| Description | This article explains the reason why FortiClient EMS is not able to sync a new AD group that has been newly created in AD server, but not showing any sync error in GUI. |
| Scope | EMS v7.0.x, v7.2.0 to v7.2.3, and Windows Server 2022 OS is used. |
| Solution |
If either the EMS server or the AD server is Windows Server 2022 OS, EMS may fail to sync correctly with the LDAP server. This is because, in Windows Server 2022, TLS 1.3 is used by default for LDAP connection. EMS version earlier than v7.2.4 does not support TLS 1.3 connection.
While EMS 7.2.3 and earlier may not show an error in GUI when performing a sync, enable Debug level logging in EMS.
Error code: 82 Error code: 85
It is likely due to this TLS 1.3 issue.
The solution is to upgrade EMS to version v7.2.4. EMS v7.2.4 supports TLS 1.3 LDAP connection. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.