Description | This article describes how to configure authentik as a SAML provider for FortiOS admin users. |
Scope | FortiOS 7.2.x, 7.4.x, and 7.6.x. |
Solution |
Authentik is a self-hosted, open source identity provider that can be configured as a SAML identify provider. Configure the following in order to connect it with FortOS.
Authentik Configuration:
Begin by logging in as an administrator in authentik.
Provider Settings:
After creation, configure the required user/group bindings.
FortiGate Configuration:
Begin by logging in as a current admin to the FortiGate. Navigate to Security Fabric -> Fabric Connectors -> Security Fabric Setup -> Single Sign-On Settings.
Note: In the sign-on and logout URLs, the slug 'fortigate_admin' from above is configured.
After configuration is complete, log out and log back in with the SAML identity to confirm that it is working as expected. A new SSO entry will be listed under System -> Administrators.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.