Im trying to find a FAC API endpoint to query what users are in a specific LDAP Group. This is as close as I could get. Unfortunately this only returns groups that are local groups, not LDAP groups.
Anyone else figured out how to do this or if its possible with the current API?
https://docs.fortinet.com/document/fortiauthenticator/6.6.2/rest-api-solution-guide/583007/local-use...
why not query the AD/LDAP directly ?
Unfortunately it doesn’t work that way. FA creates a group of LDAP users. It’s FA’s group not the domains.
Created on ‎09-14-2025 08:18 AM Edited on ‎09-14-2025 08:18 AM
so basically, it's a local FAC group that has remote LDAP server/users defined/imported.
try querying the localgroups APIs
Correct. The local groups api endpoint will only show local groups, not ldap groups. That’s the reason for the post.
did try it also in my env and cannot seem to find a way to return them.
Ok, thank you for trying. At least now I have a sanity check that I'm not missing an endpoint or something.
User | Count |
---|---|
2587 | |
1378 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.