Authentication
To configure authentication settings:
-
Go to System > Settings > Authentication.
-
Configure the settings as follows:
Field
Required
Description
Authentication Access
N
Set to Local or Remote. After changing this setting, you must log in again.
The following remote authentication options are available:
-
FortiAuthenticator: See Remote authentication: FortiAuthenticator.
-
RADIUS: See Remote authentication: RADIUS.
-
SSO: See Remote authentication: SSO.
-
OAuth2: See Remote authentication: OAuth2.
By default, Authentication Access is set as Local.
If FortiPortal is operating as a scalable cluster, the system will restart when you change the authentication configuration from local to remote or from remote to local.
N
Enable or disable two-factor authentication (2FA) for local or remote users.
FortiPortal only supports using the FortiToken Mobile application as the 2FA method. SMS and email are not supported.
2FA authentication depends on proper configuration of an SMTP server. See Email.
For 2FA, a FortiToken license needs to be applied and registered in the same account where the FortiPortal license is registered.
Email information is mandatory for 2FA users.
If the user name is the email and no Tenant Identification Attribute is set, the domain part of the email can be used for tenant identification.
-
-
Click Save.