FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mle2802
Staff
Staff
Article Id 425544
Description This article describes how to troubleshoot the issue with wrong username displayed on the FortiGate using SAML SSO for authentication. In this example, IPsec VPN is used with Azure SAML SSO.
Scope FortiGate and Azure SAML SSO.
Solution

After a user successfully has logged in to the dial-up IPsec VPN using an SAML SSO, the member column may display 'userprincipalname' instead of the real username under IPsec VPN monitor.

Screenshot 2026-01-06 100303.png
This is caused by the attribute 'username' on Azure being configured with wrong source attribute. 

Screenshot 2026-01-06 100606.png
The correct source attribute in this scenario should be 'user.userprincipalname' instead of 'userprincipalname'.

Screenshot 2026-01-06 100845.png

 

After changing it, the username is correctly displayed on FortiGate.

Screenshot 2026-01-06 101121.png