SSO Authentication Behavior Change with Embedded Browser in FortiClient 7.4.3
Previously, with FortiClient version 7.2.13, when users initiated the VPN connection using SSO, FortiClient automatically detected the existing sign-in sessions for the customer's corporate accounts. When the authentication window was displayed, the available accounts were presented for selection, allowing users to authenticate without re-entering their credentials.
However, after upgrading FortiClient to version 7.4.3, this behavior has changed. When using FortiClient's embedded browser for SSO authentication, users are always prompted to enter their username and password. The embedded browser no longer detects existing Microsoft Entra ID (Azure) sessions or displays the available signed-in accounts.
On the other hand, we have verified that when FortiClient is configured to use an external browser for SSO authentication, the expected behavior is observed. The external browser correctly detects the existing Microsoft Entra ID (Azure) sessions, displays the available corporate accounts, and allows users to authenticate without having to enter their credentials again.
We would like to know whether this is an expected behavior introduced in this version, or whether there has been any change in how the embedded (internal) browser handles or reads authentication cookies and existing Microsoft Entra ID sessions.
