Hello,
I want to ask you for advice. I am currently managing a FortiGate device where I am running a VPN setup. Within this VPN, I have a requirement to authenticate users against two separate Azure tenants. Both tenants are configured with FortiGate SSL VPN applications.
I have tested the connection, and I observed that when users are in different tenants, the authentication always attempts to validate against a single SAML provider (Users can be authenticated through one tenant, but users from the second tenant are experiencing issues. The system attempts to authenticate them through the first tenant, where they do not have access). I am looking for a solution that allows the system to attempt authentication in the second tenant if the initial SAML authentication fails.
I would appreciate any advice.
Jan
Solved! Go to Solution.
Sure, using realms you can differentiate users to connect in two different IDPs.
BR
HI,
Could you please help me configure Realms? I'm also facing this same tenant issue and stuck at realms.
Created on 02-05-2025 04:46 AM Edited on 02-05-2025 04:47 AM
Hello,
For SAML MFA configuration, I recommend this excellent tutorial: Link . After completing it, you can use realms, which need to be added under VPN > SSL-VPN Realms and VPN > SSL-VPN Settings. There, you'll find the Authentication/Portal Mapping section, where you need to assign a group for VPN access and set the corresponding realm.
Once this configuration is complete, your VPN will allow access via URLs such as:
https://yourDomain.../andYourRealm.
This setup allows you to support multiple tenants. For example:
https://yourDomain.../andYourRealm1
https://yourDomain.../andYourRealm2
And so on...
These addresses will then be used as gateways when connecting.
Best regards,
Jan
Hello @rinshadabbkr
Additional articles that might also help in this case:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Create-SSL-VPN-with-Azure-SAML-SSO-Authent...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-SAML-authentication-with-mult...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-realms-and-SAML-authenticatio...
BR
User | Count |
---|---|
2166 | |
1192 | |
770 | |
451 | |
349 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.