Skip to main content
FortiKoala
Staff
Staff
October 1, 2018

Technical Tip: Directory Attribute Mapping for authentication using Passive Agent configuration

  • October 1, 2018
  • 0 replies
  • 975 views

Description

 

This article describes that Passive Agent Configuration Rules require the 'Identifier' Directory attribute to be mapped to the NetBIOS name 'sAMAccountName'. Otherwise, Passive and/or Persistent Agents using Passive Agent Configuration rules will not authenticate correctly.


Scope


FortiNAC v9.x, vF7.x.

 

Solution

 

  1. Navigate to System -> Settings -> Authentication -> LDAP.
  2. Highlight the directory and select Modify.
  3. Select User Attributes.
  4. Verify the Identifier value is configured for 'sAMAccountName'.
  5. If different, change to 'sAMAccountName' and select OK to save. See below for an example.

 

190320_ID.jpg
Related documents:

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.