Skip to content
Project 02Cloud-delivered secure access using Microsoft Entra ID

Cloud-delivered secure access deployed with authentication handed to Microsoft Entra ID over SAML, so remote access follows the same identity as everything else.

SSOIdentity
01

Overview

Cloud-delivered secure access deployed with authentication handed to Microsoft Entra ID over SAML, so remote access follows the same identity as everything else.

02

Technical challenge

Secure access needed to work for users who were not behind the perimeter, without creating a second identity store to maintain alongside Active Directory and Entra ID.

03

Architecture

  • 01FortiSASE as the cloud-delivered secure access layer for distributed users.
  • 02SAML single sign-on federating authentication to Microsoft Entra ID as the identity provider.
  • 03Group-based access mapped from directory groups rather than locally defined users.
  • 04Policy applied centrally so remote and on-site access follow a consistent posture.
04

Implementation

  • Configured the FortiSASE tenant and secure access policy set.
  • Established the SAML trust between FortiSASE and Microsoft Entra ID.
  • Mapped directory groups to access policy for group-based authorization.
  • Validated the end-to-end authentication flow for remote users.
05

Outcome

Remote secure access authenticates against the organisation’s existing cloud identity, removing a separately managed credential store.

06Related work