Skip to main content
tweenbee
New Member
December 9, 2024
Question

Forticlient vpn 7.4.1 MFA issue

  • December 9, 2024
  • 12 replies
  • 7438 views

Hi All, 

 

I encountered a strange issue on my forticlient VPN version 7.4.1.

previously I have setup custom IPSEC VPN in my Fortigate FG500e with RADIUS/NPS user groups, and for a long time there were no issue.

 

in the few days back, the vpn client start having strange behavior, after I put my password is should have been keeping the password and asking for MS authenticator token. but now the forticlient remove the password making it blank and asking for authenticator.

 

when I put my authenticator token, it keep notifying "please provide password" :

fortiissue.png

 

for the record I'm using version 7.4.1.1736

the VPN is IPSEC not SSL

 

this issue only happens using RADIUS authentication, when using fortigate local user the vpn can be connected normally.

 

please help

 

12 replies

sjoshi
Staff
Staff
December 9, 2024

when you say it is working before..was the FCT version same v7.4.1 or was there change in the version. also is the issue specific to some user or all user

Thanks, Salon
tweenbee
tweenbeeAuthor
New Member
December 10, 2024

The issue affect all user using radius/nps authentication. for local users created in FGT, no issue

AEK
SuperUser
SuperUser
December 9, 2024

Hi

Can you check on FGT if the RADIUS authentication still works?

In RADIUS config, just perform an authentication test, enter user and password and see if authentication is successful.

AEK
tweenbee
tweenbeeAuthor
New Member
December 10, 2024

test successful in the FGT GUI and CLI, only when using FCT after entering password the field become blank then it ask for ms authenticator token

btan
Staff & Editor
Staff & Editor
December 10, 2024

If I reckon correctly, this may be a new bug in FCT 7.4.1 version.
Please test with FCT 7.4.0 and see if issue persist, I presume issue will not happen in FCT 7.4.0.

AEK
SuperUser
SuperUser
December 10, 2024

In addition to Bon's suggestion, in case 7.4.0 gives the same result then you may also try with older version, like 7.2.5 or 7.0.13.

AEK
Hostingmella
New Member
December 10, 2024

To fix MFA issues with FortiClient VPN 7.4.1, ensure MFA is configured correctly on FortiGate or FortiAuthenticator and update FortiClient to the latest version. Double-check VPN settings and test MFA on different devices. Verify the MFA device and time synchronization, and check the logs for errors. If the issue persists, clear the FortiClient cache and reconfigure the VPN settings. Contact Fortinet support if needed.

Aegis
New Member
March 5, 2025

Did you manage to resolve this?, we have the same issue. "Please provide password" is prompted after entering the MFA code. Radius is fine when not using MFA

CorneB
Explorer
April 16, 2025

Did you resolve the problem our found a workaround?

AEK
SuperUser
SuperUser
April 16, 2025

A quite similar issue has been fixed in 7.4.3.

1099714When using IPsec VPN with RADIUS authentication (Microsoft Entra ID), FortiClient (Windows) clears password field when asking for MFA.

Ref:  https://docs.fortinet.com/document/forticlient/7.4.3/windows-release-notes/22791/resolved-issues

Try update to 7.4.3 and see if it helps.

AEK
leafar
New Member
October 31, 2025

We manage to fix it via the end-user MFA settings, the user add selected the App based authentication token:Screenshot 2025-10-31 145345.png

 

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!