FortiGate FSSO has been successfully configured and enrolled. However, when applying it to a firewall policy and checking user connectivity, the connection appears to be successful.
The issue arises when a user logs into their laptop using fingerprint authentication or a PIN code—under these conditions, the FSSO-based policy is bypassed, and unrestricted access (e.g., to websites like YouTube) is allowed.
I would like to understand the root cause of this behavior and whether there is a viable solution to address it.
Hi @Reshans
Probably when user login with with fingerprint or PIN it skips the default method for generating user event logs when logging to domain controller, so IP to username mapping is not created in FortiGate then it can hit bypass policy or any mismatch policy.
I think better option will be using FSSOMA and FortiAuthenticator where the agent send information to CA in this case FortiAuthenticator regardless of method used to login ,it supports Fingerprint,PIN,Biometric..
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.