Skip to main content
doncacciatoconsuting
Explorer II
November 12, 2025
Solved

FortiAuthenticator TACACS+ | Entra MFA integration

  • November 12, 2025
  • 3 replies
  • 532 views

I'd like to use FAC's TACACS+ service. Users will be pulled in from EntraID via SAML. Of course Entra has MFA via MA Authenticator.

What happens in this scenario ? FAC couldn't broker Entra's MFA right ? 

Would I need Fortitokens in this case to do MFA ?

 

Don

Best answer by Jean-Philippe_P

Hello again Don,

 

I found this solution. Can you tell us if it helps, please?

 

In this scenario, FortiAuthenticator (FAC) cannot broker Microsoft Entra ID's MFA directly. Here's how you can proceed:

  1. TACACS+ Service on FAC: FAC supports TACACS+ for authentication and authorization. However, it does not support challenge/response, meaning MFA needs to be appended to the password.

  2. SAML Integration: FAC can integrate with Microsoft Entra ID via SAML for user authentication. However, it cannot directly enforce or broker the MFA configured in Microsoft Entra ID.

  3. MFA Requirement: If you require MFA for TACACS+ authentication, you would need to use FortiTokens or another MFA solution that FAC supports. This would involve appending the token to the password during login.

In summary, to achieve MFA with TACACS+ on FAC, you would need to use FortiTokens or a similar supported solution, as FAC cannot directly utilize Microsoft Entra ID's MFA.

3 replies

Anthony_E
Staff
Staff
November 17, 2025

Hello Don,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
November 18, 2025

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Best Regards
Jean-Philippe_P
Staff & Editor
Staff & Editor
November 19, 2025

Hello again Don,

 

I found this solution. Can you tell us if it helps, please?

 

In this scenario, FortiAuthenticator (FAC) cannot broker Microsoft Entra ID's MFA directly. Here's how you can proceed:

  1. TACACS+ Service on FAC: FAC supports TACACS+ for authentication and authorization. However, it does not support challenge/response, meaning MFA needs to be appended to the password.

  2. SAML Integration: FAC can integrate with Microsoft Entra ID via SAML for user authentication. However, it cannot directly enforce or broker the MFA configured in Microsoft Entra ID.

  3. MFA Requirement: If you require MFA for TACACS+ authentication, you would need to use FortiTokens or another MFA solution that FAC supports. This would involve appending the token to the password during login.

In summary, to achieve MFA with TACACS+ on FAC, you would need to use FortiTokens or a similar supported solution, as FAC cannot directly utilize Microsoft Entra ID's MFA.

Jean-Philippe - Fortinet Community Team