Skip to main content
xlloyd
New Member
November 6, 2015
Solved

Active Directory Bind Account Permission

  • November 6, 2015
  • 5 replies
  • 15126 views

Hi all,

 

I was looking through the forum and couldn't find any similar discussion. Please let me know if this has been addressed elsewhere.

 

I am working with a customer who is very particular when it comes to Active Directory permissions for service accounts. When using Regular binding for LDAP servers (using FSSO in polling mode), what are the minimum permissions I can assign to the bind account for the solution to function properly?

 

I have tried using regular users before and it didn't work so since then I have always used Domain Admin privileges. Unfortunately this won't fly with these guys.

 

Thanks!

Xavier

Best answer by Admin_FTNT

Hi,

 

Article is at http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD36039

 

Regards,

Admin.

5 replies

xsilver_FTNT
Staff
Staff
November 8, 2015

Hi, I would recommend to check KB articles , namely start with this one:

Technical Note: Restricting FSSO service account

http://kb.fortinet.com/kb...amp;externalId=FD36039

 

 

kind regards,Tomas

xlloyd
xlloydAuthor
New Member
November 9, 2015

Thanks so much! I was searching the kb too but apparently I was using the wrong search strings!

xlloyd
xlloydAuthor
New Member
November 9, 2015

[strike]Actually after reading through, I realised that this is with regards to the Collector Agent. I am doing only Polling Mode. Are the restrictions the same with both methods?[/strike]

 

EDIT: Sorry just reread it and it had all necessary info. Thanks again!

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!