Skip to main content
PBANZ
New Member
December 1, 2020
Question

Forticlient with Microsoft Authenticator

  • December 1, 2020
  • 4 replies
  • 30257 views

I tested the fullversion of forticlient connect before login with microsoft authenticator as the second factor auth.

I found the that in this scenario in all versions of client from 6.0.x up that the auth just times out. i had another rule that allowed the user with out 2fa and if i did a deny on the prompt it doesn't deny the user, the login times out and moves to the next rule. 

this is only with connect before login.

 

has anyone else encountered this, anyone found a way to solve it.

note: we are Not running EMS so can't log with TAC.

 

    4 replies

    isamt
    New Member
    December 4, 2020

    I have setup and tested using the nps-extension with the following documentation:

     

    https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-vpn#install-and-configure-the-nps-extension

     

    Works fine for me

     

    Not sure if you have setup in the same way.

    PBANZ
    PBANZAuthor
    New Member
    December 6, 2020

    yes setup the same, are you using a code number from the app or responding to the approve prompt. customer is using the approve/deny prompt in authenticator. the specific scenario  with connect before login and the authenticator prompt is failing. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!