Created on
12-11-2025
03:58 AM
Edited on
12-12-2025
05:11 AM
By
Jean-Philippe_P
| Description | This article describes the issue where the SAML authentication for the user is failing, and FortiAuthenticator is acting as IDP. The following error message is prompted '403 Forbidden You are not allowed to access this resource Please contact your Administrator.' |
| Scope | FortiGate, FortiAuthenticator. |
| Solution |
In the attached image, the following error is shown to the end user after SAML authentication:
This is because the misconfigured SAML SP Metadata aa shown in the image:
The same can be verified in the FortiAuthenticator logs.
The correct SAML SP Metadata is:
http://192.168.1.1:1003/remote/saml/metadata/
Once the SP Metadata is corrected, the SAML auth succeeds without any issue.
The administration guide explaining how to configure FortiAuthenticator as a SAML Identity Provider (IdP) can be found here: Configuring FortiAuthenticator as SAML IdP and FortiGate as SAML SP |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.