FortiPAM
FortiPAM allows you to protect, isolate and secure privileged account credentials, manage and control privileged user access, and monitor and record privileged account activity.
tbarua
Staff
Staff
Article Id 404846
Description

 

This article describes the prerequisite for creating Active Directory source while using Discovery Feature.

 

Scope

 

FortiPAM.

 

Solution

 

Discovery feature provides the opportunity to the following sources:   

  • Active Directory
  • Unix
  • FortiOS

 

Active Directory as a source will be covered in this article. 

 

Generally, if the target and secret are configured correctly in advance, the Target and Credential give the options to select the precreated target and secret. For example: 

 

discovery1.png

 

discovery2.png

However, if the target is not created properly with the correct template, the target will not be shown as expected. 

 

discovery4.png

Even if the target and the secret are being created manually, it might end up showing the error, as follows: 

'Source (LDAP). FortiPAM encountered a problem, try again!'

 

discovery3.png

 

In order to resolve the error, the Template setting needs to be checked under Target. In this failure scenario, the Default Template is being selected as a Windows Machine, which does not contain Domain-Controller, Domain . Hence, both Domain-Controller and Domain are prerequisites for creating Active Directory as a Discovery source.

 

discovery5.png

After correcting the Default Template  from Windows Machine to Windows Domain Account, the scan has successfully completed as follows:

 

discovery7.png

 

discovery6.png

 

Related documents:

Creating discovery entry - FortiPAM administration guide

Creating secret templates - FortiPAM administration guide