Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aagrafi1
New Contributor III

FG integration with GCPW

Hello,

 

Do you know if FortiOS supports any kind of authentication integration with GCPW (Google Credential Provider for Windows), similar to Windows AD? If not, do you know of any way of interworking with GCPW (with SAML perhaps)? A reference to a documentation link would be appreciated.

 

Thanks

Andreas

6 REPLIES 6
Debbie_FTNT
Staff
Staff

Hey Andreas,

I'm not aware of any use case/integration with GCPW. From what I understand, GCPW is very specifically intended to link Google accounts to Windows AD users, to allow the users to log in to workstations with their Google accounts instead of AD credentials.

There are two slight overlaps where FortiGate could get involved/get information:


- SAML authentication integration with Google
-> Google could serve as IdP to FortiGate, and users could utilize Google credentials for things like SSLVPN, but there would be no overlap with Windows AD


- FSSO
-> When users access workstations with their Google credentials, this should still trigger login events on domain controllers, from what I understand; an FSSO setup should be able to collect that information and consider users logged in on workstations automatically and apply policies based on that user login, but there would be very little/no overlap with Google

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
aagrafi1
New Contributor III

Hello Debbie_FTNT and thanks for the answer.

 

The SAML part is something that I understand.

 

I'm not quite sure that I understand the FSSO part of your answer: "an FSSO setup should be able to collect that information". From where? My understanding is that there is no Microsoft DC and the credential server is Google. Is there any FSSO agent that integrates to the Google Workplace? Am I missing something?

 

Cheers

Andreas

Debbie_FTNT

Hey Andreas,

 

as I understood from reading into GCWP, it's not intended as replacement for AD, but as tie-in for AD, or did I misunderstand the Google documentation I read?

https://support.google.com/a/answer/9796679?hl=en&ref_topic=9539498

-> It sounds to me that the google accounts are either linked to existing AD accounts, or create new ones, as appropriate
-> Assuming the google accounts still create login traces on domain controllers, FSSO should be able to pick up on that.

If I misunderstand how GCPW works, my apologies. There is no FSSO Agent for Google Workplace, and if GCPW replaces an AD structure (or there was no AD in the first place) then FSSO is not an option, as you note.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
davidgabriel
New Contributor

FG integration with GCP is a process of integrating functional groups within an organization with Google Cloud Platform services. The integration enables the functional groups to use Google Cloud resources, such as computing power, storage, and network services, to support their business operations.

The specific details of FG integration with GCP will vary depending on the needs and requirements of the organization and the functional groups involved.

aagrafi1

In layman words? Is it going to be supported sometime, somewhere?

Debbie_FTNT

David's update is regarding GCP (Google Computing Platform) which is not the same as GCPW; googling for GCPW and FortiGate/Fortinet does turn up the Google Computing Platform documents probaby because the abbreviations are so close.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Labels
Top Kudoed Authors