ZTNA
mavitrecco
Staff
Staff
Article Id 256045
Description This article describes how to configure FortiClient EMS SAML with Azure AD.
Scope FortiClient EMS SAML with Azure AD.
Solution

This article is related to the SAML configuration on FortiClient EMS described in the following document, which contains information about configuration on the Azure AD side:

https://docs.fortinet.com/document/forticlient/7.2.0/ems-administration-guide/156283/saml-configurat... 


Navigate to FortiClient EMS -> User Management -> SAML Configuration -> +Add:

 

mavitrecco_0-1683732068449.png

 

In Azure, access the Azure AD:

 

mavitrecco_1-1683732068457.png

 

mavitrecco_2-1683732068458.png

 

mavitrecco_3-1683732068460.png

 

mavitrecco_4-1683732068461.png

 

mavitrecco_5-1683732068463.png


Create the SSO:

 

mavitrecco_6-1683732068467.png

 

mavitrecco_7-1683732068471.png

 

mavitrecco_8-1683732068475.png


In FortiClient EMS:

mavitrecco_9-1683732068477.png

 

mavitrecco_10-1683732068480.png

 

mavitrecco_11-1683732068481.png


In FortiClient EMS:

 

mavitrecco_12-1683732068482.png

 

In Azure AD, download the certificate:

 

mavitrecco_13-1683732068484.png

 

In FortiClient EMS, upload the certificate:

 

mavitrecco_14-1683732068485.png

 

In Azure AD, choose a user or groups:

ems01.PNG

 

After that, the FortiClient agent with the telemetry configuration will push the authentication screen. It will then be possible to validate the results under FortiClient EMS -> Endpoint -> All Endpoints.

 

ems.PNG