Skip to main content
jkoay
Staff & Editor
Staff & Editor
December 30, 2025

Troubleshooting Tip: Endpoint Profile cannot be applied to Entra ID group when authenticated onboarding is enabled

  • December 30, 2025
  • 0 replies
  • 372 views
Description This article describes issues where endpoint profiles are not applied to the configured Entra ID group when authenticated onboarding is enabled.
Scope FortiSASE, FortiClient.
Solution

The following solution is only applied to FortiSASE that is running on Feature release with authenticated onboarding enabled.

In order for FortiSASE to correctly identify Entra ID user and its group memberships, when configuring authenticated onboarding (Access & Authentication -> SSO -> Authenticated onboarding) in FortiSASE, ensure that the option 'Include associated domain' is enabled and select the Entra ID domain configured in Access & Authentication -> Domains.

 

image (34).png

 

This will ensure that when the Entra user is being authenticated during onboarding, the user or group memberships are being recognized as from Entra ID.