FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
alwis
Staff
Staff
Article Id 211773
Description This article describes how to use email 2FA for FortiAuthenticator Windows Agent.
Scope FortiAuthenticator v6.2 above.
Solution

Starting from the 6.2.0 version SMS and email two-factor authentication support was added for Microsoft Windows Agent.

 

  1. Configure prerequisite setting for and refer to the link: SMTP servers (it is possible to use Gmail STARTTLS as an SMTP server: Technical Tip: Configure Gmail (STARTTLS) as a mail server and  FortiAuthenticator Agent for Microsoft Windows Install Guide).
  2. Configure OTP and email address for the user.

 

fac1234.png

Agent Testing.

  1. Select the domain from the dropdown menu, enter the username and AD password, leave the OTP field empty, and select enter to trigger an OTP through email.

 

login123.PNG

 

  1. Enter the OTP received on the email.

 

email.png

login321.PNG

 

  1. If login fails, see Appendix A - Debugging to identify the issue.