Searching user groups from SAML IdP
From FortiSASE, it is possible to search the user groups on the remote SAML provider configured for VPN and secure web gateway (SWG) SSO by configuring SAML provider credentials in the Search User Groups from SAML Provider slide-in window. You can then configure the user groups for SAML group matching. Dynamically discovering a user group from the SAML identity provider (IdP) is more convenient than manually finding a user group’s identifier (ID) from the remote SAML provider’s portal and configuring it for SAML group matching.
Before you can configure the SAML provider credentials, you must perform some setup and obtain these credentials from the SAML IdP.
Currently, searching user groups from a SAML provider from FortiSASE is supported with Entra ID SSO in FortiClient agent-based mode via Configuration > VPN User SSO, or in SWG agentless mode via Configuration > SWG User SSO. See Configuring API permissions and determining Entra ID SSO credentials and Searching user groups from Entra ID SSO. |