Hello
We are using FSSO CA mode.
We noticed frequent login attempts on servers from FSSO CA VMs with the FSSO service account.
Login Process: NtLmSsp
Authentication Package: NTLM
Package Name: NTLM V2
winlog.task: Logon
event.action: logged-in
These login attempts are not wanted on servers, since we need FSSO for client hosts only.
Tried to search on FSSO CA configuration tool how to filter the target hosts (eg.: by IP range) but didn't find such feature.
Any idea on how we can do such exclusion?
Hello @AEK
Please add all the service accounts in "ignore user list" in FSSO collector agent settings. See the technical document below.
regards,
Sheikh
Hello Sheikh
Thanks for your response. My issue is not that FSSO agent catches login events of service account users, but my concern is that FSSO service account is trying login on all our servers.
Hey AEK,
FSSO CA to verify workstation tries to connect to each machine to check if the user still logged via wmi. May be these events are related to it?
Meanwhile, the most important here is if this event overrides the current, proper user account, or not?
Hello
No it doesn't impact the proper user account since we don't need to monitor the servers. We only need to prevent these login attempt on server hosts.
Hi @AEK,
Can you check 'show monitored DCs', then 'Select DC to Monitor'? How many servers are impacted?
Regards,
Hi hbac
There are 6 monitored (screenshot).
It seems that any windows servers part of the domain are impacted (more than 50).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1771 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.