Fortinet white logo
Fortinet white logo

Administration Guide

Mapping IDP server roles user to FortiPortal profiles

Mapping IDP server roles user to FortiPortal profiles

The site administrator can create profiles on FortiPortal to restrict access to UI pages or actions. These profiles can be mapped to existing roles on the IPD server.

When users are authenticated, the user role noted in the SAML assertion from the IDP server is mapped to a profile in FortiPortaland the appropriate permissions are provided to the user.

Site administrators do not need to change or add permissions on the IDP server exclusively for FortiPortal.

FortiPortal profiles can be mapped to IDP server roles prior to setting up an SSO provider. The IDP role name will be matched to any IDP servers that are added.

To map IDP roles to FortiPortal profiles:
  1. Go to System > Settings > Authentication.
  2. In Authentication Access, select Remote.
  3. In the Remote Server dropdown, select SSO.
  4. Select View SSO Roles.
    The SSO Roles window opens.
  5. Select Create.
  6. In the Create Role window, enter the Role Name (this name must be an SSO role). Select the Role Type.
  7. Select a FortiPortal profile to associate with this SSO role. See Profiles for more information about creating profiles.
  8. Click Save.

Mapping IDP server roles user to FortiPortal profiles

Mapping IDP server roles user to FortiPortal profiles

The site administrator can create profiles on FortiPortal to restrict access to UI pages or actions. These profiles can be mapped to existing roles on the IPD server.

When users are authenticated, the user role noted in the SAML assertion from the IDP server is mapped to a profile in FortiPortaland the appropriate permissions are provided to the user.

Site administrators do not need to change or add permissions on the IDP server exclusively for FortiPortal.

FortiPortal profiles can be mapped to IDP server roles prior to setting up an SSO provider. The IDP role name will be matched to any IDP servers that are added.

To map IDP roles to FortiPortal profiles:
  1. Go to System > Settings > Authentication.
  2. In Authentication Access, select Remote.
  3. In the Remote Server dropdown, select SSO.
  4. Select View SSO Roles.
    The SSO Roles window opens.
  5. Select Create.
  6. In the Create Role window, enter the Role Name (this name must be an SSO role). Select the Role Type.
  7. Select a FortiPortal profile to associate with this SSO role. See Profiles for more information about creating profiles.
  8. Click Save.