Skip to main content
nyctelecom
New Member
February 25, 2019
Question

FortiClient & Microsoft Azure MFA

  • February 25, 2019
  • 5 replies
  • 14792 views

Hello, 

 

Can anyone point me to information related to configuring the Forticlient with MS Azure MFA?

 

Thanks!

    5 replies

    ablake
    New Member
    March 11, 2019

    Hey nyctelecom,

     

    Do you have a Radius server with the Azure MFA client running on it? if so, all you need to do is create the Radius Server entry on your FortiGate which has to be pointed to the Radius server that is running the Azure MFA client. The Azure Client can be found on your Azure portal; go to "Azure Active Directory >>  MFA >> Server Settings" then click on the "download" link to get the MFA Server client and then click on the "Generate" link to create the activation credentials that will be needed to sync your RADIUS server to Azure MFA.

    nyctelecom
    New Member
    March 11, 2019

    Perfect.

     

    Thank you!

    XavierC
    New Member
    April 10, 2020

    Hello,

    I have configured an IpSec tunnel using the Radius authentication with MS Azure MFA, and it works like a charm if I use the phone call, or the notification on the authentication App (Microsoft Authenticator) on my smartphone.

    But if I choose another option (SMS or code from authentication App), when I login to the Forticlient with my login/pwd and press "Connect", a new field appears, and it show "Enter your Microsoft verification code". Then I fill the field with the code I have received (SMS or App), but each time the connection fails, with a text box "VPN connection failed. Check network connection..." (translation from French, sorry ;) ).

    On my radius server, I see that the NPS extension rejected the connection. It looks like the code is not correctly send from the Forticlient to the Radius server. 

    The SMS/App code MFA options work correctly to access to other ressources (ie : webmail, ...)

    Any idea of what could be wrong ?

     

    jamescarell2021
    New Member
    March 29, 2022

    miniOrange Provide MFA over Forticlient VPN with 15+ MFA methods, You can connect your external Azure AD with miniOrange too. You can follow this step by step guide.
    They also offer a 30-day free trial to test the solution. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!