> Source: [sk184647](https://support.checkpoint.com/results/sk/sk184647)

# sk184647 - One Identity - Unified Authentication for Check Point Portals

| Property | Value |
|----------|-------|
| Solution ID | sk184647 |
| Date Created | 2026-02-09 |
| Last Modified | 2026-05-07 |
| Technical Level | General |
| Products | Check Point Portal |
| Versions | Cloud |

## Solution

Overview
========

Check Point introduces **One Identity** - a unified authentication system. It allows you to access all Check Point web applications - including Check Point Portal, User Center, Support Center, and other business portals - with a single set of credentials.  

**Deployment Notice**   
One Identity is **rolled out gradually** . During the rollout, automatic account unification may not occur on the first login for all users. No manual merge action is required; unification is completed automatically once the capability is active for the user.  

What Changes
============

Previously, different Check Point portals required separate credentials. One Identity uses one username and password for all Check Point applications.  
For most users, the transition is seamless - you log in to any Check Point portal as you do, and the migration is handled automatically.

How One Identity Works
======================

Password Consolidation
----------------------

If you have accounts in multiple Check Point portals:

* When you log in for the first time after One Identity activation, the service verifies your existing passwords.
* After verification, One Identity sets one password for all Check Point portals.
* You see a message confirming that this password is used across all applications.

No action is required.

Multi-Factor Authentication (MFA)
---------------------------------

If you use an authenticator application:

* After your first login with the authenticator, such as Microsoft Entra ID or Okta, One Identity applies the same MFA configuration to all portals.
* If you used SMS on some portals and an authenticator on others, One Identity sets the authenticator as your primary MFA method.

Regional Account Consolidation
------------------------------

If you have regional accounts outside US/EU datacenters (Canada, Australia, etc.):

* Access requests automatically redirect to the global authentication URL.
* Your unified credentials work across all regions.
* You can switch regions from within the Check Point Portal interface.

Single Sign-On (SSO) and Identity Provider (IDP) Integration
------------------------------------------------------------

If your organization uses SSO:

* When you enter your email, One Identity checks your last active region.
* If no previous region exists, you log in with username and password.
* If a region exists, One Identity checks for an IDP configuration:
  * If an IDP exists, you are redirected to your organization's login page.
  * If no IDP exists, you log in with username and password.

Do Users Need to Do Anything?
-----------------------------

Most users do not need to take any action. See below a detailed user migration guide.

### Recommended:

* Continue using your current credentials.
* Follow on?screen prompts about password or MFA updates.
* Update your password manager after the first login.

Benefits
========

* **Simplified Access**: One set of credentials for all Check Point applications
* **Enhanced Security**: Unified MFA across all portals
* **Seamless Experience**: No need to remember multiple passwords
* **Global Access**: Easy switching between regional accounts
* **SSO Integration**: Automatic detection and use of your organization's Identity Provider

Need Help?
==========

If you encounter issues during the transition, contact [Check Point Support](https://support.checkpoint.com/).  

*** ** * ** ***

User Migration Guide
====================

**Key Principle** : The login flows and user experience depend on two factors:  

1. Where the user starts --- the Portal (portal.checkpoint.com) or any UC-linked service (e.g. usercenter.checkpoint.com, pmap.checkpoint.com, support.checkpoint.com, etc.)
2. What accounts the user already has

Scenario 1 --- New User Signing Up
----------------------------------

**Applies to:** Users with no existing Portal or UC account.  

### Flow:

1. The user navigates to any Check Point web service (Portal or UC-linked).
2. The user selects **Sign Up** and completes the core identity setup:
   * Username and password
   * Two-Factor Authentication (2FA)
3. After the core account is created, the user is prompted to complete additional profile information depending on their entry point:
   * **Started from the Portal**? Complete Portal-specific profile fields.
   * **Started from a UC-linked service** ? Complete UC-specific profile fields.
4. The user is granted access to the service they started from.

