Hi,
I've got a short question regarding the ForitAuthenticator.
We are setting this device up for ourself and for one of out customers.
The customer needs to have it's own Admin Profile to create users and should only see it's own organization.
The problem we are facing right now is that the customer admin can see all the users even outside it's own organization.
Is there something we're missing?
Kind regards,
Tim
Solved! Go to Solution.
Hi Tim,
nope, you are not missing anything I think.
The FortiAuthenticator (FAC hereinafter) admins can be profiled so each 'role' can do certain things, but generally on whole FAC.
There is nothing like VDOMs known from FortiGate or ADOMs from FortiManager.
Usual implementation is one FAC per enterprise where admins are for one subject.
However, if you want give customer ability to manage his users then I do see two possible options:
A) Remote User Sync Rules
this feature allows you to keep admin accounts for you only, no access from customer to FAC, but FAC will sync users from customer's LDAP automatically and according to set filter (just users matching LDAP filter, for example belonging to specific group/OU on LDAP/AD). This will create/remove user on FAC once created/removed in LDAP. Plus, users can be provided with 2FA token when synced, and tokens returned to pool when user get deleted (once he is not seen as matching sync filter).
This feature is used very often in situations where FAC is managed by one group/team of admins but AD/LDAP is managed by another team.
B) Guest portal
on the FAC you can create so called 'sponsor' which is admin able to manage just guest/user accounts on FAC, nothing else.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi Tim,
nope, you are not missing anything I think.
The FortiAuthenticator (FAC hereinafter) admins can be profiled so each 'role' can do certain things, but generally on whole FAC.
There is nothing like VDOMs known from FortiGate or ADOMs from FortiManager.
Usual implementation is one FAC per enterprise where admins are for one subject.
However, if you want give customer ability to manage his users then I do see two possible options:
A) Remote User Sync Rules
this feature allows you to keep admin accounts for you only, no access from customer to FAC, but FAC will sync users from customer's LDAP automatically and according to set filter (just users matching LDAP filter, for example belonging to specific group/OU on LDAP/AD). This will create/remove user on FAC once created/removed in LDAP. Plus, users can be provided with 2FA token when synced, and tokens returned to pool when user get deleted (once he is not seen as matching sync filter).
This feature is used very often in situations where FAC is managed by one group/team of admins but AD/LDAP is managed by another team.
B) Guest portal
on the FAC you can create so called 'sponsor' which is admin able to manage just guest/user accounts on FAC, nothing else.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Hi Tomas,
Thanks for your reply, this is some useful information.
Our Authenticator is our LDAP server so the Guest portal or Remote user sync rules wouldn't be a lot of use.
We just need to administer the FAC ourself.
Cheers!
Hi,
just note that FortiAuthenticator is not AD or feature-packed LDAP server. I'd rather use it as RADIUS server (it's stronger in this role) towards other NAS devices, then as LDAP.
There I do not see any big difference between using FortiAuthenticator as RADIUS or LDAP on, let's say, FortiGate to authenticate users to policies/VPN/WebFilters etc.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.