Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Knuppel
New Contributor

SSL VPN with Azure SAML and SCEPman

So i've setup SSL VPN with Azure SAML MFA, which is working nicely.

Now i want to add another layer of protection, to make sure users only connect from company owned devices. For this i've setup SCEPman, which is deploying device certificates through Intune.

 

Coming back to the Fortigate, i have no clue what to do next. I've imported the CA certificate, which is displayed as Remote CA. How do i configure the Fortigate to check for the device certificate? And as step 2 check the validity through OCSP?

1 REPLY 1
Helpdesk275
New Contributor

I'm guessing you never got a response to this? We're trying to do the same thing, no org issued device certificate, no authentication. Valid device certificate allows the user to continue to username / password / MFA

Labels
Top Kudoed Authors