Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
andrejrepka20
New Contributor

FortiClient disconnects from EMS when switching Windows user

Hello,

 

I deployed Forticlients to hosts via Forticlient EMS Cloud.

 

EMS is connected to domain and user are being verified against EntraID so when I deploy msi file from Intune and run the install script the EMS and VPN connects automatically. Issue comes after I log off from windows user to different account (for example maintanance or admin account for the host/station). The EMS disconnects and doesn't automatically connect again and I need to insert the invitation code to connect it again.

 

Also noting that the issue is not persistent and when troubleshooting sometimes the telemetry connection stayed after switching user to Local Admin and sometimes it just disconnects.

 

We are running Forticlient EMS cloud and deployed Forticlient is 7.4.3

 

I stumbled upon some older forum and reddit posts kinda describing the same issue but there wasn't any specific fix or explanation.

 

Thank you for any help

 

 

 

 

5 REPLIES 5
funkylicious
SuperUser
SuperUser

hi,

maybe disabling Log off When User Logs out of Windows in System Settings profile ?

"jack of all trades, master of none"
"jack of all trades, master of none"
andrejrepka20

Hello, This is disabled by default, i went through all of the settings that could indicate or be related to this issue but didnt find any. 

I was thinking later that day if this could possibly be caused by the local admin user not being in domain which we are using to authenticate the users.

My theory is that when the admin switches from domain user to local admin to do some maintenance, after the sync of the telemetry it recognizes that the user has been switched and disconnects the EMS but I dont know how plausible this could be

mycoolusername
New Contributor II

We’re experiencing the exact same issue. Our users are authenticated via LDAP against our local domain controller.

It doesn’t matter whether FortiClient is installed using the .msi or .exe installer, nor does it make a difference if it is deployed using the Domain Deployment method.

We use a bulk invitation embedded in the installer. After installation, the first user who logs into the PC is prompted to enter their credentials in the FortiClient popup. Once authenticated, the endpoint appears in FortiEMS and everything works as expected.

However, when a different domain user logs into the PC, FortiClient immediately disconnects from EMS in the Client. It doesn’t prompt for credentials and remains unlicensed.

If we log back in with the original user, FortiClient automatically reconnects to EMS and gets the policy back.

Additionally, the “Last Logged In User” field under Endpoints -> All Endpoints in EMS does not update to reflect the new Windows user login, it continues to show the first original user.

We’ve tried countless combinations of settings, but nothing has resolved the issue.

FortiClient Version: 7.4.4
EMS Version: 7.4.4 on-premise with per device licenses

funkylicious

also tested this in my lab and i would say that it's the expected behaviour and EMS was not design for multiple users being logged in at the same time on a single workstation.

 

if multiple users are logged at the same time, the first one logged in connects to EMS, the newly logged one will also require to connect to EMS and the previous/first one will be disconnected or it will show the profile/user of the new user as logged into FortiClient/EMS.

 

when you go to Endpoints > All Endpoints and under the User column you see the currently logged in one, when you click the dropdown menu it will display other users that have logged in and connected to EMS.

"jack of all trades, master of none"
"jack of all trades, master of none"
mycoolusername

Hello funkylicious,

I might not have been clear enough. We are completely logging off the previous user, waiting a few seconds, and then logging in with a different user. So there are no simultaneous logins on the machine. However, only the very first user ever logged in is being connected. Additionally, the drop-down under "Endpoints" in EMS only shows the first ever logged in user.
Funny enough, when logging out with the other user and logging back in to the first user, the FC is connected again and working. But still only for the first user who ever connected on this machine.
First user is connectedFirst user is connectedAny other user loggin in after is not connected.Any other user loggin in after is not connected.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors