Configuring FortiAuthenticator Cloud - I
To enable SAML IdP service on interface:
- In FortiAuthenticator Cloud, go to System > Administration > Access Rights.
- In Services, ensure HTTPS (TCP/443) is already enabled and enable SAML IdP (/saml-idp).
- Select Save to apply the edits to the network interface.
To create a remote OAuth server:
- In FortiAuthenticator Cloud, Go to Authentication > Remote Auth. Servers > OAUTH and select Create New.
- Enter a name for the remote OAuth server.
- In the OAuth source dropdown list, select Azure Directory.
- In the Client ID field, enter the Entra enterprise application ID that you saved previously.
- In the Client Key field, enter the Client secrets Value created previously.
- Select OK to add the remote OAuth server.
To partially configure the remote SAML server on FortiAuthenticator Cloud:
- In FortiAuthenticator Cloud, go to Authentication > Remote Auth. Servers > SAML, and click Create New. In the Create New Remote SAML Server page, configure the following:
- Select Proxy as the Type.
- For the Entity ID, click the dropdown menu and select the Azure identity provider (IdP) option.
- Under Single Logout, ensure Enable SAML single logout is checked.
-
Copy these SAML fields:
Portal URL
Entity ID
ACS (login) URL
SLS (logout) URL
-
Keep this page open in your web browser since you will continue configuring it after configuring Entra ID.