Hello.
I have a question to FortiClient EMS and registration of endpoints/clients to FortiEMS-Server which is public reachable through port 8013.
I have configured that clients need an invitation code and afterwards need to autenticate with ldap username and password.
Is there any possible to get a two factor authentication via OTP like FortiToken Mobile?
Is this possible with SAML Auth and Microsoft 2FA?
Or is the Invitation Code the second factor?
Thank you.
hi,
assuming that you add FortiAuth as a SAML IdP or even EntraID, I think that you can trigger a 3rd auth method like 2FA if you configure the policy to request OTP for it, first being the invitation ( even thou they would know the IP/FQDN they could not connect w/o a invite code ) , second being the user+password for verification and third being a MFA/OTP , https://docs.fortinet.com/document/forticlient/7.4.4/ems-administration-guide/334169/configuring-use...
| User | Count |
|---|---|
| 2808 | |
| 1427 | |
| 812 | |
| 769 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.