Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Phung_Ong
New Contributor II

ZTNA TCP Forwarding access with NPS extension to provide multi-factor authentication(MFA).

Hi Everyone,

Currently we Utilized NPS Extension (Microsoft Entra ID) to provide the MFA when Access SSL VPN, It works perfect. Now, I am planing to migration SSL VPN to ZTNA (TCP Forwarding) and intend to reuse the NPS extension to provide the MFA when off network access. can someone please provide the guidance for me? is it possible with AZURE SAML can be authenticator to provide the MFA?

Thanks

 

1 Solution
Sx11
Staff
Staff

Hi Phung,

 

in this case you can use the Microsoft Entra ID to provide MFA however it will need to act as a SAML IDP. 

 

An advantage of SAML authentication is that multi-factor authentication (MFA) can be provided by the SAML Identity Provider (IdP)

Example with FAC as IDP

https://docs.fortinet.com/document/fortigate/7.2.7/administration-guide/259754/ztna-application-gate...

 

 

Check the following:

https://docs.fortinet.com/document/fortigate/7.0.4/administration-guide/461532/ztna-proxy-access-wit...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-Azure-SAML-authentication-wit...

 

Regards

sx11

View solution in original post

1 REPLY 1
Sx11
Staff
Staff

Hi Phung,

 

in this case you can use the Microsoft Entra ID to provide MFA however it will need to act as a SAML IDP. 

 

An advantage of SAML authentication is that multi-factor authentication (MFA) can be provided by the SAML Identity Provider (IdP)

Example with FAC as IDP

https://docs.fortinet.com/document/fortigate/7.2.7/administration-guide/259754/ztna-application-gate...

 

 

Check the following:

https://docs.fortinet.com/document/fortigate/7.0.4/administration-guide/461532/ztna-proxy-access-wit...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-Azure-SAML-authentication-wit...

 

Regards

sx11
Labels
Top Kudoed Authors