Fortinet white logo
Fortinet white logo

Admin Guide

26.2.0

License consumption for passthrough users

License consumption for passthrough users

In FIC, passthrough users are users who authenticate against an external identity source, and FIC passes or brokers that identity through without enforcing its own MFA challenge for those users. Any MFA challenge that they receive would come from the upstream source, if required.

The Passthrough option in SSO application configuration (Applications > SSO > Add SSO Application > Authentication) enables administrators to use FIC in pure proxy mode without the need to administer or synchronize passthrough users in FIC.

For example, you want to create an SSO application for users from both Google and your LDAP user source in FIC to log into. If you enable the Passthrough option in the SSO application configuration, you only need to manage the users from the LDAP user source (because the Passthrough option is not applicable to LDAP and local IdP user source), while the users from Google will be managed in Google. Conversely, if Passthrough is not enabled, you will have to configure the Google users in FIC first for them to be able to log in and authenticate successfully.

Passthrough users consume user licenses in the same way as regular FIC-managed users do. For instance, if you have a new 50-user license, having five passthrough users reduces the available user quota to 45. If all the user quota in the license had been used up before a passthrough user is created, the user will not be authorized to log in until a new license or user quota becomes available.

FIC automatically manages passthrough user accounts through periodic cleanup to maintain system efficiency and security. By default, passthrough users that have been inactive for 30 consecutive days are automatically removed from the system.

The User Management > Users page has a Passthrough Users tab that shows a list of passthrough users.

You can also monitor IdP sessions of passthrough users in the Monitor > IdP Sessions page. They are listed in the session Details dialog as User Type: Remote (Passthrough).

Note

Terminating an IdP session of a passthrough user will not remove the user from the system.

License consumption for passthrough users

License consumption for passthrough users

In FIC, passthrough users are users who authenticate against an external identity source, and FIC passes or brokers that identity through without enforcing its own MFA challenge for those users. Any MFA challenge that they receive would come from the upstream source, if required.

The Passthrough option in SSO application configuration (Applications > SSO > Add SSO Application > Authentication) enables administrators to use FIC in pure proxy mode without the need to administer or synchronize passthrough users in FIC.

For example, you want to create an SSO application for users from both Google and your LDAP user source in FIC to log into. If you enable the Passthrough option in the SSO application configuration, you only need to manage the users from the LDAP user source (because the Passthrough option is not applicable to LDAP and local IdP user source), while the users from Google will be managed in Google. Conversely, if Passthrough is not enabled, you will have to configure the Google users in FIC first for them to be able to log in and authenticate successfully.

Passthrough users consume user licenses in the same way as regular FIC-managed users do. For instance, if you have a new 50-user license, having five passthrough users reduces the available user quota to 45. If all the user quota in the license had been used up before a passthrough user is created, the user will not be authorized to log in until a new license or user quota becomes available.

FIC automatically manages passthrough user accounts through periodic cleanup to maintain system efficiency and security. By default, passthrough users that have been inactive for 30 consecutive days are automatically removed from the system.

The User Management > Users page has a Passthrough Users tab that shows a list of passthrough users.

You can also monitor IdP sessions of passthrough users in the Monitor > IdP Sessions page. They are listed in the session Details dialog as User Type: Remote (Passthrough).

Note

Terminating an IdP session of a passthrough user will not remove the user from the system.