Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
michael2406
New Contributor III

FortiEMS: Two-Factor-Authentication for users in FortiClient

Hello. 

I have a question to FortiClient EMS and registration of endpoints/clients to FortiEMS-Server which is public reachable through port 8013. 

 

I have configured that clients need an invitation code and afterwards need to autenticate with ldap username and password. 

Is there any possible to get a two factor authentication via OTP like FortiToken Mobile? 

Is this possible with SAML Auth and Microsoft 2FA? 

 

Or is the Invitation Code the second factor? 

 

Thank you. 

1 REPLY 1
funkylicious
SuperUser
SuperUser

hi,

assuming that you add FortiAuth as a SAML IdP or even EntraID, I think that you can trigger a 3rd auth method like 2FA if you configure the policy to request OTP for it, first being the invitation ( even thou they would know the IP/FQDN they could not connect w/o a invite code ) , second being the user+password for verification and third being a MFA/OTP , https://docs.fortinet.com/document/forticlient/7.4.4/ems-administration-guide/334169/configuring-use... 

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors