Description | This article describes that FortiClient EMS cannot match the Deployment Policy when the endpoint belongs to 2 AD groups. |
Scope |
Starting from EMS 7.2.1, EMS can integrate with Azure AD (aka Microsoft Intra ID) and import endpoint devices from it. However, up to the latest EMS 7.2.3, EMS will not match an endpoint with 2 Azure AD groups to any Deployment Policy.
Engineering is in progress to fix this. The Internal Case ID is 982536. |
Solution | As a workaround, assign the endpoint to ONE device group only in Azure AD to use the Deployment Policy based on Azure AD group membership. Assign them back to desired multiple Azure AD groups after the deployment is completed. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.