Chapter 3 Authentication for FortiOS 5.0 : SSO using a FortiAuthenticator unit : Administrator’s view of FortiAuthenticator SSO authentication
  
Administrator’s view of FortiAuthenticator SSO authentication
You can configure either or both of these authentication types on your network.
SSO widget
You need to configure the Single Sign-On portal on the FortiAuthenticator unit. Go to SSO & Dynamic Polices > SSO > Login Portal to do this. Copy the Embeddable login widget code for use on your organization’s home page. Identity-based security policies on the FortiGate unit determine which users or groups of users can access which network resources.
FortiClient SSO Mobility Agent
Your users must be running FortiClient Endpoint Security v5.0 to make use of this type of authentication.
On the FortiAuthenticator unit, you need to enable FortiClient Service when you define the unit’s secret key. Go to SSO & Dynamic Policies > SSO > Options. You need to provide your users the FortiAuthenticator IP address and secret key so that they can configure the FortiClient SSO Mobility Agent on their computers. See “Configuring the FortiGate unit”.