Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
usman907
New Contributor

Mac devices are not passing information for Entra ID conditional access

We configured SSL VPN (SAML authentication) with external IDP (Entra ID). We want to allow only compliant devices to connect to VPN. According to the Fortinet document here this is possible and upon testing it is working for window devices. 

 

However, the instructions are not working for MacOS devices. When we connect from MacOS device we notice that the sign-in log in Entra ID has "Device ID blank". We tested with an embeded browser and with an external browser as suggested in the link but it is still not working.

Please guide me on how to to resolve this issue.

 

1 REPLY 1
Quint021
Staff
Staff

Hello @usman907,


Are you using Safari as your default browser on MAC? Per the article referenced below, only Edge, Chrome, and Firefox support a feature called PRT which is required for conditional access.


Reference: https://community.fortinet.com/t5/FortiClient/Technical-Tip-FortiClient-SSL-VPN-Login-with-Azure-Con...

If the issue still persists after using a different browser, a SAML trace will be required to provide further information.

Reference: https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-record-a-client-SAML-trace...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors