Skip to main content
shawn-ev
Explorer II
June 5, 2026
Solved

Preferred FortiClient EMS authentication method for Mac computers managed via JAMF. SAML? LDAP? EntraID?

  • June 5, 2026
  • 12 replies
  • 330 views

We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support  Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document Library

That last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registration/authentication methods should I use for these Mac machines to get the same type of user-level and device-level registration in FCEMS that we have for our Windows machines?

Best answer by Jean-Philippe_P

Hello ​@dstranathan and ​@shawn-ev,

 

I found this answer, can you tell us if it helps, please?

 

⚠️ Verify before relying on this — I found relevant material, but it may not fully cover your specific issue, so please confirm this against current Fortinet documentation.

 

Recommended approach
For a cloud-only Microsoft 365 organization, use Microsoft Entra ID integration in EMS together with MDM-managed macOS enrollment—not LDAP—as the primary model for macOS.

The documented macOS requirement in the cited EMS guidance is specifically that macOS does not use native Entra ID integration in the same manner as Windows, and that the integration requires the Mac to be managed through Intune or Jamf and enrolled in Company Portal with Entra ID. Your described Jamf Pro + Intune/Company Portal setup aligns with that prerequisite.

 

Do not choose LDAP for this use case
LDAP/domain authentication is not the appropriate option for a 100% cloud-based Entra ID tenant with Macs that are not domain joined. It would introduce a dependency on a directory/LDAP service that is not part of the stated identity model. The retrieved Fortinet material instead describes EMS Entra ID integrations as Microsoft Graph/API integrations and requires appropriate application permissions and tenant admin consent. It also notes that EMS supports commercial Entra ID subscriptions, not GCC, GCC High, or EDU tenants. [1]

 

Do not substitute EMS SAML SSO for endpoint registration
SAML is useful, but for a different purpose. The Fortinet documentation describes the EMS SAML configuration as allowing users to access EMS when EMS acts as the service provider (SP) and a third-party identity provider validates credentials. [2] In other words, configure SAML with Entra ID if you want Entra-based SSO for the EMS administrative/user portal login.

SAML should not be treated as the primary replacement for the Entra ID + MDM macOS registration workflow. There is a separate documented scenario in which an EMS invitation code uses a SAML verification scope; this can be relevant when users must authenticate during an invitation-based registration flow. [3] However, that is an interactive registration-verification mechanism, not documentation of equivalent seamless device- and user-level enrollment for Jamf-managed Macs.

 

Practical model for your environment
Use the following split of responsibilities:

Requirement    Preferred mechanism
Import/synchronize Entra users and groups into EMS    Existing Entra ID authentication server/domain integration
Mac device deployment and required macOS approvals    Jamf Pro deployment and configuration profile
Mac eligibility for the Entra workflow    Enroll the Mac in Company Portal using the user’s Entra ID, as required by the EMS macOS Entra guidance cited in the question
EMS registration protection / unattended registration    Deploy a FortiClient package generated by EMS with the telemetry connection key embedded
EMS portal/admin SSO    SAML SSO with Entra ID, optionally
Manual/invitation registration that requires user sign-in    Invitation with SAML verification scope, if required

 

Registration and deployment considerations
For hands-off FortiClient registration, use an EMS-generated FortiClient installer rather than a generic installer downloaded from Fortinet Support. Fortinet states that if a FortiClient package is generated by EMS, the telemetry connection key is embedded and FortiClient does not prompt the user for it during registration. A generic Fortinet Support download does prompt for the key when a fresh registration is initiated. [4]

 

For macOS deployment through Jamf, ensure the Jamf configuration profile provides the required permissions. Fortinet documents that silent/efficient macOS deployment requires a Jamf Pro custom configuration profile to handle Full Disk Access, FortiTray network-extension permissions, and trust/import of the ZTNA CA and DNS root CA certificates. [5] Jamf is also documented as able to deploy FortiClient and associated VPN/SSL settings to macOS and iOS. [6]

 

Entra configuration checks
Because your existing Windows Entra/domain integration works, retain that integration and validate the following before expanding to Macs:

Use the client secret value, not the secret ID, in EMS. 
Configure Microsoft Graph permissions as Application permissions, not Delegated permissions, and grant tenant admin consent. [1]
Fortinet lists User.Read.All and optionally Directory.Read.All among the permissions to review, subject to the integration’s required access. 
Verify the EMS authentication-server connection using Test and confirm the imported domain’s synchronization is current in Endpoints > Manage Domains. 
Confirm that the Entra tenant is a supported commercial subscription type.

