Skip to main content
Ashton
Visitor III
January 17, 2025
Question

FortiClient EMS - Prevent Constant Entering of Invitation Code for AD Users on Multiple Windows PCs

  • January 17, 2025
  • 5 replies
  • 3075 views

Hello! I have an issue related to FortiClient EMS and how it's deployment model installed on Windows PCs is needing to use the invite code for every AD user that signs into a PC. In other words, I'm doing something wrong for how EMS handles  for AD users.

 

I am deploying this for a client to manage web filtering profiles for verified AD users and sometimes these users need to access many different machines across the facility. Ideally, when a device is installed with the FortiClient program from the EMS deployment models, we apply the invite code and the device is tethered to our EMS server. This theoretically is all we need to do for handling the invitation, and once a user logs in with their AD credentials a unique web filter would be applied to them automatically no matter what PC they're on. Now, the problem is that we don't have a way to have FortiClient activate once we've installed it and used our invite code and instead, signing out and signing in between AD users shows FortiClient not going online at all. One user might have EMS detect them but that would be the account we would be signed into when installing the FortiClient and inviting it to the EMS server. The only way to get this to work is to use another invite code for every user to sign in (when instead they're logged as a "verified" user) and we have to keep entering the user's invitation code on every single device they sign into, building licenses for verified users in the User Management's verified users section. We cannot afford to do this, as the scope of their work amounts to keeping the same web filtering profile on any device they sign into with their AD credentials and having FortiClient stay connected the whole way through.

 

I just need to know where I'm making this mistake, either within their deployments or if I need to do something else or extra. What am I missing? Any help would be more than appreciated! 

5 replies

Anthony_E
Staff
Staff
January 20, 2025

Hello Ashton,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Ashton
AshtonAuthor
Visitor III
January 20, 2025

Hi Anthony,

 

Thank you for getting back to me on this. This does feel like a very niche question to begin with, that or I may be misunderstanding something with how EMS works with users. Please don't hesitate to ask for more information if you need it, I'll be happy to provide.

Anthony_E
Staff
Staff
January 20, 2025

Hi Ashton,

 

Thank you :)!

I am sure one of our experts will see your post and will help :)!

 

Regards,

Best Regards
Anthony_E
Staff
Staff
January 22, 2025

Hi Ashton,

 

I'm checking meanwhile in our Knowledge Base if an article is answering your question.

Did you already have a look?

 

Regards,

Best Regards
Anthony_E
Staff
Staff
January 29, 2025

Hello,

 

Unfortunately I could not find any answer for your question.

The best would be to contact the Fortinet support: https://support.fortinet.com/welcome/#/

 

and open a ticket with them.

 

Thanks a lot in advance.

 

Regards,

Best Regards
michael2406
Visitor III
April 15, 2025

Do you have a solution?