Skip to main content
FortiZiq
Staff
Staff
October 23, 2025

Troubleshooting Tip: Cannot poll certain user group from FSSO Connector

  • October 23, 2025
  • 0 replies
  • 236 views
Description

This article describes the troubleshooting steps that can be taken if some user groups cannot be polled from FSSO Connector in FortiManager.

Scope FortiManager.
Solution

In the example below, FSSO Agent (FortiAuthenticator / FAC2) has three groups configured:

  • testgrp1
  • testgrpA
  • testgrpB

 

1.FAC group.jpg

 

However, when checked in FortiManager, only 'testgrpA' and 'testgrpB' can be seen from the FSSO Connector FAC2.

 

2. polledgrps.jpg

 

Comparing the two images, the user group 'testgrp1' is not received from the FSSO connector.

 

As a troubleshooting step, users can check if this object already exists in the ADOM DB under Policy & Objects -> Advanced -> CLI Configurations: user -> adgrp.

 

In the example, the user group 'testgrp1' is already polled from another FSSO Connector FAC1.

 

3. adomdb.png

 

One solution for this is to make sure the user group has a unique name in each FSSO Agent. In the example, the user group 'testgrp1' in FAC2 has been changed to 'testgrp1_FAC2' and can now be retrieved.

 

4. changed.png

 

Related article:

Technical Tip: Configuring FSSO from FortiManager 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!