FortiAuthenticator 6.0 support of nested groups on my Remote LDAP query
Hi Everyone,
Windows AD server with nested groups (groups of groups of persons). Trying to get FortiAuthenticator to add users via that group (and ultimately, sync users back too).
i have tried a bunch of things (and even enlisted support's help) and after several hours of work, they seemed frustrated and came back with a "it's not supported". But, I found recent KB for Fortigate to rework the query to support finding users in nested groups.
https://kb.fortinet.com/kb/viewContent.do?externalId=FD41657&sliceId=1
I also tracked a MS article speaking to the same:
https://docs.microsoft.com/en-us/windows/desktop/adsi/search-filter-syntax
So i have tried changing the query to align with that (experimenting with the queries in Authentication->Remote Auth Servers->LDAP, Import users by Group Membership, but not having any success. It does find any user within a specific group, but not nested groups. Hoping to if someone knows if this is really not supported or if it does work!
Thank you!!
Shawn
