Technical Tip: Configuring SAML SSO login for SSL-VPN with ADFS by AD group
| Description | This article describes how to allow specific users by AD group on SSL-VPN with SAML authentication. |
| Scope | |
| Solution | 1) Configure ADFS and FortiGate:
2) Configure Claims on AD FS:
-Go to AD FS -> Relying Party Trusts -> 'Right click' -> Edit Claim Issuance Policy -> Edit Rule. - Select 'Token-Groups - Unqualified Names' under 'LDAP Attribute'. - Select 'OK'.
3) Ensure to use the correct AD group.
4) Additional FortiGate configuration.
# config user saml edit "adfs"
# config user group next
# config vpn ssl setting
Testing:
SAML attributes:
SAML debug:
samld_send_common_reply [122]: Attr: 17, 27, magic=cd82693da567030a |






