Skip to main content
Tim_86
New Member
October 5, 2018
Solved

FortiAuthenticator - Admin Profile for customer Organization only.

  • October 5, 2018
  • 3 replies
  • 3411 views

Hi,

I've got a short question regarding the ForitAuthenticator.

 

We are setting this device up for ourself and for one of out customers.

 

The customer needs to have it's own Admin Profile to create users and should only see it's own organization.

 

The problem we are facing right now is that the customer admin can see all the users even outside it's own organization.

 

Is there something we're missing?

 

Kind regards,

Tim

    Best answer by xsilver_FTNT

    Hi Tim,

    nope, you are not missing anything I think.

    The FortiAuthenticator (FAC hereinafter) admins can be profiled so each 'role' can do certain things, but generally on whole FAC.

    There is nothing like VDOMs known from FortiGate or ADOMs from FortiManager.

    Usual implementation is one FAC per enterprise where admins are for one subject.

     

    However, if you want give customer ability to manage his users then I do see two possible options:

     

    A) Remote User Sync Rules

    this feature allows you to keep admin accounts for you only, no access from customer to FAC, but FAC will sync users from customer's LDAP automatically and according to set filter (just users matching LDAP filter, for example belonging to specific group/OU on LDAP/AD). This will create/remove user on FAC once created/removed in LDAP. Plus, users can be provided with 2FA token when synced, and tokens returned to pool when user get deleted (once he is not seen as matching sync filter).

    This feature is used very often in situations where FAC is managed by one group/team of admins but AD/LDAP is managed by another team.

     

    B) Guest portal

    on the FAC you can create so called 'sponsor' which is admin able to manage just guest/user accounts on FAC, nothing else.

    3 replies

    xsilver_FTNT
    Staff
    Staff
    October 5, 2018

    Hi Tim,

    nope, you are not missing anything I think.

    The FortiAuthenticator (FAC hereinafter) admins can be profiled so each 'role' can do certain things, but generally on whole FAC.

    There is nothing like VDOMs known from FortiGate or ADOMs from FortiManager.

    Usual implementation is one FAC per enterprise where admins are for one subject.

     

    However, if you want give customer ability to manage his users then I do see two possible options:

     

    A) Remote User Sync Rules

    this feature allows you to keep admin accounts for you only, no access from customer to FAC, but FAC will sync users from customer's LDAP automatically and according to set filter (just users matching LDAP filter, for example belonging to specific group/OU on LDAP/AD). This will create/remove user on FAC once created/removed in LDAP. Plus, users can be provided with 2FA token when synced, and tokens returned to pool when user get deleted (once he is not seen as matching sync filter).

    This feature is used very often in situations where FAC is managed by one group/team of admins but AD/LDAP is managed by another team.

     

    B) Guest portal

    on the FAC you can create so called 'sponsor' which is admin able to manage just guest/user accounts on FAC, nothing else.

    Tim_86
    Tim_86Author
    New Member
    October 8, 2018

    Hi Tomas,

    Thanks for your reply, this is some useful information.

    Our Authenticator is our LDAP server so the Guest portal or Remote user sync rules wouldn't be a lot of use.

    We just need to administer the FAC ourself.

    Cheers!

    xsilver_FTNT
    Staff
    Staff
    October 8, 2018

    Hi,

    just note that FortiAuthenticator is not AD or feature-packed LDAP server. I'd rather use it as RADIUS server (it's stronger in this role) towards other NAS devices, then as LDAP.

    There I do not see any big difference between using FortiAuthenticator as RADIUS or LDAP on, let's say, FortiGate to authenticate users to policies/VPN/WebFilters etc.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!