Technical Tip: Configuring Authentik as SAML provider for FortiOS admins
| Description | This article describes how to configure Authentik as a SAML provider for FortiOS admin users. |
| Scope | FortiOS v7.2.x, v7.4.x, and v7.6.x. |
| Solution | Authentik is a self-hosted, open source identity provider that can be configured as a SAML identity provider. Configure the following to connect it with FortOS.
Authentik Configuration: Begin by logging in as an administrator in Authentik.
After creation, configure the required user/group bindings.
FortiGate Configuration: Begin by logging in as a current admin to the FortiGate. Navigate to Security Fabric -> Fabric Connectors -> Security Fabric Setup -> Single Sign-On Settings.
Note: In the sign-on and logout URLs, the slug 'fortigate_admin' from above is configured.
After configuration is complete, log out and log back in with the SAML identity to confirm that it is working as expected. A new SSO entry will be listed under System -> Administrators.
|





