Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jr14
New Contributor III

How to allow LDAP user to change password or renew expired password via ZTNA

 

I would like to know if some have done something similar ?

How to enable a user to change password or renew expired password using ZTNA, i have seen some post but for ssl vpn or ipsec 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-allow-LDAP-user-to-change-password-...

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-LDAP-user-to-renew-expired-password...

 

FortiClient #ZTNA FortiGate 

5 REPLIES 5
AEK
SuperUser
SuperUser

I don't see the relationship with ZTNA because FortiClient still connects to Telemetry even if your password has expired, and you can still open your ZTNA apps even if your password is expired.

So to change the password while you are off-fabric then you may just open a ZTNA app that helps you do so, like your Corp's OWA or any other method.

Unless you enabled periodic user re-authentication in EMS settings. Is this what you mean?

AEK
AEK
jr14
New Contributor III

For example, we use ztna to access to the internal resource, all users are part of the domain, we have different services that use AD credential, but the credential expires after a time in the AD, so, users are unable to use their credential, I want to use ZTNA to allow the users update their password in the domain. 

AEK

I understand that when password expires the user is unable to use its credentials to access the app.

But the FCT telemetry is still connected, and ZTNA access is not affected.

As per my knowledge I don't see how we can use ZTNA to change the AD password. I think the only way to do is to change the password via the traditional way, for example some app like OWA or any other app that allows you change it, or if your off-fabric clients have connection to AD via ZTNA I guess they will be automatically invited to change password on expiration.

AEK
AEK
jr14
New Contributor III

Yes, that is the idea that i am looking for, how to use ZTNA to connet to a domain server and let the user update the password

AEK

This one I don't have the official procedure to achieve it and didn't test it before.

Hope some more experienced member can help.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors