FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
jdelafuente_FTNT
Staff & Editor
Staff & Editor
Article Id 347021
Description

 

This article describes how to configure the ignore user list directly in FortiAuthenticator for FSSO/SSO method. 

 

Scope

 

FortiAuthenticator, FSSO, ignore user list, exempt user in FSSO.

 

Solution

 

One best practice in FSSO is to set up an ignore user list for service accounts.

  1. Import SSO User: access to SSO -> SSO Users -> Import

 

FAC-FSSO-02.png

Select the Remote LDAP server, and select OK.

 

FAC-FSSO-03.png

A new window will appear, expand the tree, find and select the users to ignore, then select OK.

 

FAC-FSSO-04.png

 

  1. Configure the ignore user list. Previously selected users will appear as imported, then go to the menu: SSO -> General -> Fortinet Single Sign-On (FSSO) -> Maximum concurrent user sessions -> Select (configure Per User/Group).

 

FAC-FSSO-05.png

 

At the top right in SSO Users, mark the users to ignore and then select Exclude from SSO.

 

FAC-FSSO-06.png

 

Choose 'Do not affect current user when excluded user logs in' and select OKNow, those users will appear as excluded from SSO.

 

7FAC-FSSO-07.png

 

In the v6.6 branch:

  1. Import SSO User: access to Fortinet SSO -> Filtering -> SSO Users select Import.

 

1.jpg

 

Select the Remote LDAP server, and select Import.

 

2.jpg

 

A new window will appear, expand the tree, find and select the users to ignore, then select OK.

 

3.jpg

  1. Configure the ignore user list. Previously selected users will appear as imported, then go to the menu: Fortinet SSO -> Settings -> Methods -> Maximum concurrent user sessions, select Fine-grained control.

 

4.jpg

 

At the top, select SSO Users, mark the users to ignore, and then select Exclude from SSO.

 

5.jpg

 

Choose 'Do not affect current user when excluded user logs in' and select OK

 

6.jpg

 

These users will appear as excluded from SSO.

 

7.jpg