Chapter 4 Authentication : SSO using RADIUS accounting records : Configuration Overview
  
Configuration Overview
The general steps to implement RADIUS Single Sign-On are:
1. If necessary, configure your RADIUS server. The user database needs to include user group information and the server needs to send accounting messages.
2. Create the FortiGate RADIUS SSO agent.
3. Define local user groups that map to RADIUS groups.
4. Create a security policy which specifies the user groups that are permitted access.