Created on
‎02-13-2025
07:40 AM
Edited on
‎10-17-2025
06:08 AM
By
Jean-Philippe_P
Description | This article describes how to change passwords for Windows domain users through FortiPAM. |
Scope | FortiPAM. |
Solution |
FortiPAM allows manual password changes in secrets using various templates, such as Windows Domain Account, Windows Machine, Unix Account, or Windows Domain Account (Samba). Additionally, automatic password changing is also allowed based on parameters specified in the secret settings.
Specify Name, Classification Tag, Default Template select 'Windows Domain Account', Domain- Controller specify Domain IP, Domain section specify 'Domain FQDN'. Advanced Domain Settings ensure that the Common Name is 'sAMAccountName' and the LDAPs Port used is 636.
Note: Password change will work only when FortiPAM is connected through the LDAP server using port 636.
Note: Domain name should be the FQDN of the domain, not the NETBIOS name. Run the below command on CMD to get the domain FQDN:
wmic computersystem get domain
Specify Name, select Folder, and the Target created before in step 1. Edit the 'Fields' section and specify the user domain account and password.
When using a password changer on Windows AD by LDAPs, it is required to enable both Change password and Reset password for the user on Windows AD.
In Generate next password, select from the following two options:
Note: The Customized option may be disabled if the secret template does not use the password for authentication.
Troubleshooting commands to run in FortiPAM CLI when a password change is failing for some reason:
diagnose wad debug enable category secret diagnose wad debug enable category pwdchg diagnose wad debug enable level verbose diagnose debug enable |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.