs no backup, no incident detection or handling, no vulnerability management, no supplier assessment and no awareness training. Treat it as one named measure inside a wider programme, not as a substitute for one.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the backup and continuity side that multi-factor authentication does not address on its own.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does ESET Secure Authentication help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for a specific and frequently asked block of questions, and not beyond it. It answers the items on multi-factor authentication for remote access, MFA for administrative and privileged accounts, second-factor protection of webmail, whether authentication is centrally managed and enforced, whether phishing-resistant methods such as FIDO are available, and whether authentication events are logged. It does not answer questions on endpoint protection, patch and vulnerability management, disk encryption, backup and restore testing, email filtering, log retention beyond 30 days in the cloud version, or single sign-on and conditional access policies. If a questionnaire keeps hitting those gaps, the cheaper route is usually to move up within the same family rather than to mix vendors: ESET PROTECT Elite already contains this multi-factor authentication component alongside endpoint protection, full disk encryption, vulnerability and patch management and XDR, which means one console, one supplier and one contract to document instead of four.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains the endpoint protection layer that sits next to multi-factor authentication in most questionnaires.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between ESET Secure Authentication and ESET Secure Authentication On-Prem?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is who runs the authentication server: in the cloud version ESET hosts and maintains it and you reach the console through ESET PROTECT Hub, while On-Prem you install and patch it on your own Windows server. That single choice pulls three consequences with it. The cloud version is the only one with multitenancy for managed service providers, but it drops Sites for grouping, keeps logs for 30 days instead of as long as your storage allows, and accepts only RADIUS clients that validate the first factor themselves. Older VPN concentrators and appliances that hand the whole credential to the RADIUS server therefore still require the on-premises deployment. Both deployments run on the same subscription, so this is an architecture decision rather than a purchasing one.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Difference</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">ESET Secure Authentication</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">ESET Secure Authentication On-Prem</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Console hosting</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">ESET PROTECT Hub</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Your own server</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Updates and maintenance</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Handled by ESET</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Your IT team</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Multitenancy for MSPs</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Sites for grouping</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">RADIUS clients without first-factor check</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Log retention</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">30 days</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited by storage</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Directory synchronisation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Via sync agent</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Full AD and LDAP sync</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The desktop login plugin covers Windows only, so macOS and Linux workstations cannot be given a second factor at the local login; those systems can only be reached indirectly if they authenticate through RADIUS or a SAML identity provider. Web application protection is aimed at on-premises Microsoft products, specifically Outlook Web App and the Exchange Admin Center on Exchange 2013 through 2019 and Subscription Edition, SharePoint, Dynamics CRM and Remote Desktop Web Access; Outlook and comparable mail clients cannot be protected because of the RPC over HTTPS protocol they use, and Microsoft 365 is reached only indirectly through AD FS or the SAML identity provider connector. Hard tokens are supported as long as they are OATH-compliant and importable as a PSKC file, but ESET does not sell tokens, so that is a separate procurement. SMS delivery of one-time passwords is not included by default and needs SMS credits or your own SMS gateway, and ESET notes that SMS delivery depends on local telecommunications operators and cannot be guaranteed, which matters if you have staff working abroad. Only one FIDO authenticator can be registered per user, which rules out the common practice of enrolling a backup security key.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about ESET Secure Authentication</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it still work when the internet connection is down?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for Windows login. In offline mode the client caches 20 one-time passwords by default, and only event-based methods work: hard tokens, event-based OTPs from the mobile app, and FIDO. The cache refills automatically after the next successful online login, and the component also retries roughly ten minutes after an offline login and hourly after that.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Where is the data of the cloud version stored?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The cloud console runs through ESET PROTECT Hub, which ESET operates on Microsoft Azure with the physical data centre location exclusively inside the European Union, and backups are kept in the European Union as well. For Swiss buyers this is an EU location rather than a Swiss one, which is usually acceptable but is worth confirming against your own data location policy.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Do we need to buy it separately if we already use ESET PROTECT?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">It depends on the tier. Multi-factor authentication is already contained in ESET PROTECT Elite, while lower tiers such as Entry, Advanced and Complete do not include it and can be extended with ESET Secure Authentication as an add-on module without moving the whole organisation to a higher tier.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it protect applications we developed ourselves?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The ESA Authentication Server exposes a REST-based API, and the documentation for it is published by the console itself at the console address followed by /apidoc. This is the usual route for adding a second factor to an in-house web application or an internal tool that has no RADIUS or SAML support.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-mfa,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>