We are using Forticlient SAML login with Azure AD.
When logging in, the users enters mail address, password and MFA, and it all works.
However, we have setup the conditional access with a 'Sign-in frequency' of 7 days, but the user is prompted for login every time.
We set it up using the client v7.0.7, and it worked perfectly, but after v7.0.8 we get prompted every time.
If we change the tunnel settings to 'Use External Browser as User-agent for SAML Login', a browser tab is opened and then it works - only the first time the user is prompted for login. Any consecutive logins is done automatic (this is not ideal to use permanently as it looks weird with the open browser tab).
So to sum up, is seems that from v7.0.7 to 7.0.8 the Forticlient built in prompt doesn't save your credentials.
Any suggestions,
Thanks in advance, Per.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Having the same issue here, its asking for credentials every single time.
Same here, encountering the exact same issue.
Info: response from Fortinet. It's a known bug (BUGID 0835436). I will update when I know more.
Any updates on this from Fortinet?
No update from Fortinet. They can't (or won't) say when they might be looking at it, whether it will be in a patch release, or if it might be resolved in v7.2.
So a bit disappointing...
This was recommended by Fortinet Support for me, and it seemed to have worked:
In the Remote Access VPN profile:
Enable the "Show Remember Password" checkbox.
In the System profile,
Please, try setting the tag in the XML profile config to '1' and retest.
<system>
<ui>
...
<dont_modify_cookies>1</dont_modify_cookies>
</ui>
Just to clarify this will store the password permanently though, not cache recent credentials? I want it to prompt again if its not used for say a week or so, I don't want their password stored permanently.
It depends on your Azure settings for reauthentication/session timeout (it may be under the Conditional Access policies). We have it set to timeout authentication after 1 hour. So if we disconnect and reconnect a VPN after 1 hour it will prompt for MFA again.
I can confirm, that the solution described by rockhead006 seems to work for us as well.
Still strange then though, that when reported to Fortinet they responded that it was a known bug, and that they haven't returned to me with this 'workaround'. Oh well...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.