Created on
04-05-2024
05:17 AM
Edited on
08-18-2025
06:36 AM
By
Stephen_G
| Description | This article describes how to configure LDAP External Authentication. |
| Scope | FortiSIEM. |
| Solution |
When configuring User accounts on the FortiSIEM, there are several ways to import users from a Windows Active Directory.
Initial Steps:
In the Active Directory: Select the Domain, 'Right-click' -> Properties, and note the domain name.
Select the User, 'Right-click' -> Properties -> Member Of, and note the group names:
Select the User, 'Right-click' -> Properties -> Attribute editor, and note the name, sAMAccountName, userPrincipalName, and the distinguished name.
In the FortiSIEM: As an admin user of the FortiSIEM or of a specific Organization, Configure LDAP credentials by going to Admin -> Setup -> Credentials -> New.
Associate it with the Active Directory IP.
Test the credentials:
If the test credential is failing, review every entry involved in the access method definition. Regarding the NetBIOS/Domain field, make sure that it fits with the domain property found at the very first step of this article, or use one of the group type NetBIOS from the following command on the AD machine:
nbtstat -n
Configure the LDAP as External Authentication as a FortiSIEM admin or an Organization admin. From the organization admin user, set the domain name CMDB -> Users -> select user -> edit, and set the 'Domain' field to the expected domain of the organization.
Go to Admin -> Settings -> External Authentication, configure external authentication, and set the directory where the users are in the 'base DN' field.
Test the external authentication:
Important note: The same steps can be used while setting up LDAPS external authentication. However, note that the SSL certificate check is performed regardless of whether the 'Check Certificate' option under the External Authentication Profile configuration is ticked. This means that it is important to use the proper FQDN of the AD server in the IP/Host field that is set in the certificate to make it work.
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.