I have a new implementation of FortiSASE and trying to integrate with EntraID for SSO. We have followed all the steps as documented here including API permissions : https://docs.fortinet.com/document/fortisase/latest/agent-based-vpn-autoconnect-using-entra-id-sso/5...
SSO still doesn't work and every time, I lock the policy Source to EntraID group (My account is a member of this group), and i try to connect to agent based VPN, it gives me the following error.
AADSTS50105: Your administrator has configured the application FortiSASE ('677888668-56ff-4675-7561-ddee90078') to block users unless they are specifically granted ('assigned') access to the application. The signed in user 'abcd@ybg.com' is blocked because they are not a direct member of a group with access, nor had access directly assigned by an administrator. Please contact your administrator to assign access to this application.
Does anyone knows if there are other steps that needs to be implemented for this to work.
Solved! Go to Solution.
Please refer to the last section ("To manage application permissions")
of this document for available solutions:
hi,
maybe this would help narrow down the issue, https://learn.microsoft.com/en-us/troubleshoot/entra/entra-id/app-integration/error-code-aadsts50105...
Please refer to the last section ("To manage application permissions")
of this document for available solutions:
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.