Skip to main content
futureweb
New Member
January 25, 2026
Question

Forticient 7.4.5 Bug 1208862 - MFA and Entra ID

  • January 25, 2026
  • 7 replies
  • 1057 views

Hi,

I couldn’t find any additional information or discussion about the bug mentioned in the 7.4.5 release notes.


I’m currently doing a new EMS deployment connected to Microsoft Entra ID and I’m having issues with Invitation Code registration. The Invitation Code gets accepted, but the client never completes registration (it just keeps loading). EMS logs don’t show much.

I tested disabling MFA for one user. After some time, I was able to successfully register one device using an Invitation Code, but I still could not register a second device with the same user (same tenant, same EMS settings, devices provisioned the same way via Intune).

Because EMS can resolve and display the Entra ID domain user correctly for the device that registered, I assume the Entra connection/setup itself is basically working.


Could this behavior be caused by the following known issue?

1208862
Entra ID user verification fails if MFA is made compulsory on Entra ID side.


If yes: is there any ETA for an update or hotfix that addresses this?

Also: I’m deploying the FortiClient via Intune. I couldn’t find clear documentation whether Invitation Codes are expected to work reliably when using an Entra ID domain connection and the user is logged in via Entra on the Device, or if you have to provide invitation codes anyway to login (when it works). Or could this be related to the same issue?

When I am not forcing user (none) - it worked through intune, but I do not want to deploy this way. 

Thanks,

Patrick

 

7 replies

AEK
SuperUser
SuperUser
January 25, 2026

Hi Patrick

Invitation can be disabled, so you can register client without invitation code if the client is domain joined.

Also as far as I know MFA is not (yet?) supported with user verification on registration.

AEK
futureweb
futurewebAuthor
New Member
March 5, 2026

Thanks for your reply.

The device is Intune-provisioned, so it’s Entra ID joined, not domain joined.

So far I haven’t found a reliable way to disable MFA only for FortiClient EMS registration, as the flow goes through MSGraph.   

I’m not comfortable allowing “unverified” registrations, since we would have to expose EMS externally.

What’s especially concerning: on my own device (I’m the only user), this has already happened twice in the last 1–2 months. FortiClient suddenly showed as not registered anymore. To fix it, I had to use a new invitation code (or bulk invitation code) while disable MFA again.

Is it possible that Entra ID user verification for EMS + ZTNA on FortiGate is still not production-ready?
Right now I wouldn’t want to roll this out company-wide if clients can randomly require re-registration, which means to disable MFA to make this possible at all. 

I’m also not enforcing re-registration in EMS settings, where I think another bug exists. 

futureweb
futurewebAuthor
New Member
March 6, 2026

Thanks for your answer. But in that case, it is not really usable.

If MFA only has to be disabled once during onboarding, that would be fine. The problem is that the registration is sometimes lost. Then MFA has to be disabled again so the user can join again, which basically breaks the whole Entra ID setup in this scenario.

At the moment the registration is gone, ZTNA stops working, and an admin is required to disable MFA and wait until provisioning is completed. In total, this can take around 15 to 45 minutes.

Is there any workaround you can recommend for this case that is still secure and does not mean allowing “any user” to join?

The user should still come from Entra ID. So the issue is really only the registration process I guess. 

futureweb
futurewebAuthor
New Member
March 7, 2026

We use SAML now for the onboarding/registration process. As Microsoft pushes MFA anyway I am not sure if it does make sence giving the option to use Domain (when talking about Entra ID). Also, as it goes through Graph API, you can't tell this Enterprise App to not use MFA. Would have been nice to have the client registered automatically for Intune provisioned devices, but this will work also. 

Link to doc we used: (not up2date as Microsoft changed it a little bit): 
Configuring user verification with SAML authentication and an Entra ID server user account | FortiClient 7.4.5 | Fortinet Document Library

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!