FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
rbraha
Staff
Staff
Article Id 281383
Description This article describes how to login in windows with local users using the FortiAuthenticator Agent.  
Scope FortiAuthenticator.  
 

In some cases, a local account is created on the PC and it is necessary for these users to login with 2FA using the FortiAuthenticator Agent.

Refer to the documentation for FortiAuthenticator Agent configuration.

 

To log in with local users, it is necessary to have the '.' realm created on FortiAuthenticator.

The same username/password should be set on the FortiAuthenticator local user database.

 

facagent1.jpg

 

The same user credentials that exist on windows are created on FortiAuthenticator with local users with tokens assigned on FortiAuthenticator.

 

facagent2.jpg

 

The example above was a test performed on Windows with the user 'gimi'. On the FortiAuthenticator Agent, select '.' instead of domain.

Enter credentials. A prompt for a token will appear.

 

facagent3.jpg

 

Since the FortiAuthenticator Agent communicates with FortiAuthenticator through a Rest API, it is possible to check from debug logs on FortiAuthenticator.

 

Navigate to https://<fac-ip>/debug and select the REST API while in FortiAuthenticator Agent -> Simulation -> View Logs.

facagent4.jpg

 

If there is the error 'User name or password is incorrect':

  1. Ensure the local username and password are the same as the credentials for the Windows username and password.
  2. Ensure REST API is enabled on the interface facing the PC.
  3. Download FortiAuthenticator Agent from FortiAuthenticator itself under Authentication -> FAC Agent -> Microsoft Windows Agent, to ensure compatibility.
     Screenshot 2024-08-29 090352.png