So I have been struggling for a bit to figure out why my SSL VPN configuration with Azure SAML doesn't work with FortiClient 7.4.2. Older FortiClient version seem to not have this issue. The most telling thing I see in the server debug log is:
[394:root:5b4b]SSL state:fatal decode error (x)
SSL state:fatal decode error (x)
then:
[394:root:5b4c]saml login [394:23372] SAML_ERROR: Error occurred during remote login 'could not found corresponding saml session (101)'
If I use the option in FortiClient "Use external browser as user-agent for saml user authentication", I get no such error and everything works just fine.
Any guesses as to what might be causing this issue? When I searched on this issue, I only found similar issues but where the opposite was true - using external browser for saml user authentication did not work as expected.
I am a little reluctant to upgrade the users to such an unstable situation.
To check:
Same error message in this KB
SAML_ERROR: Error occurred during remote login 'could not found corresponding saml session (101)'
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Unable-to-login-on-SSL-VPN-48-using-...
| User | Count |
|---|---|
| 2926 | |
| 1455 | |
| 862 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.