Skip to main content
anhminh918123
New Member
February 10, 2023
Question

Regarding to 'agent joined Windows Domain' check on FortiNAC

  • February 10, 2023
  • 2 replies
  • 2928 views

Hi Team, 

We are running FortiNAC v9.4.1, and we need to run checking if 'agent joined Windows Domain'. Can you share us the guide for this task?

Thanks a lot. 

2 replies

ebilcari
Staff
Staff
February 10, 2023

If I understood your request correctly, you want to update the host with domain users that are logged in? If yes this can be achieved with the Passive Agent. Just create a entry in Policy & Objects > Passive Agent without specifying much settings. It allows FortiNAC to process the information coming from Persistent Agent regarding the domain logged in user on the PC that have the agent installed.


You can read more about it here: https://docs.fortinet.com/document/fortinac/9.4.0/administration-guide/60485/using-windows-domain-logon-credentials

Emirjon
anhminh918123
New Member
February 11, 2023

Hi emirjon, 

Thank you so much for your response. 

it isn't our case. We would like to create a policy: 'a PC (running persistent agent) can connect to Employee VLAN only if it is joined domain example  'abc.bank.vn'.  


JasonM
Staff
Staff
February 11, 2023

Hi

 

1st you need to create a custom scan (Policy & Objects > Endpoint Compliance > Scans > Custom Scans) and configure a Windows Domain check policy.  Add in the appropriate place the domain. (It's actually the NetBIOS name, not domain)

 

2nd attach that custom scan to a compliance check (Policy & Objects > Endpoint Compliance > Scans > Add > Windows > Custom > Tick the custom scan you just created)

 

There may be other methods too, like registry checking for certain keys and so on, but IMO that's probably the simplest to get you going.