Two Logon Steps were created in DualShield Configuration for Fortigate VPN (IPSec) :
For FortiClient to authenticate using MFA, Step 2 has to be Out of Band as the software does not present an extra field to input an OTP.