On your ADFS IdP, configure FortiAuthenticator as a SAML SP and return the following SAML assertions:
Type: Proxy
Subject NameID: MS-DS-consistencyGUID
IDPEmail: userPrincipalName
username: sAMAccountName