Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jharvre
New Contributor

Pre-Sales Info on FortiCloud Multi-Tenancy

Hi!  We are looking at trying to accomplish some things.  We are a managed service provider (MSP) who need some solutions for 2FA for ourselves and our customers.

 

So far, we have successfully created FortiCloud accounts for each of our staff members who manage our Fortigates ( we have roughly 55 of them deployed for various customers).  Each of these has 2FA enabled, and each of them can use the FortiCloud console and Remote Access into the firewalls.  

 

However, with some of the newer OS versions, it supports FortiCloud SSO as a login option.  This is super cool, but there is just one problem -- it only seems to support sign-in using the primary account that was used to register the account.  So, for example, we have Doug, Josh, and Joel (me).  Each of us has a Forticloud account, all linked together so we have access.  The Fortigates were all registered using Doug's account.  I can login to FortiCloud and manage the Fortigates, but when it comes time to log in, using FortiCloud SSO, I have to use Doug's credentials.  And since we're using 2FA, I have to contact Doug.  Or login with a local account.  

We want to transition to a situation where any of our accounts can be used on any of the Fortigates, use those as our primary login, and transition the local accounts on the Fortigates to be a 'break glass' account that is basically used only in an emergency (20 characters long generated by random.org, used no where else, etc).  This way, we have 2FA on all the admin access into the devices, which should nicely harden the security.

My question is:

1. We get the message "This FortiCloud account ("xxx@xxx.com") is not authorized to sign in on this FortiGate."  Is there any way to authorize it that we've missed?

2. Is this something that we need FortiCloud multi-tenancy for?  

3. Can Forticloud SSO help provide things like VPN access into the devices with 2FA?  Or do we need FortiToken or FortiToken Cloud licenses for that?

 

Thanks in advance for your help!  The documentation I've been able to find on Forticloud Multi-Tenancy has been pretty vague and doesn't go into specifics, and before we start spending $1000 a year on it, I want to make sure it does what we need.  

 

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello jhavre,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
kgeorge
Staff
Staff

Hello @jharvre,

 

You can make use of IAM account to login via FortiCloud SSO. Refer this documentation on creating IAM Accounts and granting access to those accounts on the required parameters,

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Login-to-FortiGate-GUI-using-FortiCloud-SS...

 

Just ensure that, the user is provided with required asset list access so that they can login to those devices' GUI without issues.

 

The 2FA for these IAM accounts can be enabled under Account Settings of the Master IAM User. In your case, it is "Doug's" account.

 

And, please find my answers inline for your questions,

 

1. We get the message "This FortiCloud account ("xxx@xxx.com") is not authorized to sign in on this FortiGate."  Is there any way to authorize it that we've missed?

 

Answer: The steps I mentioned should help on this.

 

2. Is this something that we need FortiCloud multi-tenancy for?  

 

Answer: Multi-Tenancy is not necessary for this as it is used only for managing devices by different account withing FortiGate Cloud portal.

 

3. Can Forticloud SSO help provide things like VPN access into the devices with 2FA?  Or do we need FortiToken or FortiToken Cloud licenses for that?

 

Answer: For VPN access, FortiToken Mobile/Hardtoken or FortiToken Cloud licenses are required. Or, you may also consider Email Token for the VPN user to activate 2FA for them.

This IAM account or FortiCloud SSO accounts cannot be integrated to VPN access or any other access as they are exclusively for Administrator login related.

 

Hope the above helps.

 

 

Regards,
Klint George
Labels
Top Kudoed Authors