Skip to main content
guchinife
New Member
April 29, 2024
Question

Wifi access with Single Sign-ON

  • April 29, 2024
  • 6 replies
  • 2311 views

Hello
I have configured a Wifi access with Single Sign-ON (SSO) connection.
The connection is successful after login.
I have created some firewall policies with Azure AD groups.
The problem I have is that to test the accesses of these groups I have to disconnect the wifi session and re-authenticate, but I don't know how to force the disconnection because every time I connect again to the wifi it doesn't ask me for the username/password.
How can I force the user to disconnect from the wifi?

Note: I have tried forgetting the wifi network and restarting, but it continues to log in automatically.

Thanks

Translated with DeepL.com (free version)

6 replies

AEK
SuperUser
SuperUser
April 29, 2024

Hi @guchinife 

Did you try from Dashboard > Users & Devices, then in the user list right-click on the user and click De-authenticate.

AEK
guchinife
guchinifeAuthor
New Member
April 30, 2024

Hi, this option does not work for me, as the users are in Azure AD.

ebilcari
Staff
Staff
April 29, 2024

I guess you have configured portal authentication with SAML as described on this article here. Since the user session will remain until it's timed out, in order to trigger a new login you can try deleting the host in Dashboard> Users & Devices.

Emirjon
guchinife
guchinifeAuthor
New Member
April 30, 2024

Here they don't tell you how to force disconnect users from Azure AD which is what I need.
Thanks

pminarik
Staff
Staff
April 30, 2024

If the problem is that the IdP (Azure/Entra) cookie is cached and the authentication just "fast-forwards" through, just delete the cookies on the endpoint. The FortiGate can't influence what happens with these cookies, that's business between the endpoint and the IdP.

Hong_FTNT
Staff & Editor
Staff & Editor
April 30, 2024
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!