Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AndreF-Nel
New Contributor II

FortiAuthenticator do not advertise Azure SAML Groups for importing users

Hi All, I configured FortiAuthenticator with integration to Azure, created the Enterprise Application and App Registration on Azure. I require to import / sync only specific group members into FortiAuthenticator as remote users and add them to identified remote SAML Group for specific authentication and autheorization managed by FAC. Unfortunately I do not get a list of groups from Azure and sync imports all users from Azure. We have approximately 9000 groups and around 11000 users in Azure and I do not require all in the FAC group.

Currently open TAC with Microsoft and Fortinet. MS propose SCIM to manage provisioning of users and group but FAC do not have SCIM.

Anyone have a similar issue and how did you resolve?

Kind Regards

Andre F

1 Solution
rbraha

Hi @AndreF-Nel 

 

On newer version of FAC 6.6.0 it is added as new feature that FAC now support SCIM client service.

 

https://docs.fortinet.com/document/fortiauthenticator/6.6.0/release-notes/568509/whats-new#What's_ne...

View solution in original post

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Andre,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
lmarinovic
Staff
Staff

When you want to import the users FAC should give you the list of groups for importing the users:

In this link at the end of document you can find that info:

 

Group Select the SAML server group to import users from.

https://docs.fortinet.com/document/fortiauthenticator/6.5.0/administration-guide/441267/remote-user...

 

Does the groups timeout when you want to list? Does FAC have enough rights to read the Azure?

 

I think on this document is stated what is needed:

https://docs.fortinet.com/document/fortiauthenticator/6.4.0/cookbook/361286/configuring-azure

 

Best regards,

 

Lazar

 

 

 

Best regards

Lazar Marinovic
AndreF-Nel
New Contributor II

New version of FortiAuthenticator 6.5.2 included page listing of Azure groups

rbraha

Hi @AndreF-Nel 

 

On newer version of FAC 6.6.0 it is added as new feature that FAC now support SCIM client service.

 

https://docs.fortinet.com/document/fortiauthenticator/6.6.0/release-notes/568509/whats-new#What's_ne...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors