FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
btan
Staff
Staff
Article Id 294318
Description This article describes that FortiClient EMS cannot match the Deployment Policy when the endpoint belongs to 2 AD groups.
Scope

Starting from EMS 7.2.1, EMS can integrate with Azure AD (aka Microsoft Intra ID) and import endpoint devices from it.

However, up to the latest EMS 7.2.3, EMS will not match an endpoint with 2 Azure AD groups to any Deployment Policy.


when-2-AD-groupswhen-2-AD-groups

 

policy-wont-matchpolicy-wont-match

 

Engineering is in progress to fix this. The Internal Case ID is 982536.

Solution As a workaround, assign the endpoint to ONE device group only in Azure AD to use the Deployment Policy based on Azure AD group membership. Assign them back to desired multiple Azure AD groups after the deployment is completed.

 

Contributors