Use MFA with a shared SSLVPN account
Hello there,
We are an MSP with around 120 different managed fortigates. If we want to quickly troubleshoot something on a client's network remotely, we would make a VPN connection using a custom local user that is joined in a userVPN group.
We are starting to implement SAML SSO via Azure for our managed devices so our users' VPN connections are secured by their MFA as well. Now we want to extend this security feature to our own technicians. So our goal is to either have an authenticator for that one local vpn user which all of the technicians can share (not sure if this is even possible). Or find a way for our technicians to log in with their own M365 accounts (protected by MFA) on every firewall, without the need for extra MFA accounts in our authenticator app.
Will this work by inviting ourselves as guest users in the customer's tenant and adding those accounts to the SAML group?
Other suggestions or techniques to add a protected SSLVPN user account that can be accessed by multiple people are more than welcome. Could this be done by for example a FortiToken or FortiAuthenticator solution?
Thanks in advance for your reply.
