I ran into the same issue, though our CA policy was in place from the
beginning of FortiClient deployment. To get ours to work, we needed to
enable 'Use External Browser as User-agent for SAML Login'. It has
worked for us and is only required (so far...