Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
David_1
New Contributor

[FortiAuthenticator + Microsoft Token]

Hello,

 

Currently, users are using FortiAuthenticator with FortiToken Mobile on their phones to access the VPN. Is there any option for integrating the VPN access token into Microsoft Authenticator, which is used for accessing Office 365?

The idea is to have both tokens within a single application: FortiToken Mobile --> (Integration with?) Microsoft Authenticator.

 

Thank you for your assistance.

FortiAuthenticator  @David_1 

David
David
4 REPLIES 4
ozkanaltas
Contributor III

Hello @David_1 ,

 

In my opinion, you can use Microsoft MFA with FortiAuthenticator. I used Microsoft MFA and Fortigate SSL VPN without a problem. 

 

Fortiauthenticator has the ability for radius proxy. For this reason, I think it will serve as a bridge between Fortigate and Microsoft MFA without any problems. 

https://docs.fortinet.com/document/fortiauthenticator/6.6.0/administration-guide/647/radius

 

This link tells how can we integrate Azure MFA and Fortigate. I think a good guide for this. You should change one thing in the guide. Your connection matrix must be like this.

 

Fortigate --> FortiAuthenticator -> Microsoft NPS

 

https://www.ultraviolet.network/post/fortigate-ssl-vpn-with-azure-ad-mfa

 

If you don't want to use FortiAuthenticator as a radius proxy. You can integrate Fortigate and Microsoft MFA same way. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
David_1

Hello @ozkanaltas,

 

Thanks for your answer.

 

Do you know if it is possible to have the FortiTokenMobile code in the Microsoft Authenticator application?

 

Best regards.

David.

 

 

David
David
ozkanaltas

Hello @David_1 ,

 

I think this is impossible. Because these are different platforms.

 

But I found an article below the link. This article describes how we can use FortiToken mobile instead of Google Authenticator for Google services. Maybe it can work with a Microsoft Authenticator too.

 

https://docs.fortinet.com/document/fortitoken/latest/comprehensive-guide/99086/example-third-party-t...

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
AEK
SuperUser
SuperUser

Hello David

I already sow a FortiGate VPN working with RSA token via RADIUS server, so a fortiori I guess FortiAuthenticator would be more able to do so with MS token.

AEK
AEK
Labels
Top Kudoed Authors