Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rafalm
New Contributor

FortiAuthenticator forceAuthn SAML parameter

Recently, I have configured FAC to act as an IdP proxy for Azure for a gate SSL VPN. The primary objective is to use EntraID and EntraID MFA for all company users. In my lab environment, it works pretty well, but on the production endpoint (i.e., with enterprise-enrolled endpoints), it doesn't ask for MFA. It seems to be related to AzureAD PRT and appears to be an issue with Azure rather than FAC problem.

 

However, I found that it is possible to send the forceAuthn=true attribute in the SAML request. Cannot find how to obtain it in FAC.

Anyone have already facing the same problem ? Did anyone solve it ?

 

Thx

Rafal
Rafal
3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello Rafal,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Rafal,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Rafal,

 

May I invite you to open a ticket with out support?: https://support.fortinet.com/welcome/#/

 

Thanks a lot in advance.

 

Regards,

Anthony-Fortinet Community Team.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors