Description |
This article explains how to remove a nonexistent Domain Controller from the SSO Domains list in the FortiAuthenticator. The Domain Controller is not visible anymore in the Authentication -> Remote Auth.Servers. |
Scope | FortiAuthenticator |
Solution |
If one or more Domain Controllers are not used anymore or do not exist but the Domain Controller is not reachable, it will still be visible in FortiAuthenticator -> Monitor -> SSO -> Domains with red cross.
This picture shows one example of this behavior. The DC-01.fortilab.com with IP address 192.168.189.5 should be removed from the list.
First thing to check is:
execute nslookup fortilab.com
Another option is to enable the option Restrict auto-discovered domain controllers to configured Windows event log sources and remote LDAP servers in Fortinet SSO -> Settings-> Methods section. It should be enabled in this case to restrict auto-discovery to only defined servers. That should update the SSO domain list. If more Domain Controllers are needed, it should be added in the Windows Event Log Sources section. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.