Description | This article describes how to delegate rights to a non admin account(s) to import users/groups from LDAP server and assign FortiTokens. |
Scope | FortiAuthenticator |
Solution |
1) Logon to Fortiauthenticator and go to System -> Administration -> Admin Profiles and select 'Permissions Sets'.
2) Select 'Create new'.
3) Enter some useful information in 'Name' field.
4) From the Permissions list, it is either possible to scroll it down and select required permissions or possible to search from the available list and it will be shown only those entries.
5) Select the required permissions and press 'Down Arrow' key in the middle to move selected permissions to "Chosen User Permissions' box In this example, here, it is necessary to select these two permissions and press 'OK'.
- Can view LDAP Server. - Can view remote server settings.
6) After pressing 'OK', it will be shown in the Permissions set. Now select 'Return' in the Top menu or select 'Admin Profiles' again in the left menu.
7) Now, it is necessary to create an 'Admin Profile' and link this permission set to it. Select 'Admin profiles' and then select 'Create New'.
8) At this point the 'Admin Profile' and 'Permission sets' are ready, now, it is necessary to link this to user account(s). it is either possible to create new accounts or use an existing account. In this example, a Helpdesk account will be created to assign this 'Admin Profile' to it.
9) Enter username and password, and ensure that the Role Administrator is selected, disable 'Full Permissions' and then in the 'Admin Profiles' list select the one created in the previous sets and select'OK'.
10) Now login with this 'Helpdesk' account and it is possible to import users from LDAP server, change user settings and also able to assign FortiTokens.
11) Now go to Authentication->Remote Users and select 'Import'.
Select the OU to import LDAP users and select 'OK'
Now, select any user account to modify settings or assign FortiTokens.
In this example, it is possible to choose 'Ad_Test' account.
After assigning the FortiToken, select 'OK' to save configurations.
Troubleshooting.
- Ensure to have the connectivity with Fortitokenmobile.fortinet.com, otherwise, issues in assigning FortiTokens to users will appear. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.