Fortinet black logo

Administration Guide

Configuring Entra ID

Configuring Entra ID

Create a new Entra enterprise application using the FortiSASE application as a template from the Entra app gallery, configure your Microsoft Entra ID (formerly known as Azure Active Directory or Azure AD) environment with users and groups and configure the enterprise application for SAML single sign-on (SSO) for the agent-based or endpoint mode deployment.

To create an enterprise application using FortiSASE as a template from the gallery and find the application ID of the FortiSASE enterprise application:
  1. Log into the Azure portal.
  2. Go to Microsoft Entra ID > Enterprise applications > New application.
  3. Search for and select FortiSASE.
  4. Click Create.
  5. In Overview > Properties, copy the application ID. You need this information in a later step.
  6. Assign Entra ID users and groups to FortiSASE.
To register the enterprise application:
  1. Log into the Azure portal.
  2. Go to the directory home, and select App registrations.
  3. In the App registrations window, select All applications, and search your application by name.
  4. In the list, select your application.
  5. Go to Manage > Certificates & secrets, and select + New client secret.
  6. In the Add a client secret window, do the following:
    1. In the Description field, enter a description for the client secret.
    2. From the Expires dropdown list, select a time period after which the client secret expires.
    3. Select Add.
Caution

In Client secrets, make note of the Value.

Since this key is visible only once (immediately after creation), you must recreate the key if you do not copy and store it.

Setting up an OAuth server requires the key.

To add the enterprise application as an assignment:
  1. Go to the Microsoft Entra ID directory home, and select Roles and administrators.
  2. From the Administrative roles list, select Directory readers.
  3. Select the ellipsis for Directory readers, then select Description.
  4. Go to Assignments and select Add assignment.
  5. In the Add assignments window, search your application by name, and select Add.

Configuring Entra ID

Create a new Entra enterprise application using the FortiSASE application as a template from the Entra app gallery, configure your Microsoft Entra ID (formerly known as Azure Active Directory or Azure AD) environment with users and groups and configure the enterprise application for SAML single sign-on (SSO) for the agent-based or endpoint mode deployment.

To create an enterprise application using FortiSASE as a template from the gallery and find the application ID of the FortiSASE enterprise application:
  1. Log into the Azure portal.
  2. Go to Microsoft Entra ID > Enterprise applications > New application.
  3. Search for and select FortiSASE.
  4. Click Create.
  5. In Overview > Properties, copy the application ID. You need this information in a later step.
  6. Assign Entra ID users and groups to FortiSASE.
To register the enterprise application:
  1. Log into the Azure portal.
  2. Go to the directory home, and select App registrations.
  3. In the App registrations window, select All applications, and search your application by name.
  4. In the list, select your application.
  5. Go to Manage > Certificates & secrets, and select + New client secret.
  6. In the Add a client secret window, do the following:
    1. In the Description field, enter a description for the client secret.
    2. From the Expires dropdown list, select a time period after which the client secret expires.
    3. Select Add.
Caution

In Client secrets, make note of the Value.

Since this key is visible only once (immediately after creation), you must recreate the key if you do not copy and store it.

Setting up an OAuth server requires the key.

To add the enterprise application as an assignment:
  1. Go to the Microsoft Entra ID directory home, and select Roles and administrators.
  2. From the Administrative roles list, select Directory readers.
  3. Select the ellipsis for Directory readers, then select Description.
  4. Go to Assignments and select Add assignment.
  5. In the Add assignments window, search your application by name, and select Add.