Created on 06-01-2022 08:06 AM Edited on 11-18-2024 04:01 AM By Anthony_E
Description | This article describes SSL VPN with Azure SAML authentication with multi-factor authentication(MFA). |
Scope | FortiGate, FortiClient |
Solution |
Azure Multi-factor authentication can be enabled for SSL VPN with SAML authentication. This can be done by enabling multi-factor authentication on Azure.
No additional setting is require on FortiGate. However, it is important to check whether the authentication timeout for remote servers is long enough for the user to authorize the challenge (MFA).
MFA window will be popped out after entering a credential as the below screenshot.
2024-10-21 11:29:26 [2092:root:b03]Timeout for connection 0x7fb7455800.
This might be not caused by FortiGate and timeout might be controlled by SAML provider or FortiClient timeout settings.
Make sure that the timeout settings in Azure and FortiClient are configured correctly.
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-userstates https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa |