We configured SSL VPN (SAML authentication) with external IDP (Entra ID). We want to allow only compliant devices to connect to VPN. According to the Fortinet document here this is possible and upon testing it is working for window devices.
However, the instructions are not working for MacOS devices. When we connect from MacOS device we notice that the sign-in log in Entra ID has "Device ID blank". We tested with an embeded browser and with an external browser as suggested in the link but it is still not working.
Please guide me on how to to resolve this issue.
Hello @usman907,
Are you using Safari as your default browser on MAC? Per the article referenced below, only Edge, Chrome, and Firefox support a feature called PRT which is required for conditional access.
If the issue still persists after using a different browser, a SAML trace will be required to provide further information.
Reference: https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-record-a-client-SAML-trace...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.