Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Cajuntank
Contributor II

FortiAuthenticator and Azure questions?

I know enough about FortiAuthenticator to be dangerous, so forgive me if I come across ignorant on the product. I currently have mine setup where I have a SAML connection to Azure where I can pull user and group information; however, the only login event I have been able to accomplish from my non-domain joined devices (which for me is about 90% of my devices as we are 1:1 Apple) is via Syslog from my 3rd party internal web filter appliance for Apple devices. I have a web filter agent providing login info to my filter where it matches it against AD users so that they can be put into the correct groups. Domain joined devices are handled via web filter agent on the AD server for those login events. So in a nutshell, I am able to filter all of that down to my FortiGates into FSSO groups for varied policies to match up against.

 

So my first question is, why doesn't Fortinet have a simple multi-OS agent that would provide that info directly to the FortiAuthenticator? In my situation, I am having to rely on someone else's technology that does provide a simple agent like this and doing this via syslog seems to be very chatty due to the number of events taking place. I also understand that this is also one part of FortiClient's many features, but I've had bad results with that product and it's support with macOS and had to stop using it as it caused more problems in my environment than it solved.

 

Second question is, if I am performing logins into Azure (and again, this might just be my ignorance), is there not a way to use those logins (since I'm already tied to Azure anyway) for FSSO use? Can that info not report back to FortiAuthenticator to use for SSO purposes?

1 Solution
pminarik

> Where would I make that feature request? Is there a specific URL for this?

 

This is something you'd need to discuss with your FTNT sales engineer. There's no way for general public to directly submit feature requests.

 

if there was a way for Azure to report back those logins to FAC

 

There has been some research into implementing exactly this into the FSSOMA agent to support smoother FSSO integration with Azure AD users. Not sure what the current state is, and I'm afraid I can't comment much further, so if you're interested, consider reaching out to your sales contact in this case as well and voice your interest, they may be able to provide some further feedback.

[ corrections always welcome ]

View solution in original post

3 REPLIES 3
pminarik
Staff
Staff

There is a barebones, FSSOMA-only, version of FortiClient, but it's Windows-only. You'd need to push through a feature request to get something similar made for Macs as well. With that said, FSSOMA currently only supports traditional AD domains. Support of plain Azure AD is somewhere in the pipeline.

 

As for SAML->FSSO integration, there's a SAML portal that can be used for this (Fortinet SSO Methods -> SSO -> Portal Services / SAML Authentication). The FAC then basically acts as a captive portal and SAML SP - it redirects the user to the IdP (Azure AD), and then when the user returns with the SAML reply it will ingest the identity&group info and generate an FSSO session out of it.

There's even a cookbook for it - https://docs.fortinet.com/document/fortiauthenticator/6.4.0/cookbook/316341/saml-fsso-with-fortiauth...

[ corrections always welcome ]
Cajuntank

Where would I make that feature request? Is there a specific URL for this?

 

I am familiar with that link, but one item it has you do is it requires you, toward the end, is configure an external captive portal off your FortiGate which would then present yet another Azure login for the user...something that they already did when logging into their device or is being sync'd for them in the background via other methods. Like mentioned, if there was a way for Azure to report back those logins to FAC, that seems to be the most optimal resolve. Like mentioned, I am getting those logins via syslog into FAC currently, but I feel like its a crazy amount of events happening as it's coming from my web-filter.

pminarik

> Where would I make that feature request? Is there a specific URL for this?

 

This is something you'd need to discuss with your FTNT sales engineer. There's no way for general public to directly submit feature requests.

 

if there was a way for Azure to report back those logins to FAC

 

There has been some research into implementing exactly this into the FSSOMA agent to support smoother FSSO integration with Azure AD users. Not sure what the current state is, and I'm afraid I can't comment much further, so if you're interested, consider reaching out to your sales contact in this case as well and voice your interest, they may be able to provide some further feedback.

[ corrections always welcome ]
Labels
Top Kudoed Authors