| Description | This article describes how to configure FortiGate to accept admin logons over SAML with LDAP credentials. |
| Scope | FortiAuthenticator 6.X. FortiGate 6.2, 6.4, 7.X. |
| Solution |
In FortiAuthenticator, configurations are located under SAML ldP -> General. Follow the steps below:
Add the following claim, filling in details as necessary:
Follow the steps below in FortiGate:
If there is a requirement to bind admin users to the SAML accounts and provide access to the specific VDOM, then follow Technical Tip: FortiGate - Admin login with remote Radius and vdom access profile:
Troubleshooting:
Useful debug commands - httpsd (general admin GUI debugging), samld (SAML-specific debugs).
Usage:
diagnose debug application httpsd -1
diagnose debug application samld -1
diagnose debug console timestamp enable
diagnose debug enable
Related articles:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.