Technical Tip: IdP/Proxy Initiated SAML SSO Login is Not Supported for FortiGate Login
| Description | This article explains the limitation that Identity Provider (IdP)-initiated or Proxy-initiated SAML Single Sign-On (SSO) login is not supported for FortiGate login due to security concerns. |
| Scope | FortiGate. |
| Solution | FortiGate supports only Service Provider (SP)-initiated SAML SSO, as it provides better security and control over the login process. When users attempt to authenticate via IdP/Proxy-initiated SAML logins, the authentication will fail, resulting in an error. When an attempt is made to log into FortiGate using IdP/Proxy-initiated SAML SSO, the following errors may be seen in CLI debugs. Error "Bad request error" will be seen on GUI login page. diagnose debug application samld -1 It is recommended to always initiate SAML authentication from the FortiGate (SP) side to ensure proper SAML SSO authentication. Refer to the below KB article to configure Service Provider (SP) initiated SAML SSO login on FortiGate: |
