Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
miciti
Contributor

FortiClient remote access: set browser to use for external saml login

Hello everyone,

 

I have a working configuration for remote accesssing via VPN and SAML (Microsoft Entra). 

 

I am trying to restrict the access to the VPN on only specific devices. It does work when FortiClient uses external saml via edge browser. But when someone has set a different browser (e.g. firefox) as default and FortiClient uses Firefox to provide the SAML login, there are some background informations missing which are needed in entra. 

These information seems to be only available when using edge as browser (shown by my testing). 

 

Is there any way to set edge as browser for using saml and not the machines default browser?

1 Solution
miciti
Contributor

After some testing, I found that setting 'After logon SAML authentication framework' to 'Web browser' made everything work as expected.

On hybrid-joined devices with Active Hello for Business, I can connect to the VPN without providing any additional login details, and Entra retrieves the necessary information from the device.

 

Edit: There is an option in Firefox called 'Windows SSO' which is disabled by default. Enabling it allows Firefox to access the Windows login. It seems that, at least as a quick test, it provides the necessary information for Entra and conditional access.

View solution in original post

3 REPLIES 3
fg_muc
New Contributor III

Hi,

 

I would assume that the FortiClient is simply referring to the “system default” of the operating system as an external browser and that it is not launched directly on the FortiClient.


However, I am also interested in the solution if available.
Maybe someone has a way of mapping this.

"Latency is just your network being dramatic."
"Latency is just your network being dramatic."
ebrlima
Staff
Staff
miciti
Contributor

After some testing, I found that setting 'After logon SAML authentication framework' to 'Web browser' made everything work as expected.

On hybrid-joined devices with Active Hello for Business, I can connect to the VPN without providing any additional login details, and Entra retrieves the necessary information from the device.

 

Edit: There is an option in Firefox called 'Windows SSO' which is disabled by default. Enabling it allows Firefox to access the Windows login. It seems that, at least as a quick test, it provides the necessary information for Entra and conditional access.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors