Skip to main content
Knuppel
New Member
July 1, 2021
Question

SSL VPN with Azure SAML and SCEPman

  • July 1, 2021
  • 1 reply
  • 2507 views

So i've setup SSL VPN with Azure SAML MFA, which is working nicely.

Now i want to add another layer of protection, to make sure users only connect from company owned devices. For this i've setup SCEPman, which is deploying device certificates through Intune.

 

Coming back to the Fortigate, i have no clue what to do next. I've imported the CA certificate, which is displayed as Remote CA. How do i configure the Fortigate to check for the device certificate? And as step 2 check the validity through OCSP?

1 reply

Helpdesk275
New Member
July 6, 2022

I'm guessing you never got a response to this? We're trying to do the same thing, no org issued device certificate, no authentication. Valid device certificate allows the user to continue to username / password / MFA

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!