FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kcheng
Staff
Staff
Article Id 207005
Description This article describes how to create IAM users in FortiCloud and allow login into the FortiGate administrator UI with read/write access.
Scope FortiGate 7.0.x, FortiCloud SSO.
Solution

In FortiOS 7.0.0 and above, a new feature that allows FortiCloud SSO login is introduced. 

 

To enable FortiCloud SSO login, go to System -> Settings and toggle FortiCloud Single Sign-On to On:

 

FG.png

 

To configure IAM users in FortiCloud, login to FortiCloud portal (https://www.forticloud.com) with administrator access.

 

Follow the steps below:

 

  1. Select Services -> IAM.

 

IAM.png

 

  1. Select 'ADD IAM USER'.

 

IAM_U.png

 

  1. Enter the details of the user:

 

IAM_U2.png

 

  1. In the User Permissions section, select the pencil icon beside FortiOS SSO, and assign proper access type:

 

Permission.png

 

  1. Review the configured details and select 'Confirm' to create the user:

 

Confirm.png

 

  1. Once the user has been created, a CSV will be generated. Download the file as it contains the password for the user to login as an IAM user:

 

Created.png

 

  1. Send the downloaded CSV file to the corresponding user.

 

Once the above has been configured, proceed to login to the FortiGate GUI using the usual URL (https://<fortigate-IP/domain>:<port>).

 

  • Notice an additional 'Sign in with FortiCloud' button. Select it.

signin.png

  • Select 'Sign in as IAM user':

 

signiniam.png

 

  • In the login form, fill in the details recorded in the CSV file downloaded previously:

 

login.png

 

  • The user is now logged in with FortiCloud SSO with the assigned rights:

 

succ.png

 

Additional notes:

Note that FortiCloud SSO could fail in the following cases:

 

  • If the FortiGate is not registered to the FortiCare account used for login, it will reject the login and give the user the option to switch account or login locally.
  • If the master account has '2FA auth enforcement' enabled, IAM users without 2FA configured will be rejected.
  • If the FortiGate is a VM appliance with a PAYG (Pay-As-You-Go) license. Note that FortiCloud SSO is not yet supported on VM with PAYG licenses.