Skip to main content
emmanuelgonzalez914
Staff
Staff
July 21, 2026

Technical Tip: Web browser launcher uses the existing SAML SSO session when FortiPAM and the target application share the same Identity Provider

  • July 21, 2026
  • 0 replies
  • 63 views

Description

This article describes why a Web Browser Launcher may authenticate with the same SAML Single Sign-On (SSO) user that is already authenticated in the FortiPAM administrative session, even when the secret is configured with a different account.

Scope

FortiPAM.

Solution

This behavior is expected when both the FortiPAM administrative login and the target web application use the same SAML Identity Provider (IdP).

Consider the following example:


Both accounts belong to the fortinet.com domain and authenticate through the same Microsoft Entra ID tenant.

The authentication flow is as follows:

  1. The administrator authenticates to FortiPAM by using Microsoft Entra ID.

  2. The web browser stores a valid authentication cookie issued by the Identity Provider for regular.user@fortinet.com.

  3. When the Web Browser Launcher opens the target website, the website redirects the authentication request to the same Identity Provider.

  4. The browser automatically sends the existing authentication cookie to Microsoft Entra ID.

  5. Because the authentication session is still valid, Microsoft Entra ID completes the authentication silently without displaying a login page.

  6. Since no authentication page is presented, FortiPAM does not have an opportunity to inject the credentials stored in the secret.

  7. The target application is authenticated as regular.user@fortinet.com instead of admin.fortinet@fortinet.com.


The following diagram illustrates the authentication flow when FortiPAM and the target application use the same SAML Identity Provider:

ea9c0fa6.jpg


This behavior is inherent to SAML SSO authentication and is not caused by FortiPAM. Credential injection can only occur when a login page is presented. If the Identity Provider has already authenticated the browser session, the authentication process is completed before FortiPAM can inject the credentials configured in the secret.

If credential injection is required, access to FortiPAM must use an authentication method other than SAML SSO, preventing the browser from reusing an existing Identity Provider session.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!