Skip to main content
hamidr
Staff
Staff
January 22, 2026

Technical Tip: How to prevent FSSO RDP logon from overriding existing user identity (polling mode)

  • January 22, 2026
  • 0 replies
  • 615 views
Description This article describes how RDP logons in environments using FortiGate with FSSO can update the IP-to-user mapping and change the active user identity, potentially impacting group-based security or web-filtering policies. This behavior is expected when FSSO operates in Windows Event Log polling mode without logon filtering, as both interactive and RDP logon events are processed.
Scope FortiAuthenticator
Solution

Problem statement (what is happening):


In environments using FortiGate with FSSO, administrators may observe that once a user opens an RDP session to another system, the user identity associated with the source IP is updated to reflect the RDP logon account. As a result, traffic may no longer match the expected security or web-filtering policies if the RDP account does not belong to the same Active Directory groups as the original interactive user.
This behavior can impact access to applications or websites that rely on group-based policy enforcement.
This is expected behavior when FSSO is operating in Windows Event Log polling mode and no logon filtering is configured. In this mode, FSSO processes successful logon events as they are detected, including interactive and remote (RDP) logons.


Root cause:


When FortiAuthenticator (FAC) or FortiGate FSSO Agent is configured for:

  • Windows Event Log polling
  • Logon type = Interactive / RemoteInteractive

Every successful RDP logon (Event ID 4624) is treated as a valid user login and mapped to the source IP.
A

s a result:

  • User A logs in locally on the workstation.
    • User A belongs to the correct AD group.
    • Access works as expected.
  • An RDP session is initiated from the same workstation using a different AD account (User B).
    • A new successful logon event is generated.
  • FSSO updates the IP-to-user mapping to User B.
    • Web filtering or firewall policies are now evaluated against User B.
    • Access fails if User B does not belong to the required AD groups.

 

Confirm the FSSO method in use:

 

Before applying any configuration changes, the FSSO method in use must be identified.

 

In FortiAuthenticator, navigate to Fortinet SSO -> Settings -> Methods.

 

Methods.jpg

 

If the configured FSSO method uses the Collector Agent, the behavior and mitigation options differ from those described in this article. For Collector Agent deployments, two supported approaches are available:

 

  1. Ignore User List (Collector Agent).

The Ignore User List in the Collector Agent GUI can be used to exclude specific user accounts from FSSO processing. Logon events generated by these users are ignored and do not update the IP-to-user mapping.

 

See Technical Tip: How and why to use the 'Ignore User List' option in FSSO Collector Agent.

 

  1. RDP Logon Override (Collector Agent).

The RDP logon override feature in the Collector Agent GUI allows control over how RDP logon events affect existing user mappings, preventing remote logons from unintentionally replacing the active user identity.

 

See Technical Tip: FSSO RDP logon override.

 

Windows Event Log polling:

 

If the configured FSSO method is Windows Event Log polling, the behavior described in this article applies.
In this mode, user identity mapping is derived from Windows logon events collected from domain controllers, including both interactive and remote (RDP) logons. Each successful logon event can update the IP-to-user association unless additional filtering mechanisms are configured.

 

Excluding users or groups from FSSO polling events:

 

To prevent specific user or group logon events from being processed by FSSO when using Windows Event Log polling, exclusions must be configured using SSO Users / SSO Groups and Fine-grained Controls, as outlined in the following steps.

 

Step 1: Define users or groups for exclusion.


First, the relevant users or groups must be created or imported from the Active Directory.
Navigate to one of the following paths on FortiAuthenticator:

  • Fortinet SSO -> Filtering -> SSO Users.

Or:

  • Fortinet SSO -> Filtering -> SSO Groups.

 

Create or import the Active Directory user(s) or group(s) whose logon events should be excluded from FSSO polling.

 

Fine-grained control-User.jpg

 

Once at least one user or group is defined, the related filtering and fine-grained control options become available.


Step 2 – Apply exclusion using Fine-grained Controls.


After defining the users or groups:

 

Navigate to:

Fortinet SSO -> Filtering -> Fine-grained Controls.

 

Select the appropriate tab at the top:

  • SSO Users, or:
  • SSO Groups.

Select the previously created or imported user(s) or group(s).

 

Choose Exclude from SSO.

 

Save the configuration.

 

Fine-grained control.jpg

 â€ƒ

Exclude_from_SSO_Part_2 (3).png

 

This configuration instructs FortiAuthenticator to ignore logon events generated by the selected users or groups, preventing those events from updating the IP-to-user mapping. 

  

Resulting behavior:

Excluded user or group logon events are ignored by FSSO, preventing RDP or secondary logons from overriding the existing IP-to-user mapping. Group-based firewall and web-filtering policies continue to evaluate the intended user.

 

Note:

This approach should be applied selectively and is recommended for shared workstations, jump servers, and administrative RDP access, where Fine-grained Controls provide precise and supported identity filtering in Windows Event Log polling mode.

 

Related documents:

Technical Tip: How and why to use the 'Ignore User List' option in FSSO Collector Agent

Technical Tip: FSSO RDP logon override 

FortiAuthenticator Administration Guide - FSSO Methods 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!