 
					
				
			
			
				
			
			
				
			
			
			
			
			
			
		I created the group a week ago now, so I would think they would have shown up by now.Do you have a group filter on the FSSO agent, that maybe excludes this group? If it was newly created and has not been added there, then it won' t show up - only if you really show all groups to the FGT - which is not best practice, as you send some additional mem&cpu load to your Fortigate. br, Roman
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
If your FGT doesn' t need to see all the groups, I would recommend you use the group filtering, and eliminate all the added baggage. Only pass the groups the FGT needs to see. Also helps a bit when debugging via CLIWhich groups do I want it to see? Only ones that have a specific user policy applied to them?
Can you do a: diag deb auth fsso list-users and have a look if the group shows up there with a user, that belongs to the group? I also remember once having had troubles with group names or DNs that were too long in total... They just didn' t show up correctly - maybe this info can also help you ... br, RomanOk. When I do that, I see the user and it does show he is a member of the group I created that is not showing up.
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.