Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ck8882
New Contributor II

Configuring least privileges for LDAP admin account authentication in Active Directory

HI

 

May i know why FortiGate integrated to LDAP Active Directory AD that account require below permission? could we just select Read only?

 

In Permissions list, select the following:

  • Change password
  • Reset password

In Property-specific.select the following:

  • Write lockoutTime
  • Read lockoutTime
  • Write pwdLastSet
  • Read pwdLastSet
  • Write UserAccountControl

thanks

2 REPLIES 2
asengar
Staff
Staff

Hi @ck8882 

Thanks for posting your query.

Can I know where are you seeing these options in AD ?

Kindly refer the below document for setting the LDAP server in Fortigate

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-FortiGate-to-use-an-LDAP-...

 

Request you to kindly elaborate your issue/query you have.

 

Regards

@bhishek
ck8882
New Contributor II

HI @bhishek

 

The document is issued from fortinet document page. Please find URL link below 

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/110412/configuring-least-privileges-for...

 

The link you shared is to show step how to integrate to LDAP server. What i would like to understand  is what permission needed and reason in Active Directory for LDAP intergrate to fortigate.

 

Thanks

 

 

Labels
Top Kudoed Authors