Skip to main content
Explorer
July 22, 2026
Solved

SSO Authentication Behavior Change with Embedded Browser in FortiClient 7.4.3

  • July 22, 2026
  • 4 replies
  • 167 views

Previously, with FortiClient version 7.2.13, when users initiated the VPN connection using SSO, FortiClient automatically detected the existing sign-in sessions for the customer's corporate accounts. When the authentication window was displayed, the available accounts were presented for selection, allowing users to authenticate without re-entering their credentials.

However, after upgrading FortiClient to version 7.4.3, this behavior has changed. When using FortiClient's embedded browser for SSO authentication, users are always prompted to enter their username and password. The embedded browser no longer detects existing Microsoft Entra ID (Azure) sessions or displays the available signed-in accounts.

On the other hand, we have verified that when FortiClient is configured to use an external browser for SSO authentication, the expected behavior is observed. The external browser correctly detects the existing Microsoft Entra ID (Azure) sessions, displays the available  corporate accounts, and allows users to authenticate without having to enter their credentials again.

We would like to know whether this is an expected behavior introduced in this version, or whether there has been any change in how the embedded (internal) browser handles or reads authentication cookies and existing Microsoft Entra ID sessions.

Best answer by Stephen_G

Hi again emilio.alonso,

Have you consulted this resource? Technical Tip: FortiClient SAML Authentication Configuration Demystified | Community It may help with what you’re trying to do. 

Beyond that, we encourage you to open a Support ticket so we can try to assist you. 

4 replies

Stephen_G
Staff & Editor
Staff & Editor
July 27, 2026

Hi emilio.alonso,

Thank you for using Fortinet Community. We will look to get you an answer or help. In the meantime, if anyone else has any advice, feel free to contribute!

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
July 29, 2026

Hi emilio.alonso,

We are still trying to get you an answer or help. I’ve a few resources in mind to check - we’ll get back to you as soon as we can. 

In the meantime, if anyone else has any ideas, feel free to share.

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Stephen_GAnswer
Staff & Editor
July 30, 2026

Hi again emilio.alonso,

Have you consulted this resource? Technical Tip: FortiClient SAML Authentication Configuration Demystified | Community It may help with what you’re trying to do. 

Beyond that, we encourage you to open a Support ticket so we can try to assist you. 

Stephen_G - Fortinet Community Team
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!