Description | This article describes the Adaptive MFA rule, which allows bypassing the OTP by subnet range or Known devices. |
Scope | FortiAuthenticator v6.6.3+. |
Solution |
Starting from v6.6.3, the FortiAuthenticator has the Adaptive MFA rule, to combines the trust subnet and known devices to give control over bypassing OTP.
The configuration process involves two key steps: Defining Trusted Subnets: Trusted subnets (e.g., the corporate office IP range) are configured under: Authentication -> User Account Policies -> Trusted Subnets.
Creating an Adaptive MFA Rule: Creating a new rule under the Adaptive MFA Rules section. The pre-defined trusted subnet can be applied.
Once the Adaptive MFA rule is configured, it is applied by selecting it within a RADIUS policy. This means that when FortiAuthenticator processes an authentication request from a RADIUS client (like a FortiGate for VPN access), it will evaluate this rule.
If the user is connecting from a trusted subnet and on a known device, the OTP challenge will be bypassed, granting access with just a username and password.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.