Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SethE
New Contributor

No MFA prompt for new users

Hi all, my first post here. Perhaps someone can help.

 

Our firewall is configured to connect to an on-prem Radius server (NPS). Hybrid connectivity is setup so users are also in Microsoft Entra with MFA setup.

 

Firewall is configured to point to Radius and only allow vpn connections if users are part of a group. 

 

For some reason, any new users that we setup do NOT get the MFA prompt in Forticlient (using either EMS client or standard) , However, old users' , setup over 6 months ago, work just fine!

 

I did find this article and will try to determine if it's applicable:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Failed-authentication-when-connectin...

 

However, what baffles me is that old users are OK, but, new users are not.  We've tried from the same workstation.  The MFA prompt (that extra field in forticlient that asks for the token does not show) and it errors out at 45%.

 

Has anybody encountered this before?

 

1 REPLY 1
ebilcari
Staff
Staff

Based on your description I think that the changes need to be done in the RADIUS server. The token is asked as an addition RADIUS challenge to FGT that triggers the new prompt in FCT. It looks like this is not being asked by the NPS for the new users. You can also check the debugs in FGT, refer to this article for SSL VPN troubleshooting tips.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors