SAML SSO with Entra ID as IdP
You can configure a single sign on (SSO) connection with Microsoft Entra ID (formerly known as Azure Active Directory (AD)) via SAML, where Entra ID is the identity provider (IdP) and FortiClient EMS is the service provider (SP). This feature allows users to log in to EMS by logging in with their Entra ID credentials.
To configure FortiClient EMS with Entra ID SSO:
- In FortiClient EMS, go to Administration > SAML SSO. Service Provider Settings displays the SP Address, SP Entity ID, and SP ACS (login) URL fields. You use these values to configure FortiClient EMS as an SP in Azure. Copy these values.
- Create and configure your FortiClient EMS environment in Azure:
- In the Azure portal, go to Microsoft Entra ID > Enterprise applications > New application.
- Search for and select FortiClient EMS.
- Click Create.
- Assign Entra ID users and groups to FortiClient EMS.
- Go to Set up single sign on.
- For the SSO method, select SAML.
- In Basic Configuration, enter the values that you copied in step 1. The following summarizes the mapping between EMS fields and Azure fields:
EMS Service Provider Settings field
Entra ID Basic SAML configuration field
SP Entity ID
Identifier (Entity ID)
SP ACS (login) URL
Reply URL (Assertion Consumer Service URL)
SP Address
Sign on URL
- Obtain the IdP information from Azure:
- Configure the IdP information in FortiClient EMS:
- In EMS, under Identity Provider Settings, In the IdP Entity ID and IdP single sign-on URL fields, paste the values that you copied from the Entra ID Identifier and Login URL fields, respectively.
- From the IdP Certificate dropdown list, select Create, then upload the certificate that you downloaded. Click Next.
- Review the SAML configuration, then click Save.