Hi Everyone,
Currently we Utilized NPS Extension (Microsoft Entra ID) to provide the MFA when Access SSL VPN, It works perfect. Now, I am planing to migration SSL VPN to ZTNA (TCP Forwarding) and intend to reuse the NPS extension to provide the MFA when off network access. can someone please provide the guidance for me? is it possible with AZURE SAML can be authenticator to provide the MFA?
Thanks
Solved! Go to Solution.
Hi Phung,
in this case you can use the Microsoft Entra ID to provide MFA however it will need to act as a SAML IDP.
An advantage of SAML authentication is that multi-factor authentication (MFA) can be provided by the SAML Identity Provider (IdP)
Example with FAC as IDP
Check the following:
Regards
Hi Phung,
in this case you can use the Microsoft Entra ID to provide MFA however it will need to act as a SAML IDP.
An advantage of SAML authentication is that multi-factor authentication (MFA) can be provided by the SAML Identity Provider (IdP)
Example with FAC as IDP
Check the following:
Regards
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.