Skip to main content
sjoshi
Staff
Staff
August 18, 2025

Troubleshooting Tip: FortiSASE SAML VPN Authentication Failure for AD-Integrated Users on FortiAuthenticator

  • August 18, 2025
  • 0 replies
  • 285 views
Description

 

This article describes a scenario where FortiSASE SAML VPN authentication succeeds for local FortiAuthenticator users but fails for Active Directory (AD)–integrated users and how to troubleshoot it.

 

Scope

 

FortiSASE, FortiAuthenticator.

 

Solution

 

Users connect to the VPN in FortiSASE using SAML, with FortiAuthenticator acting as the IdP. The VPN connection works successfully for local users created on FortiAuthenticator.

 

However, when LDAP is integrated on FortiAuthenticator, the VPN connection fails for remote AD users. LDAP connection on the FortiAuthenticator is up and is able to import the AD user successfully on the FortiAuthenticator.

 

Verify that the required realm is created and properly linked to the LDAP user source configuration.

 

image (2).png

 

Only the local user realm is configured, and no realm exists for LDAP users. As a result, authentication fails when an LDAP user attempts to connect to the FortiSASE VPN.

 

image (1).png

 

Create a new User Sources under Authentication -> SAML IdP -> User Sources and set the LDAP realm as the default.

 

1.PNG

 

1.PNG

 

Remote AD users can now connect to the FortiSASE VPN, resolving the previous authentication failures.

 

1.PNG

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!