Scenario 2 --- User Exists in UC Only (No Portal Account)
---------------------------------------------------------

**Applies to** : Users who have a UserCenter account but have never registered with the Check Point Portal.  

### Flow A --- User starts from a UC-linked service:

1. The user navigates to a UC-linked service (e.g. usercenter.checkpoint.com).
2. The user logs in with their existing UC credentials.
3. One Identity recognizes the credentials. ? **Access is granted seamlessly** --- no additional steps required.

### Flow B --- User starts from the Portal:

1. The user navigates to portal.checkpoint.com.
2. The user logs in with their existing UC credentials.
3. One Identity recognizes the credentials but detects that Portal profile information is missing.
4. The user is prompted to complete the Portal-specific profile fields (same screen as Scenario 1, Portal flow).
5. ? Portal access is granted.

<br />

Scenario 3 --- User Has a Portal Account Only (No UC Account)
-------------------------------------------------------------

**Applies to** : Users who have a Check Point Portal account but have never registered with UserCenter.  

### Flow A --- User starts from the Portal:

1. The user navigates to portal.checkpoint.com.
2. The user logs in with their existing Portal credentials.
3. One Identity recognizes the credentials. ? Access is granted seamlessly --- no additional steps required.

### Flow B --- User starts from a UC-linked service:

1. The user navigates to a UC-linked service (e.g. usercenter.checkpoint.com).
2. The user logs in with their existing Portal credentials.
3. One Identity recognizes the credentials but detects that UC profile information is missing.
4. The user is prompted to complete the UC-specific profile fields (same screen as Scenario 1, UC flow).
5. ? UC access is granted.

Scenario 4 --- User Has Accounts in Both Portal and UC
------------------------------------------------------

**Applies to** : Users with existing accounts in both the Portal and UserCenter. Passwords may be the same or different.  

### Flow:

1. The user navigates to any Check Point web service (Portal or UC-linked).
2. The user enters any one of their existing passwords (Portal or UC).
3. One Identity validates the entered password against all previously saved credentials.
4. If a match is found:
   * The user is notified: "From now on, this password will be used for  
     all Check Point Portals"
   * ? Access is granted. Credentials are unified under One Identity.
5. If no match is found, the user is prompted to try their other password or reset it.

> Note: This unification happens automatically on the first successful login. The user does not need to take any separate merge or linking action.

Scenario 5 --- BYO-IDP User Connecting to a UC-linked Service
-------------------------------------------------------------

**Applies to** : Users whose organization has configured a Bring Your Own Identity Provider (BYO-IDP) on their Check Point Portal tenant, and who are now accessing a UC-linked service.  

### Flow:

1. The user navigates to a UC-linked service (e.g. usercenter.checkpoint.com).
2. The user enters their email address on the One Identity login page.
3. One Identity checks whether the user's email domain is associated with a Portal tenant that has BYO-IDP configured.

### If a linked BYO-IDP tenant is found:

* The user is redirected to their organization's configured Identity Provider (e.g. Azure AD, Okta, or another SSO provider).
* The user authenticates via their organization's IDP.
* ? UC access is granted.

### If no linked BYO-IDP tenant is found:

* The login reverts to standard UC credential authentication.
* The user logs in with their UC username and password.
* ? UC access is granted.

> Note: BYO-IDP redirection is only triggered when the UC service is explicitly linked to the Portal tenant that has BYO-IDP configured. Unlinked tenants or unrecognized domains always fall back to standard UC authentication.

Summary Table
-------------

|---|---------------------|-----------------------------------|---------------------------------------|
| # | **User State**      | **Starts from Portal**            | **Starts from UC-linked Service**     |
| 1 | New User            | Sign up ? Complete Portal profile | Sign up ? Complete UC profile         |
| 2 | UC account only     | Login ? Complete Portal profile   | Login ? ? Seamless                    |
| 3 | Portal account only | Login ? ? Seamless                | Login ? Complete UC profile           |
| 4 | Both Portal \& UC   | Login with any password ? Unified | Login with any password ? Unified     |
| 5 | BYO-IDP configured  | Domain check ? BYO-IDP            | Domain check ? BYO-IDP or UC fallback |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
