Do you have any on-premise read only domain controllers? If not, do you
have domain services enabled with your AzureAD. If you do, fortiGate can
talk via LDAP to either of those services to perform WPA-Enterprise Auth
for your wireless clients (using...