 

Important limitation / what cannot be verified from the supplied documents
The retrieved material does not provide the precise FortiClient EMS 7.4.5 procedure that maps a Jamf-managed, Company Portal-enrolled macOS device to the exact EMS registration mode, nor does it explicitly confirm that this produces the identical user-level and device-level registration behavior seen on Entra-joined Windows devices.

 

Therefore, the supportable conclusion is:

Use Entra ID + Jamf/Company Portal enrollment for the macOS prerequisite.
Use Jamf to deploy the EMS-generated FortiClient package and required macOS configuration profile.
Use SAML only for EMS SSO and, if needed, invitation-code verification—not as the main Mac endpoint-registration replacement.
Do not use LDAP/domain authentication for this cloud-only Mac scenario.

 

The exact EMS screens and workflow for macOS registration should be confirmed against the current 7.4.5 Adding an Entra ID server and Jamf deployment documentation, or through Fortinet Support, because those specific steps are not included in the retrieved documents.

12 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
June 9, 2026

Hello shawn-ev, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Regards,

Jean-Philippe - Fortinet Community Team
Explorer
August 27, 2026

​@Jean-Philippe_P  Do you have an answer? as a new customer Id like to know this.

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 28, 2026

Hello ​@dstranathan and ​@shawn-ev,

 

I found this answer, can you tell us if it helps, please?

 

⚠️ Verify before relying on this — I found relevant material, but it may not fully cover your specific issue, so please confirm this against current Fortinet documentation.

 

Recommended approach
For a cloud-only Microsoft 365 organization, use Microsoft Entra ID integration in EMS together with MDM-managed macOS enrollment—not LDAP—as the primary model for macOS.

The documented macOS requirement in the cited EMS guidance is specifically that macOS does not use native Entra ID integration in the same manner as Windows, and that the integration requires the Mac to be managed through Intune or Jamf and enrolled in Company Portal with Entra ID. Your described Jamf Pro + Intune/Company Portal setup aligns with that prerequisite.

 

Do not choose LDAP for this use case
LDAP/domain authentication is not the appropriate option for a 100% cloud-based Entra ID tenant with Macs that are not domain joined. It would introduce a dependency on a directory/LDAP service that is not part of the stated identity model. The retrieved Fortinet material instead describes EMS Entra ID integrations as Microsoft Graph/API integrations and requires appropriate application permissions and tenant admin consent. It also notes that EMS supports commercial Entra ID subscriptions, not GCC, GCC High, or EDU tenants. [1]

 

Do not substitute EMS SAML SSO for endpoint registration
SAML is useful, but for a different purpose. The Fortinet documentation describes the EMS SAML configuration as allowing users to access EMS when EMS acts as the service provider (SP) and a third-party identity provider validates credentials. [2] In other words, configure SAML with Entra ID if you want Entra-based SSO for the EMS administrative/user portal login.

SAML should not be treated as the primary replacement for the Entra ID + MDM macOS registration workflow. There is a separate documented scenario in which an EMS invitation code uses a SAML verification scope; this can be relevant when users must authenticate during an invitation-based registration flow. [3] However, that is an interactive registration-verification mechanism, not documentation of equivalent seamless device- and user-level enrollment for Jamf-managed Macs.

 

Practical model for your environment
Use the following split of responsibilities:

Requirement    Preferred mechanism
Import/synchronize Entra users and groups into EMS    Existing Entra ID authentication server/domain integration
Mac device deployment and required macOS approvals    Jamf Pro deployment and configuration profile
Mac eligibility for the Entra workflow    Enroll the Mac in Company Portal using the user’s Entra ID, as required by the EMS macOS Entra guidance cited in the question
EMS registration protection / unattended registration    Deploy a FortiClient package generated by EMS with the telemetry connection key embedded
EMS portal/admin SSO    SAML SSO with Entra ID, optionally
Manual/invitation registration that requires user sign-in    Invitation with SAML verification scope, if required

 

Registration and deployment considerations
For hands-off FortiClient registration, use an EMS-generated FortiClient installer rather than a generic installer downloaded from Fortinet Support. Fortinet states that if a FortiClient package is generated by EMS, the telemetry connection key is embedded and FortiClient does not prompt the user for it during registration. A generic Fortinet Support download does prompt for the key when a fresh registration is initiated. [4]

 

For macOS deployment through Jamf, ensure the Jamf configuration profile provides the required permissions. Fortinet documents that silent/efficient macOS deployment requires a Jamf Pro custom configuration profile to handle Full Disk Access, FortiTray network-extension permissions, and trust/import of the ZTNA CA and DNS root CA certificates. [5] Jamf is also documented as able to deploy FortiClient and associated VPN/SSL settings to macOS and iOS. [6]

 

Entra configuration checks
Because your existing Windows Entra/domain integration works, retain that integration and validate the following before expanding to Macs:

Use the client secret value, not the secret ID, in EMS. 
Configure Microsoft Graph permissions as Application permissions, not Delegated permissions, and grant tenant admin consent. [1]
Fortinet lists User.Read.All and optionally Directory.Read.All among the permissions to review, subject to the integration’s required access. 
Verify the EMS authentication-server connection using Test and confirm the imported domain’s synchronization is current in Endpoints > Manage Domains. 
Confirm that the Entra tenant is a supported commercial subscription type.

