Skip to main content
HS08
Explorer
July 30, 2026
Question

Fnac computer authentication

  • July 30, 2026
  • 5 replies
  • 65 views

If we use computer authentication then can service connector get record grom device group? I want to make dynamic vlan assigment based on entra id with computer authentication.

5 replies

Stephen_G
Staff & Editor
Staff & Editor
August 4, 2026

Hello again HS08,

Thanks for using our forum. We’ll look to get you an answer or help.

Stephen_G - Fortinet Community Team
HS08
HS08Author
Explorer
August 5, 2026

hi ​@Stephen_G is there any update?

Stephen_G
Staff & Editor
Staff & Editor
August 5, 2026

Hi HS08, 

None so far. This can take a few days. I will keep you posted.

In the meantime, if anyone else has any advice, feel free to contribute!

Stephen_G - Fortinet Community Team
ebilcari
Staff
Staff
August 7, 2026

The integration guide mentions group matching based on user information contained within the certificate attributes (CN has the UPN format of username). You can test when the computer name is included in the CN field of the certificate and whether it can be matched to a Remote Group. If so, the same mechanism should also work for computer authentication.
https://docs.fortinet.com/document/fortinac-f/7.6.5/microsoft-entra-id-authentication-cookbook/913148/example-remote-group-use-with-user-host-profile

Emirjon
HS08
HS08Author
Explorer
August 9, 2026

hi ​@ebilcari when we create the certificate from intune use device authentication then we can’t add information about username to the certificate.

https://learn.microsoft.com/en-us/intune/device-configuration/certificates/pkcs-profiles. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.