Skip to main content
seaoptimusprimeolive
New Member
December 15, 2022
Question

FortiClient EMS Domain not updating object OU path

  • December 15, 2022
  • 11 replies
  • 6888 views

When syncing to an AD Domain it does not update the "Full Group Path" for an endpoint if it has been moved in the Domain.  It only seems to show the first OU that it was detected in and no matter where the object gets moved to in AD it always shows the same path.

 

Is there any way to fix this? Or move the group manually?

11 replies

Stephen_G
Staff & Editor
Staff & Editor
December 19, 2022

Hi seaoptimusprimeolive,

 

I've noticed your post doesn't have an answer yet. I'll get in touch with some engineers and see if we can get one.

 

Thank you for using Fortinet Community. :)

 

Kind regards,

Stephen

Stephen_G - Fortinet Community Team
aliyavuzer
Staff & Editor
Staff & Editor
December 20, 2022

Hi seaoptimusprimeolive,

 

EMS can update full group path of the endpoint. I recommend please be sure "Distinguished Name" covers your OU. Also please provide your EMS Version and build number with us.

 

seaoptimusprimeolive
New Member
December 20, 2022

Hi aliyavuzer,

 

I am syncing the domain at the root OU so I am capturing the entire domain.

 

My version is 7.0.7 build 0398

 

Thanks,

Ben

aliyavuzer
Staff & Editor
Staff & Editor
December 27, 2022

Hello Ben,

 

Thank you for sharing. EMS Version looks fine. You may check system resources and ems service restart to check ldap sync again. If these steps doesn't help, you may consider raising a ticket to us for deep research.
Kind regards,

Ali

Mario_M
Visitor III
July 7, 2023

Hi,

were you able to solve? I have the exact same problem.

Best Regards,

Mario

Stephen_G
Staff & Editor
Staff & Editor
July 7, 2023

Hi Mario,

 

The original poster has not been active since December, so you are unlikely to receive a reply. However, you're welcome to create a new topic in the support forum with the issue you're facing and link to this one to say you've tried all the advice here.

 

Our engineers will help you soon. If you don't get a response within two days, one of the Community team members will try to get you someone who can help.

 

Kind regards,

Stephen_G - Fortinet Community Team
Mario_M
Visitor III
July 7, 2023

Thanks, I fixed it myself.
Just to help if this happens to others, I followed these steps.
I set debug level for logs.
I forced a sync and saw the error: "Could not verify server certificate using local or user-supplied certificates. Certificate details: ".
I updated the ldap coniguration by uploading the updated CA certificate and everything started working again.

 

Best Regards,

Mario

seaoptimusprimeolive
New Member
July 27, 2023

To update. I have just updated my EMS server to 7.0.9

After this I was unable to get my EMS tags that relied on domain groups to work so I deleted the domain sync and recreated it again.  Now it seems to be moving devices between OUs when they are moved in the domain.  I am not sure if I was using Simple "Bind Type" before (I could not find any explanation in the documentation that explains the differences) but I am now using Regular which is working now at least.

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!