FortiMail
FortiMail provides advanced, multi-layer protection against the full spectrum of email-borne threats
iyotov
Staff
Staff
Article Id 193534

Description

 
This article describes how to allow users to log in to personal quarantine with their Active Directory credentials using LDAP.


Scope

 
FortiMail.


Solution

 

  1. Create an LDAP profile in FortiMail:
  • Go to Profile -> LDAP -> New.
  • Set profile name.
  • Set server IP and port number.
  • Expand the 'User Query Options'.
  • Set Schema: Active Directory.
  • Set the Base DN (In this example, the domain is 'tri.ton').
  • Set the Bind DN and password. This is a service account in the AD that can bind and get user information.
  • Under 'User Authentication Options' select 'Search user and try bind DN'.
  • Select the 'Create' button.

Screenshot 2025-10-23 at 12.16.44.png
 
  1. Edit the newly created LDAP profile and test.

  • Open the profile for editing.
  • Select [Test LDAP Query].
  • From the drop-down menu 'Select query type' and choose 'Authentication'.
  • Type the test user’s email address and password.
  • Select test.
  • If everything is ok, the result should be 'Bind successful'.

Screenshot 2025-10-23 at 12.18.50.png

 Screenshot 2025-10-23 at 12.20.06.png

 

In case of a problem with the user credentials, the response will be 'Failed to bind'. In case of incorrect LDAP server settings (IP/port), there will be an error 'Connection failure'.

 

  1. Apply the LDAP profile in the recipient policy.
  • Go to Policy -> Policies -> New (or Edit).
  • Expand 'Authentication and Access'.
  • Select 'Authentication type' LDAP.
  • Select the LDAP profile.
  • Enable the access options that are required.
  • Select 'Create'/OK.

Screenshot 2025-10-23 at 12.21.29.png

 

 

When a WebMail user logs in, only the authentication profile from the first policy that matches the Recipient Pattern is applied.

 

If multiple Recipient Policies have different Recipient Patterns, authentication options must be configured in all of them.

An incorrect policy order may cause WebMail or quarantine access issues. See Technical Tip: Webmail access issue 

  1. Once spam messages are quarantined, users should be able to log in to http://<FortiMail_address>/mail/ and view the quarantine mailboxes.

Screenshot 2025-10-23 at 12.25.33.png