Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
muhammadsaad
Contributor

SAML Hybrid Azure Join Implementation | Fortigate | Forticlient EMS

Hello Team,

 

We have integrated the Fortigate with the Forticlient EMS along with Azure IdP for MFA authentication. The forticlient gets connected and Azure IdP with MFA is also working as expected. 

 

Now we are trying to implement Hybrid Azure AD Joined, we are experiencing an issue where FortiClient is not able to recognize that laptop is Hybrid Azure AD Joined, even after the Hybrid Join feature has been enabled in the Conditional Access policy in Azure Active Directory. 

Also, we have followed the below link and check the mark the check on Use External Browser as user-agent for saml user authentication, but its not working.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Implementing-device-based-Conditional-Acce...

 

Anyone can help on this?

12 REPLIES 12
muhammadsaad

Hello,

Thanks for your reply.

We are using SSL VPN, The EMS serial number verification settings is already done on the firewall and its working such that if EMS is not connected on the forticlient and we try to connect the VPN, then it denied the access.

 

The Forticlient version is 7.4.3, Forti OS version is 7.4.8 and Forticlient EMS version is 7.4.1.

 

When we try to connect the user using EMS pushed remote access profiles on the FortiClient, and then sends a connect request its giving a notification of unknown error.

 

Whereas, when we create a manual profile on the forticlient and sends a connection request, its getting re-directed on the browser.

 

Is there any limitations on the Forticlient EMS or some configuration related part is missing? Please advise

Zekeout

No limitations that i am aware of - if you are able to get it working correctly when manually configuring the connection then EMS should be able to do the same. I would review the configuration between the two, something must be different. Double check you have SAML login enabled and External Browser enabled in the advanced settings of the connection profile in EMS.

muhammadsaad

Yes, both check are enabled but still the forticlient is giving an "unknown error"

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors