Does your radius pull your user creds from your windows AD LDAP? If so,
you can use your radius as an authentication proxy like you would with
FAC. You'll need to make your Fortigate a radius client, then it will
proxy authentication requests to ldap...