Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nuGeorge
New Contributor

Using OAUTH with G Suite Directory

Hi guys

 

I have a client that is wanting to use G Suite as their IdP for SSO. They want to be able to apply different policies to different Gsuite groups, which I've managed to get working by obtaining group membership from SAML assertions text-based list, which requires I manually create the SSO group on the FortiAuthenticator. However I want the FortiAuthenticator to be able to do this automatically by looking up the Gsuite directory and pulling all the Groups. So I set up a service account, downloaded the service key json file etc and set my SAML to Obtain group membership from Cloud > my oauth. The problem is when I try logon using SSO I get to my Google login prompt and login, however after this it just times out trying to get to my ACS URL.

 

Any ideas? Has anyone managed to get this working before? 

0 REPLIES 0