Skip to main content
naofomi
New Member
August 11, 2026
Question

Authenticating InTune clients

  • August 11, 2026
  • 2 replies
  • 59 views

So how are we all doing SSO user authentication on InTune/Entra joined clients going through an on-prem Fortigate?

For many years we've been using the DC SSO agent to authenticate users on domain-joined devices, but now with clients moving away from local AD and so no longer domain-joined so not authenticating on the on-prem DC, this obviously makes the DC agent redundant.

I'd rather avoid a captive portal if possible since that's a bit of a step backwards from the nice slick SSO solution we're used to, so what's the most elegant way to do SSO authentication to an Entra 365 account?
 

    2 replies

    Muttahar_Rehman
    Explorer II
    August 11, 2026

    FortiClient with EMS-based telemetry SSO is the good option.

    Thanks, R3hsec
    sjoshi
    Staff
    Staff
    August 12, 2026

    Recommended Approach: FortiClient SSO Mobility Agent (SSOMA) with FortiAuthenticator
    The most seamless replacement for your current DC agent experience is the FortiClient SSO Mobility Agent (SSOMA) working with FortiAuthenticator. This provides transparent, agent-based SSO without any user-visible authentication prompts
    https://community.fortinet.com/fortiauthenticator-8/technical-guide-a-detailed-guide-to-fsso-mobility-agent-222658

    Thanks, Salon
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!