I had SAML to Microsoft Entra ID working fine for a little bit here, but then FortiClient started showing "Credential or SSLVPN configuration is wrong. (-7200)" on every connection attempt.
SAML works just fine when connecting to the same system over WebVPN, so this does not appear to be an issue with the SAML config.
Any suggestions for getting FortiClient to work again?
I'm using FortiClient 7.2.2.0864 at the moment.
I haven't tried with multiple computers, but again, SAML works fine on this same computer for Web VPN, it is only FortiClient that is not cooperating.
I rebooted and FortiClient worked for a couple of connections again before it stopped working again. It seems that if I connect to a couple of FortiGates using the same SAML account that FortiClient caches something incorrectly.
For Windows 11 using 7.2.8 resolved the issue for a end customer
7.4.x Resulted in the same error as you described
I can’t remember the error message I got when testing but know that I saw a similar issue when DTLS was enabled in the client - turning that off and they could connect fine. Also macOS and realms seemed to be broken with SAML if that would be relevant to your case. not retested on latest FortiOS 7.0.1 yet, only 7.0.0
We are experiencing the same issue on version 7.4.2.1737
To get it working we now switched on the setting "Use external browser as user-agent for saml user authentication".
Will test further.
User | Count |
---|---|
2403 | |
1294 | |
778 | |
538 | |
454 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.