Cloud-native SASE platform combining ZTNA, SWG, and FWaaS for hybrid workforces. Managed via WatchGuard Cloud with multi-tenant support built for MSPs and SMEs.
FireCloud Total Access redefines secure remote access with a zero trust approach tailored for modern, hybrid workforces. It replaces risky VPNs with identity-aware access to cloud apps and private resources, ensuring users only reach what they are authorized to use. Integrated Firewall as a Service (FWaaS), threat detection, and web filtering provide full-spectrum protection - all from a single, cloud-native platform.
Identity Provider Integrations
FireCloud Total Access integrates with the identity providers your organization already uses. Supported options include:
Microsoft Entra ID - Connect your existing Azure AD directory for seamless authentication
Okta - Leverage Okta's identity platform for user authorization and access control
WatchGuard AuthPoint SAML - Use WatchGuard's own multi-factor authentication solution
Third-party SAML IdPs - Connect any SAML-compliant identity provider
WatchGuard Cloud Directory - Manage users directly within WatchGuard Cloud
Centralized reporting and logging are built into WatchGuard Cloud, giving you visibility across all security events and user activity from a single dashboard.
Compliance and Security Standards
WatchGuard Cloud holds ISO/IEC 27001:2022 certification and TX-RAMP Level 2 authorization, demonstrating a verified commitment to information security management and cloud security controls. FireCloud protects data in transit through encrypted VPN tunnels and supports TLS inspection to detect threats hidden in encrypted traffic.
Built for MSPs and Multi-Tenant Management
Designed with managed service providers in mind, FireCloud offers true multi-tenancy with capabilities that simplify operations at scale:
Single-pane management for multiple customer environments from one console
Centralized policies and reporting across all managed tenants
User allocation and templates for rapid, consistent tenant provisioning
MSP-focused multi-tenancy with isolated customer environments
Whether you manage five client environments or fifty, FireCloud Total Access gives MSPs the tools to enforce consistent security policies while reducing VPN complexity and lowering support overhead.
Getting Started - Step-by-Step Deployment
FireCloud Total Access is designed for fast deployment. Follow these steps to go from subscription to secured users:
Activate your license or free trial - Start with a 30-day free trial to evaluate the full platform
Configure your identity provider - Connect Microsoft Entra ID, Okta, or another supported SAML IdP
Review security settings - Customize policies for web filtering, threat detection, and access control
Install Connection Manager - Deploy the connection agent to your environment
Connect users - Onboard your workforce with identity-based access policies
Configure Firebox or Virtual Gateway - Extend protection to private resources
Add private resources - Define the applications and services users can securely access
Use Case: MSP Securing a Distributed Workforce
A regional MSP managing multiple SME clients needs to replace legacy VPN infrastructure that requires per-site hardware and generates constant support tickets. With FireCloud Total Access, the MSP provisions a new customer tenant from the WatchGuard Cloud console, connects the client's Microsoft Entra ID directory, and deploys identity-based access policies using templates. Remote employees install the FireCloud agent and immediately gain secure, policy-controlled access to only the cloud apps and private resources they are authorized to use - without a traditional VPN client. The MSP monitors all tenants from a single dashboard, enforces consistent security policies across every client, and eliminates the overhead of managing site-to-site VPN tunnels.
Start Your 30-Day Free Trial
FireCloud Total Access is available with a 30-day free trial directly through AWS Marketplace. Experience the full platform - including multi-tenant management, identity provider integration, FWaaS, and zero trust network access - before committing to a subscription. Subscribe today to activate your trial and follow the quick-start guide to deploy your first secured environment.
Highlights
Identity-Based Zero Trust Access: Replace legacy VPNs with modern, identity-driven connectivity to cloud and private applications from any location. FireCloud supports WatchGuard Cloud Directory, AuthPoint SAML, and third-party SAML identity providers including Microsoft Entra ID and Okta. Encrypted tunnels and TLS inspection protect data in transit, while identity-based policies enforce least-privilege access per user and application.
