Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nplljw
New Contributor II

how to specify a FAC group for Fortigate administrator login

Hello, I would like to know how to use FortiAuthenticator to configure saml SSO login for Fortigate administrators, and how to specify a FAC group for Fortigate administrator login

1 Solution
2 REPLIES 2
pminarik
Staff
Staff

FortiGate currently does not support group-based or wildcard-admin-based administrator logins with SAML. All authentication is individual, per-user. No support for dynamic VDOM assignment or access profile assignment either.

 

Restrictions as to who can authenticate can only be imposed from the IdP side. Unfortunately, FortiAuthenticator only allows configuring group-based restrictions on the "global level" for SAML (SAMl IdP > General), not on a per-SP basis. But maybe that will suffice for you?

[ corrections always welcome ]
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors