Skip to main content
PhiPhan
New Member
December 17, 2025
Question

FortiClient inquiry regarding ZTNA Automatic Authentication with Multiple Azure SAML Tenants

  • December 17, 2025
  • 1 reply
  • 172 views

Hi,

I have configured a ZTNA setup using FortiGate and FortiClient EMS integrated with Azure AD SAML for one domain (e.g., user@abc.com) (server A)

 

I have now added a second FortiGate to the same FortiClient/EMS environment, but it requires authentication against a different Azure AD SAML tenant (e.g., userb@xyz.com) (server B)

 

Is there a solution to achieve automatic authentication (SSO) for the second account (xyz.com) so that users do not have to manually re-authenticate when connecting to resources protected by the second FortiGate?

On my check, when the FC connect to server B it automatic use the account from the current login via browser ( which current login with domain abc.com) --> so it get the error authentication code 21.

Regards,

1 reply

PhiPhan
PhiPhanAuthor
New Member
December 17, 2025

Update my mistake provide wrong error code -> it get code 069.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!