Unified SASE Security in a Single Platform: FireCloud combines Secure Web Gateway, Firewall-as-a-Service, and Zero Trust Network Access into one cloud-native platform managed entirely through WatchGuard Cloud. Instead of integrating separate point products, organizations get centralized policy management, consolidated reporting, and consistent threat protection across all traffic - reducing the number of tools and vendor relationships to maintain.
Multi-Tenant Architecture Purpose-Built for MSPs: Manage multiple customer environments from a single WatchGuard Cloud console with centralized policies, cross-tenant reporting, user allocation controls, and reusable policy templates. ISO/IEC 27001:2022 certified and TX-RAMP Level 2 compliant, FireCloud gives partners a scalable, auditable platform they can deploy across their entire customer base without duplicating administrative effort.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy FireCloud Total Access by user license under a contract. Pricing is organized into seven volume tiers based on how many user licenses you need: 1 to 50, 51 to 100, 101 to 250, 251 to 500, 501 to 1000, 1001 to 5000, and 5000+. As your user count grows, you move into a higher-volume tier. Each tier covers the same platform, so you choose the band that matches your total number of protected users. All tiers are billed on the same contract commitment.
Top-of-mind questions for buyers
What counts as one user license for billing?
A license covers one user who connects to the service through the connection manager. You can control access so only chosen user groups consume licenses. Users in your identity provider without an access rule cannot connect and do not consume a license. Each connecting user counts as one against your tier.
If my user count grows past my current tier, which price applies to my users?
Your total user count determines which single volume band applies. When you reach a higher band, the per-user rate for that band applies across your license count, not just the added users. The seven bands are 1 to 50, 51 to 100, 101 to 250, 251 to 500, 501 to 1000, 1001 to 5000, and 5000+.
Does the license cover access to private company network resources, or only Internet protection?
FireCloud Total Access includes access to local company network resources without a VPN. You deploy a Gateway on your network and configure private resources such as a printer or file share. Access rules control which resources each user group can reach. Firewall-as-a-Service, Secure Web Gateway, and Zero Trust Network Access are all included.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
WatchGuard provides multiple support channels for FireCloud Total Access customers:
Online Support
Online support is recommended for non-critical issues. Submit cases through the WatchGuard support portal, track status updates, and upload troubleshooting documents to help resolve issues more quickly. Visit: https://www.watchguard.com/wgrd-support/overview
Phone Support
Phone support is recommended for critical network failure situations or if you do not have access to the online support portal. Have your WatchGuard serial number ready when you call.
Phone: +1 (877) 232-3531
Email Support
Contact the support team directly at support@watchguard.com for assistance with configuration, troubleshooting, or account inquiries.
Getting Started
FireCloud Total Access includes a 30-day free trial. Deployment follows these steps: activate your license or trial, configure your identity provider (supports WatchGuard Cloud Directory, AuthPoint SAML, Microsoft Entra ID, and Okta), review settings, install the Connection Manager, connect users, configure your Firebox or Virtual Gateway, and add private resources. For step-by-step guidance, refer to the FireCloud Quick Start Guide at https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/FireCloud/firecloud_quick_start.html
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
WatchGuard FireCloud Internet Access delivers Cloud-native security for the hybrid workforce. As a core component of our Unified Security Platform architecture, it embodies our security, performance, and simplicity tenets. FireCloud provides robust protection against web-based threats, simplifies management, and optimizes connectivity for users everywhere, ensuring secure and productive access to their needed resources.
Award-winning cloud MFA with phishing-resistant passkeys, device DNA, and zero trust policies. Built for organizations and MSPs protecting endpoints, VPNs, and Microsoft Entra ID.
WatchGuard Firebox Cloud delivers unified threat management for AWS VPCs with IPS, antivirus, web filtering, and application control. Built for SMBs and distributed enterprises.
WatchGuard Firebox Cloud delivers unified threat management for AWS VPCs with IPS, antivirus, web filtering, and application control. Built for SMBs and distributed enterprises.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.