FortiSASE
FortiSASE delivers both a consistent security posture and an optimal user experience for users working from anywhere. Secure your hybrid workforce by closing security gaps, plus simplify operations.
adhawan
Staff
Staff
Article Id 327124

 

Description This article describes the script error 'Access is denied' while the VPN auto-connects using Entra ID SSO.
Scope FortiSASE.
Solution

As shown in the below image. The Script error  'Access is denied' indicated that the custom redirect URL field is blank.


Auto-Login.png
Solution:
Check and confirm: it is necessary to register the enterprise application in Azure to allow the FortiClient as a mobile/desktop application to query Microsoft Entra ID identity services. 


Screenshot 2024-07-22 102116.png

 

Enable 'Use External Browser as User-agent for SAML Login' in the profiles under Configuration -> Profiles, edit the profile -> Connection -> VPNs available to users, select Secure Internet Access -> Advanced Settings> Use external browser as user-agent for SAML login.

 

Identify the profile for the connected user using the below KB article: Technical Tip: How to identify the Profile and security POP used by a connected VPN user

 

saml-external.png

 

This setting will allow FortiClient to launch the default external web browser, and allow end users to log in using the web browser instead of the FortiClient embedded web browser.

 

Related document:
Registering FortiSASE as a mobile/desktop application with a custom redirect URI