Skip to main content
CTERA
New Member
July 18, 2023
Question

Configure forticlient SAML to utilize Primary Refresh Token

  • July 18, 2023
  • 2 replies
  • 1537 views

Hey Guys,

 

We are using forticlient with SAML connected to Azure Ad. 

SAML login works ok, but further Conditional Access we try to assign are not working as expected,

 

Azure support sure the issue is related to Forticlient app:

 

"after a thorough investigation we believe that the SAML application is not utilizing the Primary Refresh Token. So we wanted to ask if there is a way to reach out to the application side's support and check if there is a way for the PRT to be utilized via some sort of re-configuration"

2 replies

asengar
Staff
Staff
July 20, 2023

Hi @CTERA 

Thanks for posting your query.

Can you please elaborate are you referring the access here to the users based on the groups or any other attributes.

I means like only the specific users should get the specific access once successfully authenticated via SAML.

 

Kindly share the SAML configuration from the firewall and make sure the attributes you have configured in the AZURE IDP is same in the FGT as well

Also confirm if you are giving the access based on the group object id.

 

Refer the below document FYR if it helps

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Create-SSL-VPN-with-Azure-SAML-SSO-Authentication/ta-p/200812

https://docs.fortinet.com/document/fortigate-public-cloud/7.4.0/azure-administration-guide/584456/configuring-saml-sso-login-for-ssl-vpn-with-azure-ad-acting-as-saml-idp

CTERA
CTERAAuthor
New Member
July 25, 2023

@bhishek

 

SAML configured and working as expected based on allowed groups.

 

The issue is after connection is established  - Azure app doesn't recognize the laptop as Azure complaint device.

as Azure Support claims - they say the Forticlient app doesn't utilized the  Primary Refresh Token.

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!