Skip to main content
avenditti
Staff
Staff
February 11, 2025
Question

FortiOS integration with Azure (WiFi users)

  • February 11, 2025
  • 2 replies
  • 1256 views

Hi guys,

 

I have a customer requesting FortiOS integration with Azure to authenticate WiFi users.

 

While researching, I found numerous references related to VPN user authentication.

What seems odd to me is that in all the articles, Azure requires specifying the authentication purpose. For example:
"Go to Enterprise Applications → New Application → Search for 'FortiGate' → Select 'FortiGate SSL VPN' and assign a name."

 
 

From my perspective, a FortiGate user group can be used for various services (VPN authentication, firewall policy authentication, captive portal authentication, etc.), so why does Azure require defining a specific ones?

More importantly, if I create a group for VPN authentication in Azure, could this prevent it from working for firewall policy authentication or other use cases?

 

Thanks in advance

A

 

 

2 replies

Dhruvin_patel
Staff
Staff
February 11, 2025

Greetings!

 

I understand you would like to authenticate wifi users with azure.

What authentication method are looking to use?

 

The information you have posted is required if you would like to authenticate using the SAML-based authentication method.

"""

What seems odd to me is that in all the articles, Azure requires the authentication purpose to be specified. For example:
"Go to Enterprise Applications → New Application → Search for 'FortiGate' → Select 'FortiGate SSL VPN' and assign a name."

"""

 

First of all, please tell us which authentication methods you would like to use.

 

Regards!

avenditti
Staff
avendittiAuthor
Staff
February 13, 2025

First of all thank you Dhruvin,

 

what I know is that the Customer currently uses an SSID with the security mode set to WPA2-Enterprise and performs authentication through a "Local" LDAP group.

current confcurrent conf

I have no constraints on using a SAML-based authentication method, my only requirement is to replicate the current setup (or make the necessary adjustments) using Azure instead of the Local LDAP.

I have no experience with Azure integration, so I might be missing some key references.

 

Regards,

Angelo

hp93
New Member
May 6, 2025

I hope you found what you need by now. If not, here it is the link for step-by-step config

Configure SAML SSO for WiFi SSID over Cap... - Fortinet Community