Created on 
    
	
		
		
		09-07-2021
	
		
		10:42 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
  Edited on 
    
	
		
		
		02-06-2022
	
		
		06:25 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 By  
				
		 Anthony_E
		
			Anthony_E
		
		
		
		
		
		
		
		
	
			 
		
Description.
This article explains how to apply a Group Filter to  LDAP Remote Authentication to limit admin login access to FortiAnalyzer or FortiManager to members of specific AD groups.
Expectations, Requirements
Objective:
Only users who are members of AD groups defined in the group filter can get admin access to Forti
Users from other AD group do not get access
Configuration
‘TestGroup1’ has member ‘group1user’
‘TestGroup2’ has member ‘group2user’



Verification
- Login with ‘group1user’ succeeds

Login with ‘group2user’ fails

To troubleshoot:
# diagnose debug application auth 25
# diagnose debug enabl
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.