Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kdot
New Contributor II

FortiNAC - Administrator accounts with privileges to create Guest Wifi accounts

I realize the following is a not so great idea but would like to know if this is even possible since management may require it.

Is it possible to give all users with a valid AD account permissions to create pre-provisioned guest wireless accounts in FortiNAC? 

Based on the following snippet from the FNAC admin guide, I can't use the AD Domain Users group: 
"The domain users group cannot be used to set administrator privileges because user details for users in that group are not populated in FortiNAC when a directory synchronization is done."

 

So, before I ask our AD admin to create a new group named something other than Domain Users and add all user accounts to it, I'm posting to see if this is even possible. 



1 Solution
ebilcari

I don't think this approach will scale well or be effectively managed. Guest accounts should be handled by a few designated accounts.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

4 REPLIES 4
ebilcari
Staff
Staff

Is the requirement to allow AD users to register their devices in BYOD style or actually create guest accounts to be used for other users?

A similar approach could be to use the Self Registration and put these AD users as sponsors to approve the guests through email links, without having to login in FNAC:

 

guest-approval.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
kdot
New Contributor II

@ebilcari - Thank you for your response. 

The proposed requirement is to allow all company employees with a valid AD account to access FortiNAC > Users & Hosts > Guests & Contractors, and Add guest accounts (for others) before the guest arrives onsite.


When the guest arrives onsite, they choose an option (we'll call it "preconfigured guest") which is linked to the "Primary Guest Login" in the portal. The guest will be prompted for username and password (provided in advance) instead of requesting access via self-registration. 

Hopefully this clarifies the requirement / question.

 

 

ebilcari

I don't think this approach will scale well or be effectively managed. Guest accounts should be handled by a few designated accounts.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
kdot
New Contributor II

Thank you @ebilcari 

I agree the approach is not ideal. I'm going to work with our AD team to test it out just to see if it's technically possible.

The old saying may apply here: "Just because you can do something..."

Thanks again for your feedback.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors