I realize the following is a not so great idea but would like to know if this is even possible since management may require it.
Is it possible to give all users with a valid AD account permissions to create pre-provisioned guest wireless accounts in FortiNAC?
Based on the following snippet from the FNAC admin guide, I can't use the AD Domain Users group:
"The domain users group cannot be used to set administrator privileges because user details for users in that group are not populated in FortiNAC when a directory synchronization is done."
So, before I ask our AD admin to create a new group named something other than Domain Users and add all user accounts to it, I'm posting to see if this is even possible.
Solved! Go to Solution.
I don't think this approach will scale well or be effectively managed. Guest accounts should be handled by a few designated accounts.
Is the requirement to allow AD users to register their devices in BYOD style or actually create guest accounts to be used for other users?
A similar approach could be to use the Self Registration and put these AD users as sponsors to approve the guests through email links, without having to login in FNAC:
@ebilcari - Thank you for your response.
The proposed requirement is to allow all company employees with a valid AD account to access FortiNAC > Users & Hosts > Guests & Contractors, and Add guest accounts (for others) before the guest arrives onsite.
When the guest arrives onsite, they choose an option (we'll call it "preconfigured guest") which is linked to the "Primary Guest Login" in the portal. The guest will be prompted for username and password (provided in advance) instead of requesting access via self-registration.
Hopefully this clarifies the requirement / question.
I don't think this approach will scale well or be effectively managed. Guest accounts should be handled by a few designated accounts.
Thank you @ebilcari
I agree the approach is not ideal. I'm going to work with our AD team to test it out just to see if it's technically possible.
The old saying may apply here: "Just because you can do something..."
Thanks again for your feedback.
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.