Hi,
we got one customer company running for some time using FAC to authenticate 2 Factor Users in a AD domain forest with about 20 sub-domains. We use realms which match the domain name for the users like samaccountname@company.at or samaccountname@company.uk and so on to match the different domains.
Everything is fine with that - but for the ease of use, we would like to globally switch user logon information to using UPN Names where (UPN=external email-address). This would need me to de-configure realms on the FAC an I am not sure, how this would work as using the "@" sign now defines which realm to use?
Can I skip all realms and just use global groups? Has anyone tried something like this yet?
Br,
Roman
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.