FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 193252

Description


This article provides steps to import administrative users from an Active Directory Group.

Scope


FortiNAC, FortiNAC-F.

Solution

 

Under System -> Settings -> Authentication -> LDAP.

 

  • 'Double-click' on the directory.
  • Select Search Branches.
  • Configure a group search branch mapping.

 

Figure 1. Create Group search branches to find relevant Admin groups.Figure 1. Create Group search branches to find relevant Admin groups.


Under the Selected Groups tab, place a checkmark in the group desired to give administrative privileges to (this case: Domain Admins).

Figure 2. Select the needed groups for Administrator account synchronization in FortiNAC.Figure 2. Select the needed groups for Administrator account synchronization in FortiNAC.


Under System -> Scheduler.

  • Select Synchronize Users with Directory.
  • Select the Run Now button (the previously selected 'Domain Admins' group will be imported in FortiNAC as a Host group).


Figure 3. Perform directory synchronization after making group changes.Figure 3. Perform directory synchronization after making group changes.


Under System -> Groups.

  • Delete the group (because it is imported as a host group).
  • Add a group with the exact same name 'Domain Admins'.
  • Make the group type Administrator.

Under Users -> Admin Profiles ->  Profile Mappings.

  • Select Add.
  • Use the drop-down to select the admin privileges the desired group to have. In this case 'Super Administrator'.
  • Use the drop-down to select the group 'Domain Admins'.
  • Select the OK button.

    Figure 4. Create profile mapping with required permission sets.Figure 4. Create profile mapping with required permission sets.

 

The remote LDAP admin accounts will be created in FortiNAC Users -> Admin Users under the following scenarios:

 

  1. Manually added by an Administrator. FortiNAC will detect this is a Directory user and add it with the LDAP attributes collected after the directory Synchronization.
  2. The LDAP Administrator logs for first time in FortiNAC GUI.
  3. The LDAP Administrator account is registered through a host registration process. Initially it will be created as a User type account. In the next Directory synchronization, the user account is elevated to Administrator type account in FortiNAC and mapped to the Group profile.

Related documents: