Forticlient VPN - SAML SSO Azure AD - credentials cache
Hi to everybody,
one of my customer has this problem:
We have implemented SAML SSO login in a Fortigate unit (Fortigate VM00) where Azure AD acts as SAML IdP
Everything works fine except we have a "strange" behavior with Forticlient VPN.
Seems Fortigate VPN makes a sort of credential cache.
After a user makes logout, if he tries to reconnect, the authentication phase is skipped.
This happens only if Forticlient VPN interface is not close.
If the user, after a disconnect / logout, closes the Forticlient VPN interface , when he tries to reconnect he must follow the authentication steps.
Seems this cache is done by the lock file inside C:\users\(username)\appData\Local\FortiClient
Everytime Forticlient VPN interface is closed, this file is deleted.
Seems that, until the lock file exists, the session between forticlient and microsoft is kept open (if he clicks disconnect, the session is close between laptop and fortigate firewall but not beween laptop and microsoft)
In order to close this "persistent session", is enough to close the login form
I have opened a TT with Fortinet support but Forticlient VPN is not a "paid product" and they can't help me directly. They suggested me to open here my case.....
Somebody else has the same issue?
Regards
Marco
