Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ck8882
New Contributor II

Configuring least privileges for LDAP admin account authentication in Active Directory

HI

 

May i know why FortiGate integrated to LDAP Active Directory AD that account require below permission? could we just select Read only?

 

In Permissions list, select the following:

  • Change password
  • Reset password

In Property-specific.select the following:

  • Write lockoutTime
  • Read lockoutTime
  • Write pwdLastSet
  • Read pwdLastSet
  • Write UserAccountControl

thanks

2 REPLIES 2
asengar
Staff
Staff

Hi @ck8882 

Thanks for posting your query.

Can I know where are you seeing these options in AD ?

Kindly refer the below document for setting the LDAP server in Fortigate

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-FortiGate-to-use-an-LDAP-...

 

Request you to kindly elaborate your issue/query you have.

 

Regards

@bhishek
ck8882
New Contributor II

HI @bhishek

 

The document is issued from fortinet document page. Please find URL link below 

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/110412/configuring-least-privileges-for...

 

The link you shared is to show step how to integrate to LDAP server. What i would like to understand  is what permission needed and reason in Active Directory for LDAP intergrate to fortigate.

 

Thanks

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors