Recently, I have configured FAC to act as an IdP proxy for Azure for a gate SSL VPN. The primary objective is to use EntraID and EntraID MFA for all company users. In my lab environment, it works pretty well, but on the production endpoint (i.e., with enterprise-enrolled endpoints), it doesn't ask for MFA. It seems to be related to AzureAD PRT and appears to be an issue with Azure rather than FAC problem.
However, I found that it is possible to send the forceAuthn=true attribute in the SAML request. Cannot find how to obtain it in FAC.
Anyone have already facing the same problem ? Did anyone solve it ?
Thx
Hello Rafal,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello Rafal,
We are still looking for someone to help you.
We will come back to you ASAP.
Thanks,
Hello Rafal,
May I invite you to open a ticket with out support?: https://support.fortinet.com/welcome/#/
Thanks a lot in advance.
Regards,
User | Count |
---|---|
2522 | |
1347 | |
794 | |
639 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.