Skip to main content
nplljw
New Member
December 9, 2024
Solved

how to specify a FAC group for Fortigate administrator login

  • December 9, 2024
  • 2 replies
  • 1817 views

Hello, I would like to know how to use FortiAuthenticator to configure saml SSO login for Fortigate administrators, and how to specify a FAC group for Fortigate administrator login

2 replies

dingjerry_FTNT
Staff
Staff
December 9, 2024
pminarik
Staff
Staff
December 9, 2024

FortiGate currently does not support group-based or wildcard-admin-based administrator logins with SAML. All authentication is individual, per-user. No support for dynamic VDOM assignment or access profile assignment either.

 

Restrictions as to who can authenticate can only be imposed from the IdP side. Unfortunately, FortiAuthenticator only allows configuring group-based restrictions on the "global level" for SAML (SAMl IdP > General), not on a per-SP basis. But maybe that will suffice for you?