Skip to main content
New Member
June 26, 2026
Question

FortiAuthenticator On-Premises integration

  • June 26, 2026
  • 5 replies
  • 60 views

Hi Team,

We are planning to deploy FortiAuthenticator On-Premises for a client.

Client Requirement:

  • When users register their endpoint with FortiClient EMS (ZTNA), MFA should be enforced.

  • The client wants users to have either SMS OTP or Google Authenticator (TOTP) as the second factor, with both options available for redundancy.

Could you please confirm the following:

  1. Is this requirement supported with FortiAuthenticator?

  2. What are the prerequisites for implementing this setup?

  3. For SMS OTP, does FortiAuthenticator require a third-party SMS gateway/provider? If yes, which integrations are supported or recommended?

  4. Are there any licensing or configuration considerations we should be aware of before deployment?

Any implementation guidance or best practices would be appreciated.

Thanks!

5 replies

funkylicious
SuperUser
SuperUser
June 26, 2026

MFA isnt enforced based on device registration in EMS, but only at a user level in FAC

you can should be able to provision TOTP w/ Google Auth and for SMS you need a SMS gateway

in regards to licensing, it’s based on the number of users, the base licensing having 100 users licensed and then you would need to add according to your needs. additional licensing could be required if you want to use FortiToken Mobile. you can search for the ordering guide only to see the SKU’s

https://docs.fortinet.com/document/fortiauthenticator/6.6.10/release-notes/917508 

"jack of all trades, master of none"
New Member
June 26, 2026

Hi,

Thank you for the clarification.

Just to confirm our proposed deployment:

  • We will use FortiAuthenticator as the SAML Identity Provider (IdP).

  • FortiClient EMS will act as the SAML Service Provider (SP).

  • Users will authenticate through FortiAuthenticator, where MFA will be enforced at the user level.

  • Users should have the option to use either Google Authenticator (TOTP) or SMS OTP (via an SMS Gateway) as the second authentication factor.

Could you please confirm that this architecture is fully supported and is the recommended deployment for EMS SAML authentication?

Also, please confirm that EMS redirects authentication requests to FortiAuthenticator (IdP), and after successful SAML authentication and MFA, the user is redirected back to EMS to complete the registration/login process.

Thanks!

funkylicious
SuperUser
SuperUser
June 26, 2026

Users will authenticate through FortiAuth as IdP using EMS as SP to what exactly ? As far as I know you can only use EMS with SAML for User verification when using Invite Codes or for Admininistrators

"jack of all trades, master of none"
New Member
June 26, 2026

Thanks for the clarification.

Our use case is specifically for FortiClient EMS endpoint registration.

The customer requirement is that when a user registers an endpoint with EMS, they should be required to complete MFA using either:

  • Google Authenticator (TOTP), or
  • SMS OTP (via an SMS gateway).

Our understanding was that this could be achieved by integrating FortiAuthenticator with EMS using SAML.

 

Thanks!

funkylicious
SuperUser
SuperUser
June 26, 2026
New Member
June 26, 2026

Our customer's requirement is to use this onboarding flow and have FortiAuthenticator enforce MFA, allowing users to authenticate with either:

  • Google Authenticator (TOTP), or
  • SMS OTP (via an SMS gateway).

Could you please confirm whether FortiAuthenticator MFA is fully supported in this SAML onboarding flow? In other words, after EMS redirects the user to FortiAuthenticator for SAML authentication, can FortiAuthenticator require either TOTP or SMS OTP before returning the SAML assertion back to EMS?

thanks

Â