Description | This article describes why domain controllers do not appear on 'Select Domain Controllers to Monitor User Logon Events'. |
Scope | Fortinet Single Sign On(FSSO) Collector Agent, FortiGate. |
Solution |
FSSO Collector agent uses an auxiliary executable called 'Fortinet Single Sign On Agent Configuration' for its monitoring and configuration. This auxiliary program runs with the privilege of the current user session.
FSAEConfig.exe uses Directory Replication Service Remote Protocol (DRSUAPI) to retrieve the Domain Controller information from the domain controller. This protocol requires authentication, which the workstation admin fails because the admin is not part of the domain.
When the Domain Administrator is used, however, the feature works as expected:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.