Chapter 1 What’s New for FortiOS 5.0 : Authentication: users and devices : SSO using a FortiAuthenticator unit : User’s view of FortiAuthenticator SSO authentication : Users with FortiClient Endpoint Security - FortiClient SSO Mobility Agent
  
Users with FortiClient Endpoint Security - FortiClient SSO Mobility Agent
All authentication is performed transparently with no request for credentials. IP address changes, such as those due to WiFi roaming, are automatically sent to the FortiAuthenticator unit. When the user logs off or otherwise disconnects from the network, the FortiAuthenticator unit is aware of this and deauthenticates the user.
The FortiClient SSO Mobility Agent, a feature of FortiClient Endpoint Security v5.0, must be configured to communicate with the appropriate FortiAuthenticator unit. After that, the agent automatically provides user name and IP address information to the FortiAuthenticator unit for transparent authentication.