Description
This article describes the necessary configuration for FSSO logins to be processed in UPN(userPrincipalName) on FortiGate.
The required configuration and permissions are listed from collector agent and active directory.
Scope
FortiGate.
Solution
Step 1: Create a registry key.
Navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Fortinet\FASE\Collectoragent create a string with the value as 'UserPrincipalName'.
Step 2: Under Advanced settings, the event ID to poll should be set to 1. Alter the required event IDs as required. Refer to Event IDs used in FSSO.
Step 3: For the user account 'fsso_srv', it is needed to assign read/write permissions so that event logs are read and written to the collector eventlog.
Add the permission to the Collector agent, set this to full control.
Note: Giving full control to FSAE will as well propagate the changes to any mode enabled.
Step 4: As the 'eventlog' polling mode is used, it is necessary to allow permissions as 'eventlog reader role' for the specified user account.
The FortiGate will now show the events being processed in UPN format.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.