This article describes how to fix the error 'Response validation failed. SAML response rejected' when logging in using SSO FortiCloud in FortiAnalyzer/FortiManager.
FortiManager, FortiAnalyzer, FortiCloud.
Pre-requisite:
Enable 'Allow admins to login with FortiCloud' in System Settings -> Admin -> SAML SSO.
Example:
Registered email for FortiAnalyzer, serial number FAZ-VMTMXXXXXXXX john@test.com (Account ID: 9xxxxxx1).
When logged in using FortiCloud SSO in FortiAnalyzer, it will prompt to the FortiCloud login page, and proceed to access the EMAIL LOGIN page and enter john@test.com credentials.
Example:
Permission Profiles named SSO user created with FortiOS SSO portal enabled, and SuperAdmin for Access Type.
Example: IAM user user1ssoforticloud@gmail.com created, and assigned SSO user for permission profiles
Note:
Account ID is located under the dropdown username
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.