FortiEMS + SSLVPN + MACOS
Bussines need: separation of users into groups based on AD membership so all fortigate firewalls can create polices based on that groups of SSLVPN connected users. Not only on VPN gateways but also other FWs that are not aware of vpn session establshed.
Original solution: use ZTNA tags and sync forigates to fortiems. Works fine on windows,
Problem: we have MACos that are not AD joined so cannot utilize ZTNA tags based on group membership (local user on mac).
Main idea was to user ztna tags to keep policy "source IP agnostic" and no matter what source endpoint users uses. FortiEMS is using local account on system rather than the one SAML2 used for authentication in RA SSO.
How would you solve this?