Configure SAML settings on FortiAuthenticator
Configure SAML settings on FortiAuthenticator
To configure FortiAuthenticator IdP settings:
- Go to Authentication > SAML IdP > General and click Enable SAML Identity Provider portal.
- Configure the following settings:
- Server address: The IP address or FQDN of the FortiAuthenticator.
- Realms: Select the previously created SAML realm.
- Default IdP certificate: Choose a certificate. The default can be used if desired.
The remaining settings can be left in their default state.
- Click OK to save your changes.
To configure the O365 service provider settings on FortiAuthenticator:
- Go to Authentication > SAML IdP > Service Providers and click Create New.
- Configure the following settings:
- SP name: enter a name for your O365 service provider.
- IdP Prefix: Click Generate prefix to create a new IdP prefix.
- Server certificate: Select the certificate to be used in your configuration or choose Use default setting in SAML IdP General page.
- IdP signing algorithm: Select Use default signing algorithm in SAML IdP General page.
- Participate in single logout: Can be enabled if you wish this SP to participate in SAML single logout.
- In the Assertion Attribute Configuration section, configure the following settings:
- Subject NameID: Select Subject NameID.
- Format: Select urn:oasis:names:tc:SAML:2.0:nameid-format:persistent.
- Click Save and the SP Metadata and Assertion Attribute fields are displayed. Configure the following settings for the SP Metadata.
- SP entity ID: Enter
urn:federation:MicrosoftOnline
. - SP ACS (login) URL: Enter
https://login.microsoftonline.com/login.srf
. - SP SLS (logout) URL: Enter
https://login.microsoftonline.com/login.srf
.
- In Assertion Attributes click Create New and configure the following assertion attribute:
- SAML attribute: IDPEmail
- User attribute: SAML assertion
- Custom field: IDPEmail
- Save your changes to the SAML SP.
Configure SAML settings on FortiAuthenticator
Configure SAML settings on FortiAuthenticator
To configure FortiAuthenticator IdP settings:
- Go to Authentication > SAML IdP > General and click Enable SAML Identity Provider portal.
- Configure the following settings:
- Server address: The IP address or FQDN of the FortiAuthenticator.
- Realms: Select the previously created SAML realm.
- Default IdP certificate: Choose a certificate. The default can be used if desired.
The remaining settings can be left in their default state.
- Click OK to save your changes.
To configure the O365 service provider settings on FortiAuthenticator:
- Go to Authentication > SAML IdP > Service Providers and click Create New.
- Configure the following settings:
- SP name: enter a name for your O365 service provider.
- IdP Prefix: Click Generate prefix to create a new IdP prefix.
- Server certificate: Select the certificate to be used in your configuration or choose Use default setting in SAML IdP General page.
- IdP signing algorithm: Select Use default signing algorithm in SAML IdP General page.
- Participate in single logout: Can be enabled if you wish this SP to participate in SAML single logout.
- In the Assertion Attribute Configuration section, configure the following settings:
- Subject NameID: Select Subject NameID.
- Format: Select urn:oasis:names:tc:SAML:2.0:nameid-format:persistent.
- Click Save and the SP Metadata and Assertion Attribute fields are displayed. Configure the following settings for the SP Metadata.
- SP entity ID: Enter
urn:federation:MicrosoftOnline
. - SP ACS (login) URL: Enter
https://login.microsoftonline.com/login.srf
. - SP SLS (logout) URL: Enter
https://login.microsoftonline.com/login.srf
.
- In Assertion Attributes click Create New and configure the following assertion attribute:
- SAML attribute: IDPEmail
- User attribute: SAML assertion
- Custom field: IDPEmail
- Save your changes to the SAML SP.