Skip to main content
aguerriero
Explorer
August 7, 2024
Solved

EMS Authentication Server with multiple domains

  • August 7, 2024
  • 7 replies
  • 6092 views

When adding an authentication server in EMS I only ever get 1 domain even when the tenant has multiple domains registered and synced. These aren't subdomains but two different unique domains.

example1.com
example2.com


The only information I provide is the tenant ID, client ID, and secret. And then I only get 1 domain available for doing user to OU matching to assign policies.

How do I get all of the available domains that are synced in azure so I can can assign policies? Currently I have to create workgroups and assign the users to that either manually or with group assignment rules.

 

Capture1232131.PNG

Best answer by Anil_Solakoglu

Hello,

 

In the earlier stages of 7.2.x we used to provide a workaround like described below.

https://community.fortinet.com/t5/FortiClient/Technical-Tip-Transforming-users-attributes-while-verifying-via/ta-p/274594

 

This behavior changed after 7.2.3 due to a resolved issue over bug 953051.

 

Starting from version EMS 7.2.3 supports UPNs with different domain names rather than the imported one, as long as the SAML attributes contain the right user UPN.

 

https://docs.fortinet.com/document/forticlient/7.2.3/windows-release-notes/22791/resolved-issues

7 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 10, 2024

Hello aguerriero, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
August 14, 2024

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

 

Thanks,

Jean-Philippe - Fortinet Community Team
haunglu
New Member
August 14, 2024

ive done that already but there is the one server which refuses to allow logins from the 2nd domain. i also tried machine account password resets but same issue.

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 14, 2024

@AEK @ozkanaltas @sw2090 @pminarik do you have maybe an idea for this issue please?

Jean-Philippe - Fortinet Community Team
pminarik
Staff
Staff
August 14, 2024

EMS is not my strong suit, same for more advanced Azure AD/Entra ID configurations.

 

With that said, my personal gut-based expectation (which can be completely wrong!) would be something along the lines of creating two "enterprise applications", one under each domain/directory, and then creation of two "authentication servers" in EMS.

 

From my limited exposure, my understanding is that each directory would have a separate "tenant ID", hence why I'd expect two apps and two "auth servers".

aguerriero
Explorer
August 14, 2024

I tried that but you can only put the tenant ID in one time. If you try to use it again the EMS says the tenant ID already exists.

sw2090
SuperUser
SuperUser
August 14, 2024

Sorry I have no experience with EMS yet as we do not yet use it.

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 14, 2024

Thanks guys for answering so quickly :)

Jean-Philippe - Fortinet Community Team
Anil_Solakoglu
Staff
Staff
August 19, 2024

Hello,

 

In the earlier stages of 7.2.x we used to provide a workaround like described below.

https://community.fortinet.com/t5/FortiClient/Technical-Tip-Transforming-users-attributes-while-verifying-via/ta-p/274594

 

This behavior changed after 7.2.3 due to a resolved issue over bug 953051.

 

Starting from version EMS 7.2.3 supports UPNs with different domain names rather than the imported one, as long as the SAML attributes contain the right user UPN.

 

https://docs.fortinet.com/document/forticlient/7.2.3/windows-release-notes/22791/resolved-issues