Fortigate-110C (BACKUP) # get name : BACKUP server : 172.17.36.50 secondary-server : tertiary-server : source-ip : 0.0.0.0 cnid : userPrincipalName dn : DC=domain,DC=ads port : 389 type : regular username : CN=ldap,OU=Dienstkonten,OU=Benutzer,OU=Gellen,DC=domain,DC=ads password : * group-member-check : user-attr secure : disable password-expiry-warning: disable password-renewal : disable member-attr : memberOf
 We had to create the user on the FG with the full principalname as well !!!
 If I create a user like m.name@domain.com and link it to the LDAP server with configured Common Name Identifier " userPrincipalName" , then it works!
 We had to create the user on the FG with the full principalname as well !!!
 If I create a user like m.name@domain.com and link it to the LDAP server with configured Common Name Identifier " userPrincipalName" , then it works!
					
				
			
			
				
			
			
				
			
			
			
			
			
			
		 You already needed to do that for assigning FortiToken to AD Users......Now I come to know to know that setting CNID to userPrincipalName dosent either work..
 
 You already needed to do that for assigning FortiToken to AD Users......Now I come to know to know that setting CNID to userPrincipalName dosent either work..
					
				
			
			
				Ahead of the Threat. FCNSA v5 / FCNSP v5
Fortigate 1000C / 1000D / 1500D
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2711 | |
| 1416 | |
| 810 | |
| 727 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.