Skip to main content
ahsanali_FTNT
Staff
Staff
August 11, 2016

Technical Tip: Setup a LDAP profile on FortiMail for Windows Active Directory group query for group based recipient policy matching

  • August 11, 2016
  • 0 replies
  • 5870 views

Description


This article describes the changes required to configure FortiMail LDAP profile to support Group Query against a Windows Active Directory LDAP server.


Scope


This has been tested against Windows Server 2008 R2, Windows Server 2012 R2, and Windows Server 2019.


Solution


Section A. Configure the LDAP Profile:

  1. Refer to Configuring LDAP profiles for complete steps on how to set up the Default Bind Options and User Query Options for Windows Active Directory.
  2. Configure the Group Query Options
 

LDAP_group.JPG

 

  • Group membership attribute: For Windows Active Directory, this is memberOf.
  • Select Use group name with base DN as group DN.
  • Group base DN - Enter the DN of the Group Container in the Active Directory. In this example, the Groups are all configured in the User container.

 

Here is how to retrieve the DN of the Group Container from Active Directory:

 

DN.png

 

  • Group name attribute: For Windows Active Directory, this is CN. Ensure the check mark beside Group Query Options is selected.
  • Save the configuration. Scroll down to the bottom of the page and select Apply.
  • Test the configuration. select 'Test LDAP Query...'.