Skip to main content
tonyagustin
New Member
May 6, 2024
Solved

FortiAuthenticator MFA - SAML

  • May 6, 2024
  • 7 replies
  • 3382 views

Hello.

We'd like to configure our FortiAuthenticator as SAML IdP. The first authentication factor is password from AD. We've tested several OTP options: fortitoken, sms, email, etc. and the work fine but we'd like to use another second factor: client certificate. We've used local CA or remote CA, and we've configure "certificate bindings" under user configuration, but when SAML web page is shown, it only asks for username and password, and it doesn't prompt to chose a certificate.

Anyone knows if it's possible to configure 2FA with AD password and user certificate?.

Thank you!.

Best answer by lmarinovic

Hello Tony,

 

Unfortunately this is not supported yet. Even if you set certificate bindings on user. This currently can only work for radius. Only second factor under SAML can be:

 

 

Best regards,

 

Lazar

 

7 replies

Stephen_G
Moderator
Moderator
May 9, 2024

Hello tonyagustin,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen_G - Fortinet Community Team
Stephen_G
Moderator
Moderator
May 13, 2024

Hello tonyagustin,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Stephen_G - Fortinet Community Team
lmarinovic
Staff
Staff
May 13, 2024

Hello Tony,

 

Unfortunately this is not supported yet. Even if you set certificate bindings on user. This currently can only work for radius. Only second factor under SAML can be:

 

 

Best regards,

 

Lazar

 

pminarik
Staff
Staff
May 13, 2024

As far as I am aware, this is not currently supported.

Certificate-bindings are used only for EAP-TLS authentication, SAML IdP currently doesn't support client-certificate verification. You'll need a new feature request for this.

tonyagustin
New Member
May 14, 2024

Thank you all for your answers!

True-i
New Member
May 28, 2024

Dear Sir،,

If you don't mind to share the steps  I need to configure authenticator using saml to login to OWA Mircosoft exchange

Thanks for your support

Rabah35or
New Member
September 4, 2024

Did MFA worked for Exchange AciveSync and AnyWhere ?