Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

FortiPAM Integration with FortiAuthenticator & FortiIdentity

Fortinet
03/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this video, we'll walk through a quick demo showcasing a solution we built from Fortinet within our Identity and Access Management portfolio. In this video, you'll notice that our FortiPAM solution serves various categories of users, either a contractor or an employee. As contractors log in, they are presented with simplified dashboards from a FortiPAM solution designed for quick access on various targets that contractors can access and also can be pre-selected during configuration, while other users, like our employees, can receive a more robust dashboard with added capabilities and users. On the screen, we have an integration between FortiPAM, our very own privileged access management solution from Fortinet, a Forti Authenticator working seamlessly with various third-party identity providers such as your EntraID, Okta, or a local authentication or Active Directory authentication. We also have a seamless integration with FortiIdentity Cloud, which provides the MFA solution. With the MFA solution, we can add an extra layer of security such that when a user logs into an application, a system, a service, he or she is fully protected reducing the success of phishing attacks as well as lowering the risk of compromised credentials. This is a key Fortinet solution to pay attention to because it applies to any vertical, whether you're an MSSP or an enterprise of any size, small, medium, or large. With the rising trend of company acquisition and mergers, the complexity of merging multiple identity providers, unifying authentication environments can quickly become a daunting challenge. With FortiPAM, Forti Authenticator Cloud, and FortiIdentity Cloud, our identity and access management strategy becomes exceptionally strong and unified. So let's get started with the demo. In this demo, we have a FortiPAM solution along with FortiIdentity Cloud and FortiAuthenticator Cloud to secure both internal and remote access. Internal users connect directly to FortiPAM, while remote endpoint users leverage CTNA logging for secure access control. When a user logs into FortiPAM, the system authenticates the identity through FortiAuthenticator Cloud using either RADIUS or SAML, validating the credentials against the remote user database. Once authenticated, FortiIdentity Cloud provides multi-factor authentication through options such as mobile push notification or email verification. All right, let's provision. On the secrets folder, let's do a quick check on the settings and sharing and enable CTNA controls. Select the device tag, and in this demo, we disable all any tags. Now that it's all set and ready to go, let's log into the FortiIdentity Cloud portal and configure remote users. In this case, we're using carl.okta.com, and let's check the remote SAML user configuration and the delivery options. We have delivery options as token code, buy FortiToken via mobile, and an email as an activation delivery method. Now let's check on JDO as well, and we are set to go. All right, let's get started with a PuTTY with SSH session, which is successful, and then let's follow up with the WinSCP launcher, WebSSH, and WebSFTP. As you can see, I was able to access them according based on my pre-configured configuration. Let's log out, and this time, let's use carl using single sign-on login. With carl, we're using Okta, and as we log in, the authentication is sent to the Okta from our FortiAuthenticator integration. With carl's account, we have a remote desktop and a web RDP launchers established as customer to Windows Server, as indicated in the earlier part of the video. Now, let's log in directly through FortiPAM and access other resources. This would be your typical FortiPAM access with predefined launchers with credentials. Now, let's check on our user list that has been initiated in the previous demo. We have a feature called auto-provision, which automatically creates privileges and access to a secret. We have carl and jdoe that are configured, and so from our recent secret event access and FortiPAM logs, not just the access that are recorded, but also it records the actual session that occurred. It records the actual session and what commands and what are the actual users did within a target. So here's an uploaded video which provides the date, the source IP, the destination IP, the secret server name, the user, and what type of launcher they used. For added FortiPAM reporting capabilities, you can download a general report on a daily basis report which provides the user login reports, the system report, secret launcher report, and more. If you want additional information about secret access report, this can be downloaded and viewable from the reports tab from the management portal. I hope you found this video helpful as we demonstrated how to integrate a complete IAM solution using FortiPAM for privilege access management, for the Authenticator Cloud for primary authentication and identity verification, and for the Identity Cloud for MFA enforcement. Thank you for watching.

TL;DR

  • FortiPAM integrates with FortiAuthenticator Cloud and FortiIdentity Cloud to provide unified privileged access management with MFA enforcement across internal and remote users
  • The solution supports authentication through multiple identity providers (Entra ID, Okta, Active Directory) via RADIUS or SAML, addressing the complexity of mergers and multi-IdP environments
  • Role-based dashboards differentiate contractor and employee access, with comprehensive session recording capturing actual commands executed on target systems
  • Auto-provisioning automatically creates privileges and access to secrets for authenticated users, with detailed reporting on user logins, secret access, and launcher usage

Unified Identity and Access Management Architecture

This technical demonstration showcases Fortinet's integrated IAM solution combining FortiPAM (Privileged Access Management), FortiAuthenticator Cloud, and FortiIdentity Cloud. The architecture supports both internal and remote users, with FortiAuthenticator providing primary authentication through RADIUS or SAML integration with third-party identity providers including Entra ID, Okta, Active Directory, and local authentication. FortiIdentity Cloud adds multi-factor authentication through mobile push notifications or email verification. The solution addresses the complexity of merging multiple identity providers during company acquisitions and mergers, offering a unified authentication environment applicable to MSSPs and enterprises of any size.

Role-Based Access and Session Management

FortiPAM delivers differentiated user experiences based on role classification. Contractors receive simplified dashboards with pre-configured access to specific targets, while employees access more robust dashboards with expanded capabilities. The platform supports multiple access methods including SSH via PuTTY, WinSCP, WebSSH, WebSFTP, Remote Desktop, and Web RDP launchers. A key security feature is comprehensive session recording that captures not only access events but the actual commands executed within target systems. The auto-provisioning capability automatically creates privileges and access to secrets for authenticated users, streamlining administrative overhead while maintaining security controls.

Chapters

0:00 - Introduction and Solution Overview
0:52 - Architecture Components and Integration
2:26 - Demo Setup and Configuration
3:15 - Secret Provisioning and ZTNA Controls
5:13 - FortiIdentity Cloud User Configuration
5:41 - Access Methods Demonstration
6:24 - Single Sign-On with Okta Integration
8:10 - Session Recording and Audit Capabilities
9:29 - Summary and Conclusion

Key Quotes

1:21 "With the MFA solution, we can add an extra layer of security such that when a user logs into an application, a system, a service, he or she is fully protected reducing the success of phishing attacks as well as lowering the risk of compromised credentials."
1:41 "This is a key Fortinet solution to pay attention to because it applies to any vertical, whether you're an MSSP or an enterprise of any size, small, medium, or large."
1:55 "With the rising trend of company acquisition and mergers, the complexity of merging multiple identity providers, unifying authentication environments can quickly become a daunting challenge."
8:41 "It records the actual session and what commands and what are the actual users did within a target."

Categories:
  • » Webinar Library » Fortinet
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Zero Trust
  • Demo
  • Technical Deep Dive
  • Compliance & Governance
  • Privileged Access Management
  • Identity and Access Management
  • Multi-Factor Authentication
  • SAML Integration
  • RADIUS Authentication
  • Session Recording
  • Zero Trust Network Access
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: FortiPAM Integration with FortiAuthenticator & FortiIdentity

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version