Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BKP09
New Contributor

FortiNAC- Role Assignment Issue with Active Directory Integration

I deployed a FortiNAC VM and configured policies to assign users to VLANs based on their department. To achieve this, I used an Active Directory attribute to assign a role to each user, which FortiNAC then parses via AD synchronization.

image_2025-03-27_140755044.png

In the User Accounts page (first image), I can see that the correct role "112" has been assigned to the user. However, in the Hosts section (second image), the user’s laptop—where the same user is logged in—does not have the expected user role assigned (it should be 112 but is missing).

d0565a5f-7683-4aec-9035-59d83a1c4028.png

This discrepancy prevents proper VLAN assignment. How can I troubleshoot and ensure that the role is correctly applied to the host?

5 REPLIES 5
ebilcari
Staff
Staff

When the host is registered to the same user, the role should be inherited. Based on the second screenshot, which is a bit blurry it appear like the host is not registered to this user, that's why it doesn't have the role.

You can also check this article and the troubleshooting tips.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
BKP09
New Contributor

Sorry for the blurry image. the logged on users is the one that appears to have attribute 112 on the User Role (first image)

image_2025-03-27_144449248.png

Thank you for the article but i have already saw it and this is the exact process i followed.
What do you mean by registered? the user logged on the device with the Host name, shouldn't this mean that the user will inherit the atribute?

ebilcari

As you can see, the host is missing the 'Registered To' information, which means that this host is registered as device and not tied to a user.

If dot1x is used in this case, you can use the dot1x auto registration feature, it will register the host directly to the user during the initial authentication.

In case you want to apply the policy based on the 'Logged On User' information, you can use a UHP that checks the role of the user as shown below:

UHP-user-role.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
BKP09
New Contributor

Thank you for your prompt response. I want to apply the policy based on the below configured UHP:

 

image_2025-03-27_151032495.png

Auto registration is off. DO you suggest enabling it and this will be the solution? I cant remember the reason i disabled it n the first place, since this is something i tried before.

ebilcari

The only limitations is that the "Registered To" field is populated only during host registration and is not updated later on if the user change. So in cases when the same host is used by different users that require different policies, this may be a limitation.

The rule above should match. To get a better overview of matching conditions done by FNAC, you can go to the host and by r-click choose 'Policy Details' and than Debug Log.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors