Skip to main content
HS08
Visitor III
July 30, 2024
Question

Azure AD

  • July 30, 2024
  • 3 replies
  • 1100 views

Hello,

Can we use  Azure AD as source on firewall rule, and make the log by username also rather than using source IP?

3 replies

pmeet
Staff
Staff
July 30, 2024

Unfortunately Azure AD can't be connected to FortiGate as windows AD agent also called FSSO.

mle2802
Staff
Staff
July 30, 2024

Hi @HS08,

You can use Azure as SAML Idp for firewall authentication but user need to login at the time of connection, not like FSSO suggested by my colleague where user can login to their domain computer and the user is already authenticated. Please refer to this document for more information https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/33053/outbound-firewall-authentication-with-microsoft-entra-id-as-a-saml-idp

Regards,
Minh

Cajuntank
Contributor III
July 30, 2024

This might not be applicable to your situation, but I had the same problem due to most of my devices being non-bind AD MacBooks. What I was able to do to solve the problem to get to the result you are asking for, was to use FortiAuthenticator (FAC). What you are trying to get is FSSO like the others have mentioned. That FSSO for me was via the use of this methodology using FAC. I have a web filter that gives me constant syslog info from the clients, thus I am able to match them to policy rules I source out to their FSSO group pretty easily.

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Configure-FSSO-using-Syslog-as-source-custom/ta-p/198650

 

There is also a cookbook article to use Azure AD with FAC to achieve FSSO using this article.

https://docs.fortinet.com/document/fortiauthenticator/6.5.0/cookbook/316341/saml-fsso-with-fortiauthenticator-and-microsoft-azure-ad

 

FAC also has a Windows client (though I have never used or implemented it), but they don't have a macOS client, so I never looked further (hint hint Fortinet!!).