Enrolling for external IdP
Before you can access the external IdP features supported by FortiCloud, you must first enroll for the service.
To enroll for external IdP access to FortiCloud, you must:
-
Contact your Fortinet sales representative.
-
Configure your IdP application.
-
Fill out the enrollment form with information about your IdP application and FortiCloud account.
-
Download and share the IdP Metadata file with your Fortinet sales representative.
Once your enrollment has been approved, you should:
-
Update the application URLs based on what you received from your Fortinet sales representative. See Configuring external IdP.
-
Configure external IdP roles with which to access the account and FortiCloud Services portals. See Adding external IdP roles to the application and External IdP roles.
-
Configure a co-exist end date for any IAM or sub-users in your account.
All IAM and sub-users of the account will be disabled following the IdP transition period. You can extend this if necessary by setting a co-exist date. See Setting a co-exist end date.
This document only covers configuring external IdP with Okta and Microsoft Entra ID. However, multiple external identity providers are supported by FortiCloud. This topic includes the following enrollment examples:
Enrolling with Okta
External IdP can be enrolled with Okta.
To enroll for external IdP with Okta:
-
Contact your Fortinet sales representative about enrolling for external IdP.
-
Prepare the application:
-
In Okta, go to Applications > Applications.
-
Click Create App Integration.
-
Select SAML 2.0.
-
Click Next.
-
Enter an App Name.
-
Click Next.
-
Enter a temporary URL into the Single sign-on URL and Audience URI (SP Entity ID) fields, such as https://customersso1.fortinet.com/.
After enrollment is complete, your Fortinet sales representative will provide you with the necessary URLs.
-
Click Next.
-
Select the App type.
-
Click Finish. The Metadata file is generated.
-
Download and save the Metadata file.
-
-
Fill out the enrollment form. The following information must be included in the enrollment form:
-
Company name
-
SAML 2.0 IdP name (Okta)
-
Account ID and the Master user email
-
Company administrator and Fortinet Inc. contact
-
IdP Metadata file
The account ID and email can be found in your FortiCloud account dropdown menu. To find the information, log into the Master account. In the top, right corner, select the account. A dropdown menu is displayed that lists the account ID and email information on the left side.
-
-
Send the enrollment form and Metadata file to your Fortinet sales representative.
Once you have been approved, you will receive an email with the next steps and SAML information.
Enrolling with Microsoft Entra ID
External IdP can be enrolled with Entra ID.
To enroll for external IdP with Microsoft Entra ID:
-
Contact your Fortinet sales representative about enrolling for external IdP.
-
Prepare the application:
-
In Microsoft Azure, select Microsoft Entra ID.
-
Go to Enterprise applications.
-
Click New application.
-
Click Create your own application. The Create your own application pane is displayed.
-
Enter the name of the application.
-
Click Create. The Overview page is displayed.
-
Select Set up single sign on.
-
Select SAML.
-
Edit the Basic SAML Configuration:
-
Enter a temporary URL for the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) fields, such as https://customersso1.fortinet.com/.
After enrollment is complete, your Fortinet sales representative will provide you with the necessary URLs.
-
Click Save.
-
-
Download the Federation Metadata XML file from the SAML Certificates section.
-
-
Fill out the enrollment form. The following information must be included in the enrollment form:
-
Company name
-
SAML 2.0 IdP name (Microsoft Entra ID)
-
Account ID and the Master user email
-
Company administrator and Fortinet Inc. contact
-
IdP Metadata file
The account ID and email can be found in your FortiCloud account dropdown menu. To find the information, log into the Master account. In the top, right corner, select the account. A dropdown menu is displayed that lists the account ID and email information on the left side.
-
-
Send the enrollment form and Metadata file to your Fortinet sales representative.
Once you have been approved, you will receive an email with the next steps and SAML information.