Adding external IdP roles
Create External IdP roles to allow users to log in to a cloud portal with their organization's user credentials using a third-part ID provider.
![]() |
IdP roles is a limited beta feature. New enrollment requests are not available at this time. |
To add an external user role:
- Go to Manage External IdP Roles. The Manage External IdP Roles pane opens.
- Click Add IDP Role.
The Create External IdP Role pane opens.
- In the Role Name field, type the name of the role.
- (Optional) In the Description field, enter a description of the role.
- From the Status dropdown, select active or disabled.
- From the Asset Permissions dropdown, select an asset group. See
- Configure the Effective Portal Permissions.
Permission Description Allow Portal Access Toggle Yes to allow access to a portal.
Access Type The Access Type is defined by the portal. For example, the access types for Asset Management are:
Admin
Read/Only
Read/Write
Whereas the access types for FortiOS SSO are:
SuperAdmin
Read Only
Additional Permission Additional permissions vary depending on the portal.
Asset Management:
Recieve Renewal Notification
FortiCare (Read Only or Read/Write)
Customer Serivce
Technical Assistance
RMA/DOA
Some portals have user roles that are specific to that portal. When a portal has a unique user role, the Custom option is displayed. For information about the role, see the product's documentation.
- Configure the Cloud Management & Services permissions.
- Click Add (+), select a service from the list, and then clickADD.
- Click the Edit button, and configure the portal permissions.
Permission Description Allow Portal Access Toggle Yes to grant access to the service. AccessType The Access Type is defined by the portal. For example, the access types for Asset Management are:
Admin
Read/Only
Read/Write
Whereas the access types for FortiOS SSO are:
SuperAdmin
Read Only
- Click Confirm.
- Click Update.
After the IAM user is created, the IAM user account holder is required to perform a validation check.
To delete a role:
- Go to Manage External IdP Roles. The Manage External IdP Roles pane opens.
- Select a role(s) from the list.
- Click Delete. The Delete Third Party IdP Role(s) dialog is displayed.
- Click Confirm.
To disable a role:
- Go to Manage External IdP Roles. The Manage External IdP Roles pane opens.
- Select a role(s) from the list.
- Click Disable. The Disable User Third Party IdP Role(s) dialog is displayed.
- Click Confirm.
To enable a role:
- Go to Manage External IdP Roles. The Manage External IdP Roles pane opens.
- Double-click the disabled role. The Manage External IdP Roles ><name> pane opens.
- Click Edit.
- From the Status dropdown, select active.
- Click Update.