Hi Forum!
I have two issues with the Group Assignment Rules in FortiClient EMS.
The manual says
If a newly connected endpoint does not match any group assignment rule and belongs to an imported AD domain, the endpoint is moved into the OU to which it belongs in the AD domain tree. If no AD domain has been imported, or the endpoint also does not belong to the imported AD domain, it is placed in the Other Endpoints group.
My endpoints all belong to an AD domain for now. The domain-membership should only be relevant, if a newly connected endpoint does not match any group assignment rule. Only when there is no rule match, the endpoint should be moved into the OU to which it belongs in the AD domain tree.
The problems starts, when creating an assignment rule. I can only choose groups from within Endpoints > Workgroups and not from Endpoints > Domains... If I use a Workgroups-group, domain joined endpoints are not placed into that group but in its OU.
My second issue is, that I cannot use the AD group Assignment rule, introduced with FortiClient 6.2.0. I'm simply not offered the AD Group-Type in the dropdown list.
best regards
Kai
Created on 12-17-2021 12:30 AM Edited on 12-17-2021 12:31 AM
Hi Jay8,
we never got this to work. We have learned to live without group assignment rules.
best regards
Kai
P.S.: I cannot login to the forum as kernal anymore and I don't know why. I assume it's because login is handled by "FortiCloud" now. Don't have time to investigate this issue... ;)
Hi all,
There is a reported issue about this if you are using Split Tunnel:
https://docs.fortinet.com/document/forticlient/7.0.3/ems-release-notes/310815/known-issues
760816 | Group assignment rules based on IP addresses do not work when using split tunnel. |
Cheers.
Ezequiel.
I've encountered similar issues with group assignment rules in various software. It can be quite frustrating when the system doesn't work as expected, especially when it affects your workflow or project deadlines. Speaking of clear and effective communication—whether it's in software instructions, project guidelines, or even public speaking—it's essential to convey your message clearly and persuasively. On that note, if anyone here is also grappling with preparing speeches or presentations, especially in technical or complex fields, it might be worth checking out some professional help. https://us.dissertationteam.com/speech-writing-services offers specialized speech-writing services that can help articulate your thoughts clearly and impactfully, ensuring your message is both understood and persuasive. It’s great for those who need to present at seminars, conferences, or even team meetings where clear communication is crucial.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.