FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Nur
Staff
Staff
Article Id 307971
Description This article describes how to resolve an issue where the customer is unable to log in to FortiAnalyzer using SAML SSO.
Scope SAML SSO, Azure, and FortiAnalyzer.
Solution

The following error appears upon trying to access FortiAnalyzer with SAML SSO:

 

Screenshot 2024-04-02 210346.png

 

To fix this:

 

  1. Fill in the 'Relay State' on Azure:

https://<IP address or FQDN>:<port number>/p/sso_sp/

 

  1. If step 1 did not work: in Azure, the 'Reply URL' is the 'SP ACS (Login) URL'. Leave the 'sign on URL' blank.

     

Screenshot 2024-04-02 211039.png

 

Related article:

Technical Tip: SAML SSO - FortiManager/FortiAnalyzer Troubleshooting Options.