Technical Tip: FortiClient VPN Android fails to establish a VPN connection with IKEv2 and SAML with MFA enabled
| Description | This article describes the issue of FortiClient VPN Android failing to establish a VPN connection with IKEv2 and SAML authentication when Multifactor authentication (MFA) is enabled. |
| Scope | FortiGate, FortiClient Android. |
| Solution | When using FortiClient on Android with SAML authentication and Multifactor authentication (MFA) enabled, the application may unexpectedly close or dismiss the authentication screen when the user switches between FortiClient and the MFA application. As a result, the active authentication session is lost, and the user is unable to complete the login process after returning to FortiClient. This issue is specific to SAML authentication when Multifactor authentication (MFA) is involved. If SAML authentication is used without MFA (for example, IPsec VPN with SAML only on Android), this behavior does not occur, and authentication completes successfully.
Additionally, the FortiClient app may close immediately when minimized or when switching quickly between applications. This behavior further complicates completing multi-factor authentication on Android devices. This issue is related to the FortiClient Android application and is currently under investigation by the FortiClient engineering team. Workarounds:
Related document: |

