Skip to main content
rickas27
New Member
February 20, 2026
Question

Not retrieving multiple groups via SAML from Entra ID for SSL-VPN

  • February 20, 2026
  • 6 replies
  • 837 views

I configured my FG (latest 7.2.x) to authenticate SSL-VPN users via SAML to Entra ID then map the security groups received via SAML "group" attribute to groups in the FG (remote SAML server, then using the object ID of the group). The groups were added into SSL-VPN settings to map to SSL-VPN portals.

 

I configured 2 security groups in Entra ID (group 1 and group 2). 2 corresponding FG groups (group 1 and group 2). 2 corresponding SSL-VPN portals, and 2 corresponding firewall policies.

 

The intention is if a user is a member of group 1, he will get policy 1 applied (e.g. allow SSH to 1.1.1.1). If a user is a member of group 2, he will get policy 2 applied (e.g. allow SSH to 1.1.1.2). If a user is a member of both groups, he should get both policies applied.

 

However it seems for a member who is in both groups, FG is only receiving group membership for one of the groups (group 1 for 1.1.1.1). I checked the VPN logs and VPN user dashboard widget and saw group 1.

 

Unfortunately limitations to my lab environment prevent me currently from testing whether the user actually has access to 1.1.1.2 (to confirm that FG put him in group 2, but it's just not visible to me).


1. Am I configuring this correctly for my use case?

2. Am I checking the right things (VPN log) to confirm if user was put into multiple groups based on what SAML returned from Entra ID?

6 replies

funkylicious
SuperUser
SuperUser
February 20, 2026

I think that the first portal/group that the user is being matched will count towards the rules that he will match.

the 2nd one will never be checked, if i recall correctly it's first matched, first used and the rest ignored.

"jack of all trades, master of none"
rickas27
rickas27Author
New Member
February 20, 2026

I've removed the separate SSL-VPN setting Authentication/Portal Mappings for each group and then added both groups together to map to a single SSL-VPN Portal (so each group doesn't map to separate SSL-VPN Portals).

 

However this didn't change anything.

funkylicious
SuperUser
SuperUser
February 20, 2026
MorseCode
Visitor
February 20, 2026

Yes, your logic is correct, but you likely need to adjust your Entra ID claim or FortiGate group matching to handle multiple attributes.

1. Are you configuring this correctly?

Mostly, yes. The behavior you're seeing usually happens because Entra ID sends groups in a single multi-valued attribute, but the FortiGate might only be matching the first one it finds in the list unless the group objects are configured as "Remote Group" types pointing to your specific SAML server.

2. Are you checking the right things?

The VPN log and dashboard usually only display the primary group (the first match).

rickas27
rickas27Author
New Member
February 20, 2026

Can you please elaborate on "need to adjust [...] FortiGate group matching to handle multiple attributes"?

I configured a FortiGate user group, added a Remote group to it, pointed it to my SAML server, and then specified the object ID of the Entra security group.

 

Your comment makes me think I'm missing a config somewhere else (maybe in VPN or global config?) that says "allow multiple groups" or something. Is this correct?

 

 

The article (351851) that funklicious posted shows a screenshot of the VPN dashboard widget showing multiple groups for a single user. I feel like this is something that can be done.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!