Skip to main content
fearoon
New Member
January 30, 2026
Solved

Can Azure SSL VPN cater for multiple Entra ID Groups?

  • January 30, 2026
  • 2 replies
  • 194 views

The goal is to cater for two types of user accounts which require VPN access; internal staff accounts added to a dynamic group and member accounts used by third-party users which are manually assigned to a group as required. 

 

My question is whether it is possible to set multiple Object Ids in the below config on the FortiGate corresponding to multiple Groups assigned to the FortiGate Enterprise App in Entra.

 

Any alternative suggestions for how this scenario can be handled are welcome.

 
2026-01-30 13_42_29-Greenshot.png
Best answer by tbarua

Hi fearoon, 

 

You can add the object id from Add group match > Groups >  specify > click + sign. Image as reference. 

 

 objectid.png

 

Kind regards,

 

2 replies

tbarua
Staff
tbaruaAnswer
Staff
January 30, 2026

Hi fearoon, 

 

You can add the object id from Add group match > Groups >  specify > click + sign. Image as reference. 

 

 objectid.png

 

Kind regards,

 

fearoon
fearoonAuthor
New Member
February 2, 2026

Thanks tbarua. I couldn't locate the Add group match page, but the below cleared it up for me.

 

Found documentation here outlining what is required: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-User-Groups-to-match-multiple-Remote/ta-p/358789

 

GroupAssignmentsFortiGate.png