 

Important limitation / what cannot be verified from the supplied documents
The retrieved material does not provide the precise FortiClient EMS 7.4.5 procedure that maps a Jamf-managed, Company Portal-enrolled macOS device to the exact EMS registration mode, nor does it explicitly confirm that this produces the identical user-level and device-level registration behavior seen on Entra-joined Windows devices.

 

Therefore, the supportable conclusion is:

Use Entra ID + Jamf/Company Portal enrollment for the macOS prerequisite.
Use Jamf to deploy the EMS-generated FortiClient package and required macOS configuration profile.
Use SAML only for EMS SSO and, if needed, invitation-code verification—not as the main Mac endpoint-registration replacement.
Do not use LDAP/domain authentication for this cloud-only Mac scenario.

 

The exact EMS screens and workflow for macOS registration should be confirmed against the current 7.4.5 Adding an Entra ID server and Jamf deployment documentation, or through Fortinet Support, because those specific steps are not included in the retrieved documents.

Jean-Philippe - Fortinet Community Team
Explorer
August 28, 2026

Lots of details here. Thanks ​@Jean-Philippe_P 

By pure coincidence, we are building out our Entra Device Compliance registration workflow using Jamf Pro, MSFT ESSO and MSFT Comp Portal. I had a stumbling block so its slowed down due to a support case.

I'll share your info with my team. 🤙🏻

shawn-ev
shawn-evAuthor
Explorer II
August 28, 2026

Thank you for this info. We have our macs managed through Jamf and are using SAML authentication for them in EMS. There are a few details I want to verify before I comment further, but I believe we are largely aligned with this configuration already.

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 31, 2026

Hey guys,

I am glad that it helped! I am waiting for your answer ​@shawn-ev and am ready to help you further if needed :)

Have a good day!

Jean-Philippe - Fortinet Community Team
shawn-ev
shawn-evAuthor
Explorer II
August 31, 2026

​@Jean-Philippe_P, I have confirmed we are using Jamf and SAML authentication for Macs. We enforce user authentication for both Windows and Mac and do not use hands-off registration for any users. Because Macs cannot use Domain authentication, we were forced to create additional groups under Endpoints > Workgroups to manage the Mac users and ensure they were assigned to the proper Endpoint Profile. The Windows users are assigned to the proper profile through the Domain authentication and Entra group membership.

In practice, we created two top-level group folders, “Windows” and “Mac”. For Windows, assignment to the correct Endpoint Profile is based on Entra Group membership. For Mac, we created subfolders using the same Entra group names. We assign that group to the correct Endpoint profile. It works great!

Explorer
August 31, 2026

Thanks - Have you tried using Jamf Device Compliance with Entra (uses Comp Portal to register them)? That would assign a Mac to a Entra user I think…?

shawn-ev
shawn-evAuthor
Explorer II
September 1, 2026

We are using Jamf device compliance. Users register via Company Portal, which assigns the device to the user in Intune/Entra. Jamf then reports device compliance to Intune.

Explorer
September 1, 2026

OK great, thats outrageous plan as well eventually. DC registration is still in testing phase. Thanks. 🙏🏻

New Member
September 3, 2026

For a cloud-based environment, I’d avoid LDAP for the Mac devices. Using Jamf with Entra ID/Company Portal seems like the cleaner approach, while SAML can handle the user authentication. This also makes it easier to manage Mac users and assign the correct EMS profiles.

Explorer
September 4, 2026

Thanks ​@ThomasMonie - We are in the process of testing a workflow to register Macs into Entra using Jamf Pro, Jamf Self Service+, MSFT Company Portal, MSFT ESSO, and a custom UI workflow using swiftDialog to provide user-facing info. To me this process seems a little fragile and annoying. Requirng users to self-register is a PITA.

Im hoping we are going to manage profiles/rules at the computer level rather than user level.

We are brand-new customers with lots of questions and challenges. To start, we are focusing on VPN (always-on IPSec split tunnel), Web/DNS filtering. These are replacing Palo Alto GlobalProtect and DNSFilter. We might also leverage FortiAuthenticator but I don't know much about this.

Then we will move to full ZTNA, FortiNAC (replace Cisco ISE for 802.1x/SCEP) and possibly replace SentinelOne EDR.