Not sure why my setup isnt working, ive seen conflicting guides on this, i have a saml_user in a saml_group on firewall, i have duo setup to send samaccountname as Username and Group i send the name of the saml group, a little confusing here, but i think that's how it works? Anyways i have the security fabric setup with sso ap for admin login, but that's a different sp. I am not sure what I am missing here.
use this doc and make sure everything is right : https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-DUO-as-SAML-IdP-using-Azure-A...
Hi @margiweno,
In addition to Fortinet document, you can also refer to DUO document in this link "https://duo.com/docs/sso-fortinet-fortigate"
Regards,
Minh
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.