Fortinet black logo

Cookbook

Configuring SSO on FortiMail

Configuring SSO on FortiMail

In this section, you will enable SSO within FortiMail, then paste the federation metadata URL from the SAML signing certificate generated within Azure. FortiMail then retrieves the necessary information from the identity provider (IDP) metadata. This establishes a connection between Azure and FortiMail, and generates an SSO certificate the FortiMail uses to authenticate SSO users.

  1. In FortiMail, go to System > Customization > Single Sign On and enable SSO, ensuring that it applies to both Webmail and Admin.

  2. From the Azure portal, under SAML Signing Certificate, copy the App Federation Metadata URL and paste it into the URL field under Identity Provider (IDP) Metadata in FortiMail.
  3. Once pasted into the URL field, select Retrieve from URL. This will populate the IDP metadata Certificate field.

  4. Select Apply to enable and finish configuring SSO authentication on the FortiMail unit.

Users logging into FortiMail can now select Single Sign On and will be redirected to Azure for authentication.

Configuring SSO on FortiMail

In this section, you will enable SSO within FortiMail, then paste the federation metadata URL from the SAML signing certificate generated within Azure. FortiMail then retrieves the necessary information from the identity provider (IDP) metadata. This establishes a connection between Azure and FortiMail, and generates an SSO certificate the FortiMail uses to authenticate SSO users.

  1. In FortiMail, go to System > Customization > Single Sign On and enable SSO, ensuring that it applies to both Webmail and Admin.

  2. From the Azure portal, under SAML Signing Certificate, copy the App Federation Metadata URL and paste it into the URL field under Identity Provider (IDP) Metadata in FortiMail.
  3. Once pasted into the URL field, select Retrieve from URL. This will populate the IDP metadata Certificate field.

  4. Select Apply to enable and finish configuring SSO authentication on the FortiMail unit.

Users logging into FortiMail can now select Single Sign On and will be redirected to Azure for authentication.