FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
ChrisTan
Staff
Staff
Article Id 411893
Description This article describes the Adaptive MFA rule, which allows bypassing the OTP by subnet range or Known devices.
Scope FortiAuthenticator v6.6.3+.
Solution

Starting from v6.6.3, the FortiAuthenticator has the Adaptive MFA rule, to combines the trust subnet and known devices to give control over bypassing OTP.

 

The configuration process involves two key steps:

Defining Trusted Subnets: Trusted subnets (e.g., the corporate office IP range) are configured under: Authentication -> User Account Policies -> Trusted Subnets.

 

2025-09-22_14h51_21.png

   

Creating an Adaptive MFA Rule: Creating a new rule under the Adaptive MFA Rules section. The pre-defined trusted subnet can  be applied. 

 

2025-09-22_15h16_42.png

 

Once the Adaptive MFA rule is configured, it is applied by selecting it within a RADIUS policy. This means that when FortiAuthenticator processes an authentication request from a RADIUS client (like a FortiGate for VPN access), it will evaluate this rule.

 

If the user is connecting from a trusted subnet and on a known device, the OTP challenge will be bypassed, granting access with just a username and password.

 

2025-09-22_15h28_07.png

 

 

 

Contributors