I know enough about FortiAuthenticator to be dangerous, so forgive me if I come across ignorant on the product. I currently have mine setup where I have a SAML connection to Azure where I can pull user and group information; however, the only login event I have been able to accomplish from my non-domain joined devices (which for me is about 90% of my devices as we are 1:1 Apple) is via Syslog from my 3rd party internal web filter appliance for Apple devices. I have a web filter agent providing login info to my filter where it matches it against AD users so that they can be put into the correct groups. Domain joined devices are handled via web filter agent on the AD server for those login events. So in a nutshell, I am able to filter all of that down to my FortiGates into FSSO groups for varied policies to match up against.
So my first question is, why doesn't Fortinet have a simple multi-OS agent that would provide that info directly to the FortiAuthenticator? In my situation, I am having to rely on someone else's technology that does provide a simple agent like this and doing this via syslog seems to be very chatty due to the number of events taking place. I also understand that this is also one part of FortiClient's many features, but I've had bad results with that product and it's support with macOS and had to stop using it as it caused more problems in my environment than it solved.
Second question is, if I am performing logins into Azure (and again, this might just be my ignorance), is there not a way to use those logins (since I'm already tied to Azure anyway) for FSSO use? Can that info not report back to FortiAuthenticator to use for SSO purposes?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
> Where would I make that feature request? Is there a specific URL for this?
This is something you'd need to discuss with your FTNT sales engineer. There's no way for general public to directly submit feature requests.
> if there was a way for Azure to report back those logins to FAC
There has been some research into implementing exactly this into the FSSOMA agent to support smoother FSSO integration with Azure AD users. Not sure what the current state is, and I'm afraid I can't comment much further, so if you're interested, consider reaching out to your sales contact in this case as well and voice your interest, they may be able to provide some further feedback.
There is a barebones, FSSOMA-only, version of FortiClient, but it's Windows-only. You'd need to push through a feature request to get something similar made for Macs as well. With that said, FSSOMA currently only supports traditional AD domains. Support of plain Azure AD is somewhere in the pipeline.
As for SAML->FSSO integration, there's a SAML portal that can be used for this (Fortinet SSO Methods -> SSO -> Portal Services / SAML Authentication). The FAC then basically acts as a captive portal and SAML SP - it redirects the user to the IdP (Azure AD), and then when the user returns with the SAML reply it will ingest the identity&group info and generate an FSSO session out of it.
There's even a cookbook for it - https://docs.fortinet.com/document/fortiauthenticator/6.4.0/cookbook/316341/saml-fsso-with-fortiauth...
Created on 12-08-2022 05:27 AM Edited on 12-08-2022 05:35 AM
Where would I make that feature request? Is there a specific URL for this?
I am familiar with that link, but one item it has you do is it requires you, toward the end, is configure an external captive portal off your FortiGate which would then present yet another Azure login for the user...something that they already did when logging into their device or is being sync'd for them in the background via other methods. Like mentioned, if there was a way for Azure to report back those logins to FAC, that seems to be the most optimal resolve. Like mentioned, I am getting those logins via syslog into FAC currently, but I feel like its a crazy amount of events happening as it's coming from my web-filter.
> Where would I make that feature request? Is there a specific URL for this?
This is something you'd need to discuss with your FTNT sales engineer. There's no way for general public to directly submit feature requests.
> if there was a way for Azure to report back those logins to FAC
There has been some research into implementing exactly this into the FSSOMA agent to support smoother FSSO integration with Azure AD users. Not sure what the current state is, and I'm afraid I can't comment much further, so if you're interested, consider reaching out to your sales contact in this case as well and voice your interest, they may be able to provide some further feedback.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1013 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.