I just went through figuring this out today with some trial and error.
Here is what worked for my setup. I'm on FortiOS v6.0.4 build0231 (GA)
This is for Azure AD with no local domain sync enabled. Make sure domain
services is set up and ldaps is con...