Enabling passthrough for IdP Proxy use cases
In all SSO applications, the Passthrough option in the Authentication tab can be enabled for IdP Proxy for use cases wherein the users do not exist in the FIC system. With this option enabled, users from the configured identity provider can access the application once they have been successfully authenticated by the remote identity provider. For more information, see License consumption for passthrough users.
By default, the Passthrough option is enabled in FortiSASE SSO application configuration. This makes it easier for FortiSASE admins to use their existing remote IdP user source with FIC acting as a pure proxy.