A company wants to use FortiGate as a SAML service provider (SP) for authenticating administrators to the FortiGate GUI. The identity provider (IdP) is Azure AD. After configuration, administrators are redirected to Azure AD login but receive an error that the SAML request is invalid. What is the most likely misconfiguration?
If the IdP entity ID or SSO URL is wrong, the SAML request will be considered invalid by the IdP.
Why this answer
As an SP, FortiGate must be configured with the correct IdP entity ID and SSO URL. If the IdP entity ID is incorrect, the IdP rejects the SAML request.