Skip to main content
mle2802
Staff
Staff
January 6, 2026

Troubleshooting Tip: Wrong username display wtih SAML SSO authentication

  • January 6, 2026
  • 0 replies
  • 534 views
Description This article describes how to troubleshoot the issue with wrong username displayed on the FortiGate using SAML SSO for authentication. In this example, IPsec VPN is used with Azure SAML SSO.
Scope FortiGate and Azure SAML SSO.
Solution

After a user successfully has logged in to the dial-up IPsec VPN using an SAML SSO, the member column may display 'userprincipalname' instead of the real username under IPsec VPN monitor.

Screenshot 2026-01-06 100303.png
This is caused by the attribute 'username' on Azure being configured with wrong source attribute. 

Screenshot 2026-01-06 100606.png
The correct source attribute in this scenario should be 'user.userprincipalname' instead of 'userprincipalname'.

Screenshot 2026-01-06 100845.png

 

After changing it, the username is correctly displayed on FortiGate.

Screenshot 2026-01-06 101121.png