Skip to main content
bakarudin
New Member
January 20, 2023
Question

fortiauthenticator setup questions

  • January 20, 2023
  • 2 replies
  • 1361 views

we purchased the fortiauthenticator for two main reasons, 1- to get away from using the Fortinet Single Signon Agent for authentication purposes, and 2 - to use the fortitokens so we can do MFA on forticlient.

we want to do MFA first, is there any problem with setting up fortiauthenticator just for MFA, and later setting it up for replacing the FSSO agent?

2 replies

rbraha
Staff
Staff
January 20, 2023

Hello bakarudin ,

There is no problem with that , you can configure FAC to use MFA with SSL VPN authentication with FCT and later you can use FAC as Collector Agent to receive logon events on DC and to forward these events to FGT. 

https://docs.fortinet.com/document/fortigate/6.2.12/cookbook/207191/ssl-vpn-with-radius-and-fortitoken-mobile-push-on-fortiauthenticator

 

https://docs.fortinet.com/document/fortiauthenticator/6.4.6/administration-guide/712256/general-settings

Sheikh
Staff
Staff
January 21, 2023

Hi,

 

Fortiauthenticator can be configured for MFA for number of services e.g. SSLVPN, Portals, Admin console access, Logon to Domain computer using Fortiauthenticator Agent for Microsoft Windows and so on.

 

https://docs.fortinet.com/document/fortiauthenticator/6.4.0/fortiauthenticator-agent-for-microsoft-windows-4-2-release-notes/355786/fortiauthenticator-agent-for-microsoft-windows-4-2-release

 

https://docs.fortinet.com/document/fortiauthenticator/6.4.0/fortiauthenticator-agent-for-microsoft-owa-2-4-install-guide/459996/introduction

 

regards,

 

Sheikh

 

 

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!