In SAML Configuration, you can configure connections to SAML identity providers (IdP), such as Azure Active Directory (AD). This allows end users to connect to FortiClient EMS and authenticate using their relevant credentials, such as to Azure AD.
- In EMS, go to User Management > SAML Configuration.
- In the Name field, enter the desired name for this configuration.
- For Authorization Type, do one of the following:
- Select LDAP to associate a domain with this SAML configuration. From the Domain dropdown list, select the desired domain.
- Select None to not associate a domain with this SAML configuration. This is only recommended for non-domain endpoints.
- Configure Service Provider Settings. EMS is the service provider (SP):
Enter the prefix generated in EMS for the IdP. You can generate a new prefix by clicking the Generate button.
SP ACS (login) URL
Enter the SP login URL.
SP Entity ID
Enter the SP entity ID.
Click Upload new certificate to upload the SP certificate.
Only upload an SP certificate if you uploaded the same certificate for this SP (in this case, EMS) in the IdP server.
- Configure Identity Provider Settings:
IdP single sign-on URL
Enter the IdP single sign-on URL, including the http or https prefix as applicable.
IdP entity ID
Enter the IdP entity ID, including the http or https prefix as applicable.
Click Upload new certificate to upload the IdP certificate.
Upload the same certificate that you configured in the IdP.
- Click Save.