Description | This article describes how to login to FortiClient EMS using SAML SSO with Microsoft Azure AD users. | ||||||||
Scope | FortiClient EMS. | ||||||||
Solution |
The objective of this configuration example is to provide three Entra ID users three distinct EMS admin roles, with the Azure domain being fortitest.net:
The user test is a member of the RestrictedAdminGroup security group in the Entra ID and anyone who is part of this group will be able to login to EMS with the Restricted Administrator role in EMS:
In this example, the Identity Provider Settings configurations will be completed later.
Fill in the Access Control section based on the table above, as demonstrated in the image below. Under the Rule column, enter the Entra ID users, but for the RestrictedAdminGroup security group, enter its object ID instead. Under the Role column, assign the corresponding user and group roles accordingly.
The image below shows overall configurations of EMS and its corresponding Entra ID at a glance:
Attempt to login to EMS with three different Entral ID users. First, enter superadmin@fortitest.net:
After successfully authenticating against Microsoft Azure, EMS login page will show up and since the user is a Super Administrator, can see the Backup and Restore options under System Information along with all menus:
Now, login with the user readonlyadmin, and since this user is Read-only Administrator, there are no Backup and Restore options under System Information, but all menus are still visible without letting the user change any configuration:
Finally, login with the user test, and since this user is a Restricted Administrator, only limited options are available for this user:
These administrators can be removed in FortiClient EMS by selecting the Delete option under Administration -> Admin Users, although the roles cannot be altered.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.