Question 1
A financial services company is deploying FortiAuthenticator as a SAML IdP to provide SSO access to several third-party SaaS applications. The security policy requires that user access roles within the SaaS applications be determined by their Active Directory group membership. During testing, all users are being granted a default, low-privilege role regardless of their AD group. What is the most likely cause of this issue?
Answer and explanation
Correct answer: B
The most probable cause is that the SAML assertion is not sending the required group membership information to the Service Provider (SaaS application). FortiAuthenticator, acting as the IdP, must be configured to query the user's groups from the remote LDAP/AD server and then map that information into a specific SAML attribute (like 'memberOf' or 'role') that the SP expects to receive to assign the correct privileges.