> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/1.4/features.md).

# Features

- [Overview](https://docs.defguard.net/1.4/features/overview.md)
- [Zero-Trust VPN with 2FA/MFA](https://docs.defguard.net/1.4/features/wireguard.md)
- [Create/Manage VPN Location](https://docs.defguard.net/1.4/features/wireguard/create-your-vpn-network.md)
- [Network overview](https://docs.defguard.net/1.4/features/wireguard/network-overview.md)
- [Multi-Factor Authentication (MFA/2FA)](https://docs.defguard.net/1.4/features/wireguard/multi-factor-authentication-mfa-2fa.md): Defguard is the sole VPN solution that genuinely implements Multi-Factor Authentication (MFA) before a WireGuard® VPN connection is established, significantly enhancing security against cyberattacks.
- [Internal SSO based MFA](https://docs.defguard.net/1.4/features/wireguard/multi-factor-authentication-mfa-2fa/internal-sso-based-mfa.md)
- [External SSO based MFA](https://docs.defguard.net/1.4/features/wireguard/multi-factor-authentication-mfa-2fa/external-sso-based-mfa.md)
- [Remote desktop client configuration](https://docs.defguard.net/1.4/features/wireguard/remote-desktop-activation.md): How to manually generate token for user as an administrator.
- [VPN & Client behaviour customization](https://docs.defguard.net/1.4/features/wireguard/behavior-customization.md)
- [DNS and domains](https://docs.defguard.net/1.4/features/wireguard/dns-and-domains.md)
- [Executing custom gateway commands](https://docs.defguard.net/1.4/features/wireguard/executing-custom-gateway-commands.md)
- [Remote user enrollment](https://docs.defguard.net/1.4/features/remote-user-enrollment.md)
- [User onboarding after enrollment](https://docs.defguard.net/1.4/features/remote-user-enrollment/user-onboarding-after-enrollment.md)
- [Automatic (real time) desktop client configuration & sync](https://docs.defguard.net/1.4/features/remote-user-enrollment/automatic-real-time-desktop-client-configuration.md)
- [Internal SSO (OpenID Connect Provider)](https://docs.defguard.net/1.4/features/openid-connect.md)
- [Portainer](https://docs.defguard.net/1.4/features/openid-connect/portainer.md)
- [Grafana setup](https://docs.defguard.net/1.4/features/openid-connect/grafana-setup.md)
- [Proxmox](https://docs.defguard.net/1.4/features/openid-connect/proxmox.md)
- [Matrix / Synapse](https://docs.defguard.net/1.4/features/openid-connect/proxmox-1.md)
- [Django](https://docs.defguard.net/1.4/features/openid-connect/django.md)
- [MinIO](https://docs.defguard.net/1.4/features/openid-connect/minio.md)
- [Vault](https://docs.defguard.net/1.4/features/openid-connect/vault.md)
- [External SSO/OpenID providers](https://docs.defguard.net/1.4/features/external-openid-providers.md)
- [Google](https://docs.defguard.net/1.4/features/external-openid-providers/google.md)
- [Microsoft](https://docs.defguard.net/1.4/features/external-openid-providers/microsoft.md)
- [Okta](https://docs.defguard.net/1.4/features/external-openid-providers/okta.md)
- [JumpCloud](https://docs.defguard.net/1.4/features/external-openid-providers/jumpcloud.md)
- [Keycloak](https://docs.defguard.net/1.4/features/external-openid-providers/keycloak.md)
- [Zitadel](https://docs.defguard.net/1.4/features/external-openid-providers/zitadel.md)
- [Custom](https://docs.defguard.net/1.4/features/external-openid-providers/custom.md)
- [External OIDC secure enrollment](https://docs.defguard.net/1.4/features/external-openid-providers/external-oidc-secure-enrollment.md)
- [LDAP and Active Directory integration](https://docs.defguard.net/1.4/features/ldap-and-active-directory-integration.md)
- [Configuration](https://docs.defguard.net/1.4/features/ldap-and-active-directory-integration/configuration.md): How to configure connection between Defguard instance and LDAP.
- [Settings table](https://docs.defguard.net/1.4/features/ldap-and-active-directory-integration/settings-table.md): List with description of settings for LDAP found in settings page.
- [Two-way LDAP and Active Directory synchronization](https://docs.defguard.net/1.4/features/ldap-and-active-directory-integration/two-way-ldap-and-active-directory-synchronization.md)
- [Access Control List](https://docs.defguard.net/1.4/features/access-control-list.md)
- [ACL Aliases](https://docs.defguard.net/1.4/features/access-control-list/acl-aliases.md)
- [Implementation Details](https://docs.defguard.net/1.4/features/access-control-list/firewall-internals.md)
- [Network devices](https://docs.defguard.net/1.4/features/network-devices.md)
- [Activity & Audit logs](https://docs.defguard.net/1.4/features/activity-log.md)
- [Audit Log Streaming to SIEM systems](https://docs.defguard.net/1.4/features/activity-log/activity-log-streaming.md): This feature is designed to help teams centralize visibility into user actions, security events, and system behavior by integrating with tools they already use for monitoring and incident response.
- [Supported SIEM systems integrations](https://docs.defguard.net/1.4/features/activity-log/activity-log-streaming/activity-log-integrations.md): List of supported services to stream activity logs into.
- [Vector integration guide](https://docs.defguard.net/1.4/features/activity-log/activity-log-streaming/activity-log-integrations/vector-integration-guide.md): How to stream activity logs to vector.
- [Logstash integration guide](https://docs.defguard.net/1.4/features/activity-log/activity-log-streaming/activity-log-integrations/logstash-integration-guide.md): How to stream activity logs to vector.
- [Notifications](https://docs.defguard.net/1.4/features/notifications.md)
- [Email notifications](https://docs.defguard.net/1.4/features/notifications/setting-up-smtp-for-email-notifications.md)
- [Gateway notifications](https://docs.defguard.net/1.4/features/notifications/gateway-notifications.md)
- [New version notifications](https://docs.defguard.net/1.4/features/notifications/new-version-notifications.md)
- [Integrations](https://docs.defguard.net/1.4/features/integrations.md)
- [Webhooks](https://docs.defguard.net/1.4/features/integrations/webhooks.md)
- [REST API](https://docs.defguard.net/1.4/features/integrations/api-tokens.md)
- [OPSense Configuartion](https://docs.defguard.net/1.4/features/gateway.md)
- [SSH Authentication](https://docs.defguard.net/1.4/features/ssh-authentication.md)
- [Forward auth](https://docs.defguard.net/1.4/features/forward-auth.md)
- [YubiKey Provisioning](https://docs.defguard.net/1.4/features/yubikey-provisioning.md): Provisioner repository: https://github.com/DefGuard/YubiKey-Provision
- [User SNAT bindings](https://docs.defguard.net/1.4/features/user-snat-bindings.md)
