Skip to main content
akhan2
New Member
December 29, 2023
Solved

Remote user sync rule

  • December 29, 2023
  • 8 replies
  • 3346 views

Hi Everyone , 
I am facing a strange issue with sync rules. I have created sync rule to import the remote LDAP users. Sync is not happening correctly  because it does not reflect the correct users of the remote LDAP group.

I move the user to another OU  which is not part of the filter and the user is not removed from the group. I have also deleted the user for test purposes and user still remains in the remote users.

 

Best answer by dbu

This error is received because are no users on the this remote LDAP group and as result the sync rule is failing to run.
This explains why user is not getting deleted.
Enable the option : Proceed with rule even when response empty . 

Check and let me know if it helped. 

8 replies

dbu
Staff
Staff
December 29, 2023

Hi @akhan2 ,
Check if this option is enabled on the remote user sync rules : "Do not delete synced users when they are no longer found on the remote server" .

If enabled , disabled it and test again . 

akhan2
akhan2Author
New Member
December 29, 2023

Hi @dbu , This option is disabled, which means user should be removed  correct?

dbu
Staff
Staff
December 29, 2023

Yes if the option is disabled the user should be removed from the group in FortiAuthenticator.
Can you try a manual sync of the rule and check the logs if you see something related.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!