Technical Tip: Directory Attribute Mapping for authentication using Passive Agent configuration
Description
This article describes that Passive Agent Configuration Rules require the 'Identifier' Directory attribute to be mapped to the NetBIOS name 'sAMAccountName'. Otherwise, Passive and/or Persistent Agents using Passive Agent Configuration rules will not authenticate correctly.
Scope
FortiNAC v9.x, vF7.x.
Solution
- Navigate to System -> Settings -> Authentication -> LDAP.
- Highlight the directory and select Modify.
- Select User Attributes.
- Verify the Identifier value is configured for 'sAMAccountName'.
- If different, change to 'sAMAccountName' and select OK to save. See below for an example.

Related documents:
