Skip to main content
ck8882
Explorer
September 22, 2023
Question

Configuring least privileges for LDAP admin account authentication in Active Directory

  • September 22, 2023
  • 2 replies
  • 1640 views

HI

 

May i know why FortiGate integrated to LDAP Active Directory AD that account require below permission? could we just select Read only?

 

In Permissions list, select the following:

  • Change password
  • Reset password

In Property-specific.select the following:

  • Write lockoutTime
  • Read lockoutTime
  • Write pwdLastSet
  • Read pwdLastSet
  • Write UserAccountControl

thanks

2 replies

asengar
Staff
Staff
September 22, 2023

Hi @ck8882 

Thanks for posting your query.

Can I know where are you seeing these options in AD ?

Kindly refer the below document for setting the LDAP server in Fortigate

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-FortiGate-to-use-an-LDAP-server/ta-p/196141

 

Request you to kindly elaborate your issue/query you have.

 

Regards

ck8882
ck8882Author
Explorer
September 22, 2023

HI @bhishek

 

The document is issued from fortinet document page. Please find URL link below 

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/110412/configuring-least-privileges-for-ldap-admin-account-authentication-in-active-directory

 

The link you shared is to show step how to integrate to LDAP server. What i would like to understand  is what permission needed and reason in Active Directory for LDAP intergrate to fortigate.

 

Thanks

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!