Technical Tip: How to remove a Domain Controller which is not used/does not exist anymore from the SSO Domains list in the FortiAuthenticator
| Description | This article explains how to remove a nonexistent Domain Controller from the SSO Domains list in the FortiAuthenticator. The Domain Controller is not visible anymore in the Authentication -> Remote Auth.Servers. |
| Scope | FortiAuthenticator |
| Solution | If one or more Domain Controllers are not used anymore or do not exist but the Domain Controller is not reachable, it will still be visible in FortiAuthenticator -> Monitor -> SSO -> Domains with red cross.
This picture shows one example of this behavior. The DC-01.fortilab.com with IP address 192.168.189.5 should be removed from the list.
First thing to check is:
execute nslookup fortilab.com
Another option is to enable the option Restrict auto-discovered domain controllers to configured Windows event log sources and remote LDAP servers in Fortinet SSO -> Settings-> Methods section. It should be enabled in this case to restrict auto-discovery to only defined servers. That should update the SSO domain list. If more Domain Controllers are needed, it should be added in the Windows Event Log Sources section. |



