I have followed this as much as possible, I am using sAMAccountName on the config user ldap so it looks at every account, but NTLM doesnt work at all, So I set up basic Auth to the same LDAP server, and that works fine, user has to log in with current credentials and they can hit the proxy policy and surf the web etc, can see them under "diagnose wad user list" as "basic auth"
I need the behaviour to be transparent, so NTLM seems to be the answer (Not using FSSO yet!)
but the login box appears, you type in creds, then it just appears again.
config user ldap
edit "ldap-server"
set server "x.x.x.x"
set cnid "sAMAccountName"
set dn "dc=lab,dc=local"
set type regular
set username "myadadmin"
set password ENC blah blah blah
next
config authentication scheme
edit "MYAD-LDAP"
set method nlm
set domain-controller "MYDC" (LDAP SERVER ABOVE)
config authentication rule
edit "auth-web"
set srcintf "proxy-int"
set srcaddr "all"
set active-auth-method "MYAD-LDAP"
Any advice please?
| User | Count |
|---|---|
| 2930 | |
| 1459 | |
| 869 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.