FortiAuthenticator
FortiAuthenticator provides access management and single sign on.
tonylin1
Staff
Staff
Article Id 302535
Description

This article describes that when automatically assigning FortiToken Mobile authentication to all active directory users, the disabled user will not be assigned FortiToken.

Scope FortiAuthenticator.
Solution
  1. There are two existing remote users from Remote Auth. Servers -> LDAP.

 

截圖 2024-03-04 上午9.16.01.png

 

  1. After disabling one user 'twtac2':

 

截圖 2024-03-04 上午9.16.19.png

 

  1. Change the Remote User Sync Rules with FortiToken Mobile:

 

截圖 2024-03-04 上午9.16.39.png

 

  1. The disabled user will not be automatically assigned with the FortiToken:

 

截圖 2024-03-04 上午9.17.02.png

 

  1. The system event log shows that FortiAuthenticator has only added the FortiToken Mobile to the enabled user: 

 

date=2024-03-04 time=01:16:57+0000 oid=1739 logid=30303 cat="Event" subcat="System" level="information" nas="" action="" status="" msg="Assigning remote LDAP user twtac1 with FortiToken Mobile FTKMOB42C9A9F2FA, activation code EEIHZ3NAO5W6Z4D2." user=""

 

Related article:

Technical Tip: Automatically assigning FortiToken Mobile authentication to all active directory user...

 

 

Contributors