Skip to main content
fukimo
New Member
March 30, 2023
Question

Forticlient EMS MFA

  • March 30, 2023
  • 1 reply
  • 2418 views

Hi, I am migrating from classic SSL VPN in fortigate with fortitoken to Forticlient EMS ZTNA. What do I need to enable MFA with EMS/ZTNA?

- Can the client registration to the EMS be done with MFA? or do you just use MFA for access to ZTNA servers?

- do I need fortiauthenticator?

- In order to just have 1 authentication app: Can I use Microsoft Authenticator instead of fortitokens? Do I need fortiauthenticator? Or on the contrary is it better to use fortitoken to access O365?

thanks

1 reply

gfleming
Staff
Staff
March 31, 2023

As far as I'm concerned ZTNA does not do classic MFA. It uses client and device certificates on the back-end as a form of MFA.

ZTNA allows the access to your servers without the need to be connected to a VPN.

If I were you I would just enable MFA on your servers and let ZTNA do its thing.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.