Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Phung_Ong
New Contributor II

ZTNA TCP Forwarding access with NPS extension to provide multi-factor authentication(MFA).

Hi Everyone,

Currently we Utilized NPS Extension (Microsoft Entra ID) to provide the MFA when Access SSL VPN, It works perfect. Now, I am planing to migration SSL VPN to ZTNA (TCP Forwarding) and intend to reuse the NPS extension to provide the MFA when off network access. can someone please provide the guidance for me? is it possible with AZURE SAML can be authenticator to provide the MFA?

Thanks

 

1 Solution
Hatibi
Staff
Staff

Hi Phung,

 

in this case you can use the Microsoft Entra ID to provide MFA however it will need to act as a SAML IDP. 

 

An advantage of SAML authentication is that multi-factor authentication (MFA) can be provided by the SAML Identity Provider (IdP)

Example with FAC as IDP

https://docs.fortinet.com/document/fortigate/7.2.7/administration-guide/259754/ztna-application-gate...

 

 

Check the following:

https://docs.fortinet.com/document/fortigate/7.0.4/administration-guide/461532/ztna-proxy-access-wit...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-Azure-SAML-authentication-wit...

 

Regards

View solution in original post

1 REPLY 1
Hatibi
Staff
Staff

Hi Phung,

 

in this case you can use the Microsoft Entra ID to provide MFA however it will need to act as a SAML IDP. 

 

An advantage of SAML authentication is that multi-factor authentication (MFA) can be provided by the SAML Identity Provider (IdP)

Example with FAC as IDP

https://docs.fortinet.com/document/fortigate/7.2.7/administration-guide/259754/ztna-application-gate...

 

 

Check the following:

https://docs.fortinet.com/document/fortigate/7.0.4/administration-guide/461532/ztna-proxy-access-wit...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-Azure-SAML-authentication-wit...

 

Regards

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors