Skip to main content
barisben
New Member
September 19, 2025
Question

FortiNAC Role Assignment Issue with LDAP Users

  • September 19, 2025
  • 2 replies
  • 582 views

Users are connecting to the corporate network with their LDAP credentials and I have configured their roles accordingly. However for some reason, about 1-2 out of every 10 users end up coming to FortiNAC-F with the NAC-Default role, even though they are in the correct LDAP group on AD. The correct behavior and what usually happens is that when a user connects for the first time, if they are a member of group X, they are assigned to the X role. The issue resolves by deleting the host registration from the NAC and when the user disconnects and reconnects to the network they get the correct role. What could be the reason?

 

Screenshot_5.png

 

2 replies

Anthony_E
Staff
Staff
September 22, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Sheikh
Staff
Staff
September 22, 2025

Hello @barisben ,

 

When assigning user roles, it is recommended to base the assignment on the user’s Directory attributes in LDAP rather than on Directory group membership.

 

This is because FortiNAC checks directory attribute data during the user registration process. Group membership, however, may not always be up to date, since the latest Directory synchronization might not have run yet to refresh the FortiNAC cache with the updated group information.

 

 - Have you checked that the "ldap bind" user has sufficient permissions on that specific OU where the user resides ?

 - Are there any changes in AD for users (e.g., moving from one OU to another OU) ?

 - Moreover, are the DCs and FortiNAC in the same location ? If not how is the network latency ?

 

regards,

 

Sheikh

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
barisben
barisbenAuthor
New Member
September 29, 2025

Hello,

 

-Checked that the "ldap bind" user has sufficient permissions on that specific OU where the user resides.

-There are no any changes in AD for users (e.g., moving from one OU to another OU)

-Moreover, DCs and FortiNAC are in the same location. Network latency is so normal, always.