Skip to main content
shawn-ev
Explorer II
June 5, 2026
Question

Preferred FortiClient EMS authentication method for Mac computers managed via JAMF. SAML? LDAP? EntraID?

  • June 5, 2026
  • 1 reply
  • 63 views

We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support  Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document Library

That last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registration/authentication methods should I use for these Mac machines to get the same type of user-level and device-level registration in FCEMS that we have for our Windows machines?

1 reply

Jean-Philippe_P
Staff & Editor
Staff & Editor
June 9, 2026

Hello shawn-ev, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Regards,

Jean-Philippe - Fortinet Community Team