Description
This article describes the difference between the 'Display name' and 'Logon name' and the steps to configure authentication based on the user logon name.
'cn' is the default, and most of the customers will be using 'sAMAccountName'. 'cn' refers to 'Common Name' which is the 'Display name', and 'sAMAccountName' is the logon name (about Windows LDAP server).
Scope
FortiGate.
Solution
In the screenshot below, the 'Common Name Identifier' configured in FortiGate is 'sAMAccountName'.
To get authenticated with the user and log in by 'Logon name', use the 'Common Name Identifier' value as 'sAMAccountName'. The below screenshot shows the 'User logon name' from the Windows Active Directory.
On the other hand, when 'cn' is applied as a 'Common Name Identifier', the user will need to authenticate through the 'Display name'. The below screenshot shows the 'Display name' from the Windows LDAP server.