Hello,
Is it possible to setup MFA by email when authentication is by LDAP or RADIUS.
Actually, I use it when user authentication is on the FGT, but I never setup with LDAP or RADIUS.
Personnaly I made configuration with Duo Security it work well ( push)... But the customer does not want to pay for a license :( So I don't have choice to test email solution.
Thanks for your help
Hi Team,
Yes its possible, you can use this article for the same:
First you need to extract the user from ldap to the firewall and enable email based authentication for that user.
Hello,
I know this tips, but isn't not that.
This tips work when user are declared on Fortigate, and it's working well.
But my authentification use LDAP and / or RADIUS. I have more 300 users on many domains.
So I just want to know if it's possible to use email MFA with LDAP authentification
You always have to define the individual LDAP/RADIUS users when you want to enforce 2FA on Fortigate.
Bellow is an example of email authentication enabled for LDAP user.
config user local
edit "test_user"
set type ldap
set two-factor email
set email-to "test@example.com"
set username-sensitivity disable
set ldap-server "LDAP"
next
end
Ok I will test this week
Thanks
sorry this is old, but keep in mind that reissuing the MFA token will delete this setting. I've requested that they add a global default setting but no action yet.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
764 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.