So i've setup SSL VPN with Azure SAML MFA, which is working nicely.
Now i want to add another layer of protection, to make sure users only connect from company owned devices. For this i've setup SCEPman, which is deploying device certificates through Intune.
Coming back to the Fortigate, i have no clue what to do next. I've imported the CA certificate, which is displayed as Remote CA. How do i configure the Fortigate to check for the device certificate? And as step 2 check the validity through OCSP?
I'm guessing you never got a response to this? We're trying to do the same thing, no org issued device certificate, no authentication. Valid device certificate allows the user to continue to username / password / MFA
User | Count |
---|---|
2067 | |
1176 | |
770 | |
448 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.