Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
daemonhunter
New Contributor

FortiAuthenticator API Endpoint for LDAP Groups

Im trying to find a FAC API endpoint to query what users are in a specific LDAP Group. This is as close as I could get. Unfortunately this only returns groups that are local groups, not LDAP groups.

 

Anyone else figured out how to do this or if its possible with the current API?

https://docs.fortinet.com/document/fortiauthenticator/6.6.2/rest-api-solution-guide/583007/local-use...


6 REPLIES 6
funkylicious
SuperUser
SuperUser

why not query the AD/LDAP directly ?

"jack of all trades, master of none"
"jack of all trades, master of none"
daemonhunter

Unfortunately it doesn’t work that way. FA creates a group of LDAP users. It’s FA’s group not the domains. 

funkylicious

so basically, it's a local FAC group that has remote LDAP server/users defined/imported.

try querying the localgroups APIs

"jack of all trades, master of none"
"jack of all trades, master of none"
daemonhunter

Correct. The local groups api endpoint will only show local groups, not ldap groups. That’s the reason for the post. 

funkylicious

did try it also in my env and cannot seem to find a way to return them.

"jack of all trades, master of none"
"jack of all trades, master of none"
daemonhunter

Ok, thank you for trying. At least now I have a sanity check that I'm not missing an endpoint or something. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors