| Description | This article describes how the SAML attribute mismatches between FortiGate and Microsoft Entra ID can cause identity-based policies to fail, resulting in traffic being directed to the implicit deny policy. | ||||||
| Scope | FortiGate v7.x and earlier. | ||||||
| Solution |
Overview. In environments using SAML authentication integrated between FortiGate and Microsoft Entra ID (Azure AD), the correct alignment of SAML attributes is critical for the firewall to properly identify users and groups. When the attributes configured on the FortiGate do not exactly match the attributes sent by Microsoft Entra ID, authenticated traffic fails to match identity-based firewall policies, resulting in the application of the implicit deny policy (Policy ID 0).
Environmental architecture. The authentication and authorization flow works as follows:
Any inconsistency in the attributes breaks this flow at step 3.
Critical configuration on FortiGate. On the FortiGate, under User & Authentication -> Single sign-on, the attributes expected from the IdP are defined:
These names are not symbolic: they must exist exactly as defined in the SAML assertion sent by Microsoft Entra ID.
Corresponding configuration in Microsoft Entra ID. In Microsoft Entra ID -> Enterprise Applications -> Single sign-on -> SAML -> Attributes & Claims, claims must be configured to match the FortiGate expectations, for example:
Important notes:
Common issue: Symptoms:
Root cause: The attributes configured on the FortiGate do not match those sent by Microsoft Entra ID, for example:
As a result:
Firewall impact. When no group match occurs:
This behavior occurs even when authentication is successful, which often confuses troubleshooting.
Recommended best practices.
Conclusion. In FortiGate environments integrated with Microsoft Entra ID via SAML, authentication does not equal authorization. If SAML attributes, especially the group attribute, are not perfectly aligned between Microsoft Entra ID and the FortiGate:
Ensuring attribute consistency is essential for proper identity-based policy enforcement. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.