FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
btan
Staff & Editor
Staff & Editor
Article Id 376760
Description This article describes how to resolve the 'expecting attribute "userPrincipalName"' message when performing FortiClient SAML User Verification with Entra ID.
Scope FortiClient EMS v7.0, v7.2 and v7.4
Solution

After configuring SAML user verification with Entra ID, the endpoint is getting 'The SAML configuration you are using to authenticate is expecting the userPrincipalName attribute "userPrincipalName" error message:

 

feb-kb3-1.PNG

 

This is due to there being non-default Entra ID settings in the Azure tenant. 

 

To resolve this:

  1. In the Entra ID application, go to Single sign-on.
  2. Under Attributes & Claims, add a claim for userPrincipalName:


feb-kb3-2.PNG

Select Add a new claim:

  • In the Name field, type userPrincipalName.
  • In the Source attribute field, select user.userPrincipalName.

 

  1. Save the configuration. On the endpoint FortiClient, enter the Invitation Code with SAML verification, the verification will be successful.

 

feb-kb3-3.PNG

Contributors