| Description | This article explains the limitation that Identity Provider (IdP)-initiated or Proxy-initiated SAML Single Sign-On (SSO) login is not supported for FortiGate login due to security concerns. |
| Scope | FortiGate. |
| Solution |
FortiGate supports only Service Provider (SP)-initiated SAML SSO, as it provides better security and control over the login process. When users attempt to authenticate via IdP/Proxy-initiated SAML logins, the authentication will fail, resulting in an error. When an attempt is made to log into FortiGate using IdP/Proxy-initiated SAML SSO, the following errors may be seen in CLI debugs. Error "Bad request error" will be seen on GUI login page. diagnose debug application samld -1 It is recommended to always initiate SAML authentication from the FortiGate (SP) side to ensure proper SAML SSO authentication. Refer to the below KB article to configure Service Provider (SP) initiated SAML SSO login on FortiGate: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.