Skip to main content
Visitor III
May 28, 2026
Question

FortiAuthenticator 8.0.3 - Does Usage Profile work with Remote LDAP/AD users or only local/manually imported users?

  • May 28, 2026
  • 1 reply
  • 54 views

Hello everyone,

I am working on a FortiAuthenticator 8.0.3 deployment and I need to apply a usage limit to AD users authenticated through FortiAuthenticator.

The goal is simple: after the user logs in to the captive portal using their Active Directory credentials, they should be allowed to use the network for only 1 hour.

I found this old Fortinet KB article from 2019:

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-RADIUS/ta-p/198682

In the article, there is a note saying that Usage Profiles can only be applied to local users and, starting from version 6.5, to manually imported LDAP users.

My question is:

Does this limitation still apply in FortiAuthenticator 8.0.3?

Or is it now possible to apply a Usage Profile directly to a Remote LDAP group, LDAP directory group, or LDAP filter, without manually importing each LDAP user into FortiAuthenticator?

In the current FortiAuthenticator documentation, the Usage Profile option appears available under User Groups, including Remote LDAP groups, but I could not find a clear statement confirming whether manually imported LDAP users are still required or not.

The environment is:

- FortiAuthenticator 8.0.3
- Users authenticated against Active Directory / LDAP
- FortiGate used as the RADIUS client / captive portal
- Requirement: limit authenticated AD users to 1 hour of usage after login
- RADIUS Accounting and CoA can be configured if required

Has anyone tested this behavior on FortiAuthenticator 8.0.x?

I would like to confirm whether Usage Profile works with dynamic Remote LDAP users/groups, or if the users must still be manually imported into FortiAuthenticator for the limit to be enforced.

Thank you.

1 reply

Sheikh
Staff
Staff
May 28, 2026

Hello ​@Daniel.athayde,

Usage profiles are reliably enforced for:

  • Local users
  • LDAP users imported into FortiAuthenticator

For dynamic remote LDAP/AD groups (users authenticated directly from LDAP without import), usage profile enforcement may not work, especially for RADIUS accounting/session tracking. 

So for your use case (1-hour captive portal access for AD users):

  • Recommended approach = Import LDAP users/groups into FortiAuthenticator
  • Then apply the Usage Profile to the imported group
  • Configure RADIUS Accounting + CoA on FortiGate for proper session timeout enforcement

https://docs.fortinet.com/document/fortiauthenticator/8.0.0/administration-guide/738461/usage-profile
 


regards,

 

Sheikh

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!