Removing VPN access to AD pull for SAML for KACE
Hello everyone,
I recently configured SAML for our KACE helpdesk platform as we wanted to simplify the login process with SSO through our Azure AD. We got everything working fine and encountered no real access issues at first.
However, it was noted that when trying to use SAML to login from outside the network the login process got stuck in a loop. One further exploration we determined that in order for SAML to pull from AD we had to be on VPN when outside the internal network.
I have scoured forums, blogs, posts, tutorials, youtube and have yet to find the answer to this issue. I put in a support claim with KACE and their assessment is that it's a firewall policy within fortiguard that is preventing an internal device trying to access AD for an internal system but from an external connection.
I have looked through our firewall policies and I am stumped as nothing seems to be preventing this access.
Have anyone encountered this issue before? Any idea where I can resolve this access loop?
