FortiEDR
FortiEDR automates the protection against advanced threats, pre and post-execution, with real time orchestrated incident response functionality.
ymasaki
Staff
Staff
Article Id 318631
Description This article describes when LDAP authentication fails although LDAP Test indicates Success.
Scope FortiEDR.
Solution

LDAP authentication integrates with Active Directory and authenticates users to log in to FortiEDR Central Manager.

Sometimes, the LDAP test indicates 'Success,' but the LDAP authentication fails with correct user credentials.

 

Below are sample outputs when the LDAP test indicates 'Success,' but the authentication fails.

 

kb_ldap1.png

 

kb_ldap2.png

 

The issue happens with the LDAP group settings either in FortiEDR Central Manager or the Active Directory server.

 

Follow these steps to rectify the LDAP authentication issue:

  1. Verify the LDAP group configuration in Active Directory.
  2. Check the group membership of the user in the Active Directory.
  3. In Role/Group mapping, the group must be set up using the LDAP group DN, but the current setting uses only the LDAP group name.

 

kb_ldap3.png

 

 

  1. To check the LDAP group DN, run 'dsquery group -name 'Group_Name'' to identify the correct DN on the Active Directory server. If the LDAP group is not created yet, create the group first.

 

kb_ldap4.png

 

  1. Update the Group settings to the LDAP group DN from Step 4:

 

kb_ldap5.png

 

  1. Save the change and log in again with LDAP user credentials under the LDAP groups:

 

kb_ldap6.png

 

  1. Once the login is successful, download the audit log under Administration -> Tools -> Audit Trail, to confirm the LDAP user logged into the system

 

kb_ldap7.png

Contributors