Skip to main content
vincenzo
Explorer
May 24, 2024
Question

Fortideceptor sso attibutes

  • May 24, 2024
  • 2 replies
  • 1033 views

Hi All,

I'm configuring sso authentication on Fortideceptor 5.3 and Azure administrators told me to use NameID as attribute.

In Fortideceptor user guide is specified user.userprincipalname as attibute. Is mandatory to use these attribute?

Thank you

 

2 replies

ozkanaltas
Valued Contributor III
May 24, 2024

Hello @vincenzo ,

 

It depends on your Azure AD configuration. If your AD admin says you need to use NameID you can use that value while configuring Fortideceptor sso. 

 

IdP (AzureAD) will send the username information with this attribute. When you enter this attribute on FortiDeceptor, FortiDeceptor understands this as a username. 

 

 

vincenzo
vincenzoAuthor
Explorer
May 27, 2024

Hi Ozkanaltas,

in effect we are using NameID,  but when i try to login I receive a generic error "Error happened while using SAML login. Please try another login method" in log that can't help me to understand where is the error.

 

I trace the Saml response and I have the confirm that we use NameID.

Reading the admin guide I had a doubt, how does it associate the user login via saml with administrator profile?

 

Thank you

 

Vincenzo Stolfi

 

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.