Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

Azure AD

Hello,

Can we use  Azure AD as source on firewall rule, and make the log by username also rather than using source IP?

3 REPLIES 3
pmeet
Staff
Staff

Unfortunately Azure AD can't be connected to FortiGate as windows AD agent also called FSSO.

PATELMM
mle2802
Staff
Staff

Hi @HS08,

You can use Azure as SAML Idp for firewall authentication but user need to login at the time of connection, not like FSSO suggested by my colleague where user can login to their domain computer and the user is already authenticated. Please refer to this document for more information https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/33053/outbound-firewall-auth...

Regards,
Minh

Cajuntank
Contributor II

This might not be applicable to your situation, but I had the same problem due to most of my devices being non-bind AD MacBooks. What I was able to do to solve the problem to get to the result you are asking for, was to use FortiAuthenticator (FAC). What you are trying to get is FSSO like the others have mentioned. That FSSO for me was via the use of this methodology using FAC. I have a web filter that gives me constant syslog info from the clients, thus I am able to match them to policy rules I source out to their FSSO group pretty easily.

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Configure-FSSO-using-Syslog-as-so...

 

There is also a cookbook article to use Azure AD with FAC to achieve FSSO using this article.

https://docs.fortinet.com/document/fortiauthenticator/6.5.0/cookbook/316341/saml-fsso-with-fortiauth...

 

FAC also has a Windows client (though I have never used or implemented it), but they don't have a macOS client, so I never looked further (hint hint Fortinet!!).

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors