FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
Anil_Solakoglu
Article Id 274582
Description This article describes how to create a configuration for SAML verification on EMS and Google Workspace. 
Scope EMS, FortiClient, Google Workspace
Solution
  1. In order to create a custom SAML application log in to Google Workspace with the appropriate administration account on the left pane and select Application -> Web Applications and mobile applications.

 

Anil_Solakoglu_0-1695162906494.png

 

  1. A name should be assigned for the Google Custom SAML application:

 

Anil_Solakoglu_1-1695162906496.png

 

  1. This is where we get IDP configuration details for EMS configuration:

EMS side -> Google side

SSO URL (Google) = IdP single sign-on URL (EMS)

Asset ID (Google) = IdP Entity ID (EMS)

Certificate  (Google) = Identity Provider settings certificate -> Should be downloaded and attached to EMS SAML configuration.

 

Anil_Solakoglu_2-1695162906501.png

 

  1. Attach the required fields on the previous step to EMS SAML configuration.

Go to EMS -> User Management -> SAML Configuration.:

  • SP Address on the configuration should be publicly accessible FQDN for EMS.

 

Anil_Solakoglu_3-1695162906505.png
  1. In Google custom SAML application as 3. Step.

ACS URL (Google) = SP ACS (login) URL (EMS)

Asset ID (Google) = SP ENTITY ID(EMS)

 

Anil_Solakoglu_4-1695162906508.png

 

  1. On Google Workspace remaining configuration on the custom SAML APP is optional.

Once the application is created, it is necessary to allow users who use custom applications.

 

Note:

Application rights can be narrowed via groups.

 

Anil_Solakoglu_5-1695162906512.png

 

Anil_Solakoglu_6-1695162906514.png
  1. An EMS invitation code should be created for user verification on FortiClients:

 

Anil_Solakoglu_7-1695162906516.png

 

  1. Once the created invitation code is applied on Forticlient it will prompt for the Google authentication page:

 

Anil_Solakoglu_8-1695162906518.png

 

  1. It is necessary to type a valid e-mail address that exists on Google Workspace.

 

Anil_Solakoglu_9-1695162906518.png

 

  1. After successful login, there will be a prompt to select the open link.

 

Anil_Solakoglu_10-1695162906519.png

 

  1. After a successful connection was made to EMS.

End user verification details should be shown with a valid Google Workspace e-mail as follows under EMS-> User Management -> Verified Users.

 

Anil_Solakoglu_11-1695162906520.png

 

  1. Go under EMS -> Endpoints -> All endpoints.

 

Anil_Solakoglu_12-1695162906523.png