Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shawn-ev
New Contributor III

Configure Entra ID SSO for ZTNA authentication

I am starting the process to migrate our SSL-VPN users to ZTNA. We have SSO configured for all SSL-VPN users now. I cannot find any documentation for configuring EntraID as the SSO provider for ZTNA authentication. I have found this reddit post that says it can be done, but all requests for documentation/proof were met with "the site is no longer available" and "I don't have the config anymore", so I'm skeptical.

 

Has anyone configured Entra ID SSO for ZTNA connections? What is the correct Authentication Sheme config? What are the correct ZTNA Server settings and how do they correlate to the existing SSO for SSL-VPN, e.g., login url, logout url, idp url, etc?

 

edit: readability, formatting

2 REPLIES 2
shawn-ev
New Contributor III

As I said in my original post, we already have SSO configured for SSL-VPN using Entra ID. This is already working (same as referenced in your second link, which has nothing to do with ZTNA). We have this same SSO config in place on numerous firewalls where we grant specific access to specific user Entra ID user groups. Works great!

 

I am trying to migrate over to ZTNA. Your first link does not explain how the Entra ID groups are associated to access, and where to put those groups. For example, when configuring SSO for SSL-VPN, I create a User Group object on the firewall, using the Entra ID SSO config, and referencing the Object ID of the Entra ID group. I then identify those groups in firewall rules to allow/deny access. How/where do I "make that connection" for ZTNA.

 

What do I use for the LDAP server? Do I need a separate LDAP server when using Entra ID SSO for ZTNA?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors