Skip to main content
haldahan
Staff
Staff
May 10, 2024

Technical Tip: Configuring SAML SSO login for SSL VPN with Azure AD acting as SAML IdP in FortiManager

  • May 10, 2024
  • 0 replies
  • 1852 views
Description This article describes how to configure SAML SSO login for SSL VPN with Azure AD acting as the SAML IdP in FortiManager and pushing to multiple FortiGates.
Scope FortiManager, SAML.
Solution
  1. Enable 'CLI Only Objects' under Policy & Objects -> Object Configurations -> Tools -> Display Options.

1.1 (1).jpg

 

1.2.jpg

 

  1. Configure the SAML user. Ensure that identity provider (IdP)-related entries match the Azure-side configuration.

 

2.1 (1).jpg

 

2.2.jpg

 

  1. Create a User Group under Policy & Objects -> Object Configurations -> CLI Only Objects:

3.1.jpg

 

4.2.jpg

 

3.3.jpg

 

Notes:

  • It is also possible to create a User Group under Policy & Objects -> Object Configurations -> CLI Only Objects.
  • 'Config Match' will only appear after creating a User Group.

3.4.jpg

 

  1. Configure group matching based on Azure Active Directory Group ObjectId.

4.1.jpg

 

3.2.jpg

 

  1. Go to VPN -> SSL VPN Settings. Configure as desired.
  2. Go to Policy & Objects. Create a new SSL VPN firewall policy or modify an existing one to apply to the group that contains the SAML user configured in step 3.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!