FortiAuthenticator
FortiAuthenticator provides access management and single sign on.
dbu
Staff
Staff
Article Id 278448
Description This article describes how to install and configure SSO MA with FortiAuthenticator as a collector agent.
Scope SSO MA, FortiAuthenticator, Domain joined Microsoft Windows.
Solution

Complete these steps to install from the GUI and command prompt (CMD).

 

  1. Download the SSO MA configuration tool 'FortiClientSSOConfigurator'.
  2. Initiate the installation
  3. Configure:
  • Collector agent IP (FortiAuthenticator CA).
  • Listening port on FortiAuthenticator.
  • Secret (must be the same on both sides).

 

sni1.PNG

 

  1. Select 'Skip' on the Package Signing window.

 

sni2.PNG

 

  1. Installation files created.


sni3.PNG

 

  1. Select 'Finish' and the installation folder with the setup files will be opened.
    There will be two files created (msi+mst) :

FortiClientSSO.msi

FortiClientSSO.mst

 

  1. Install the SSO MA client from the GUI.
    Open 'FortiClientSSO.msi' and continue with the installation.

sni6.PNG

 

  1. Install the SSO MA client silently from the command line.
    Open the command prompt and navigate to the installation folder. In this example, it is as follows: 

 

sni5.PNG

 

cd C:\Users\Administrator\Desktop\FortiClientSSOConfigurationTool_7.2.0.0690\repackaged\7.2.0.0690-SSO_20231010052350\x64\ActiveDirectory


Inside the folder, run the following command: 

 

msiexec.exe /qb /i forticlientsso.msi TRANSFORMS=FortiClientSSO.mst

 

Note: the .mst file name is case-sensitive.

 

sni7.PNG

 

FortiAuthenticator configuration.

 

tempsnip1.png

 

Verify the resulting SSO Sessions:

 

snip8.PNG