Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor II

FortiAuthenticator do not advertise Azure SAML Groups for importing users

Hi All, I configured FortiAuthenticator with integration to Azure, created the Enterprise Application and App Registration on Azure. I require to import / sync only specific group members into FortiAuthenticator as remote users and add them to identified remote SAML Group for specific authentication and autheorization managed by FAC. Unfortunately I do not get a list of groups from Azure and sync imports all users from Azure. We have approximately 9000 groups and around 11000 users in Azure and I do not require all in the FAC group.

Currently open TAC with Microsoft and Fortinet. MS propose SCIM to manage provisioning of users and group but FAC do not have SCIM.

Anyone have a similar issue and how did you resolve?

Kind Regards

Andre F

Community Manager
Community Manager

Hello Andre,

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Anthony-Fortinet Community Team.

When you want to import the users FAC should give you the list of groups for importing the users:

In this link at the end of document you can find that info:


Group Select the SAML server group to import users from.


Does the groups timeout when you want to list? Does FAC have enough rights to read the Azure?


I think on this document is stated what is needed:


Best regards,






Best regards

Lazar Marinovic
New Contributor II

New version of FortiAuthenticator 6.5.2 included page listing of Azure groups


Hi @AndreF-Nel 


On newer version of FAC 6.6.0 it is added as new feature that FAC now support SCIM client service.'s_ne...

Top Kudoed Authors