Description | This article describes how to initiate a manual/automation sync for SSO Groups. |
Scope | FortiOS, FSSO. |
Solution |
After connecting the external connector, if View User/Groups is selected, it is possible to observe what groups are being passed from the FSSO agent. If a change is made to the groups being monitored on FSSO, this change may not be immediately reflected on the FortiGate's GUI via Security Fabric --> Fabric Connectors --> edit FSSO connector --> Select View Users/Groups:
get user adgrp
As a result, it is possible to force a refresh manually by issuing the following command via CLI:
exec fsso refresh
For an automatic process, change the default of the group-poll-interval (0 minutes which is equivalent to do not poll) to a value within 1-2880 via the CLI as follows:
Configure Fortinet Single Sign On (FSSO) agents:
config user fsso end end Related document: Troubleshooting Tip: FSSO Complete troubleshooting for TAC tickets |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.