Fortinet black logo

EMS Administration Guide

Adding endpoints using an Active Directory domain server

Adding endpoints using an Active Directory domain server

Endpoints can be manually imported from an AD server. You can import and synchronize information about computer accounts with an LDAP or LDAPS service. You can add endpoints by identifying endpoints that are part of an AD domain server.

An instructional video on how to add a domain is available in the Fortinet Video Library.

You can add the entire domain or an organizational unit (OU) from the domain.

  1. Go to Endpoints > Manage Domains > Add. The Domain pane displays.

  2. Configure the following options:

    IP address/Hostname

    Enter the domain's IP address or hostname.

    Port

    Enter the port number.

    Distinguished name

    Enter the distinguished name (optional).

    Bind type

    Select the bind type: Simple, Anonymous, or Regular. When you select Regular, you must enter the Username and Password.

    Username

    Available when Bind Type is set to Regular. Enter the username.

    Password

    Available when Bind Type is set to Regular. Enter the user password.

    Show Password

    Available when Bind Type is set to Regular. Turn on and off to show or hide the password.

    LDAPS connection

    Turn on to enable a secure connection protocol when Bind Type is set to Regular.

    Sync every

    Enter the sync schedule between FortiClient EMS and the domain in minutes. The default is ten minutes.

  3. Click Test to test the domain settings connection.
  4. If the test is successful, select Save to save the new domain. If not, correct the information as required, then test the settings again.
note icon

After importing endpoints from an AD server, you can edit the endpoints. These changes are not synced back to the AD server.

Adding endpoints using an Active Directory domain server

Endpoints can be manually imported from an AD server. You can import and synchronize information about computer accounts with an LDAP or LDAPS service. You can add endpoints by identifying endpoints that are part of an AD domain server.

An instructional video on how to add a domain is available in the Fortinet Video Library.

You can add the entire domain or an organizational unit (OU) from the domain.

  1. Go to Endpoints > Manage Domains > Add. The Domain pane displays.

  2. Configure the following options:

    IP address/Hostname

    Enter the domain's IP address or hostname.

    Port

    Enter the port number.

    Distinguished name

    Enter the distinguished name (optional).

    Bind type

    Select the bind type: Simple, Anonymous, or Regular. When you select Regular, you must enter the Username and Password.

    Username

    Available when Bind Type is set to Regular. Enter the username.

    Password

    Available when Bind Type is set to Regular. Enter the user password.

    Show Password

    Available when Bind Type is set to Regular. Turn on and off to show or hide the password.

    LDAPS connection

    Turn on to enable a secure connection protocol when Bind Type is set to Regular.

    Sync every

    Enter the sync schedule between FortiClient EMS and the domain in minutes. The default is ten minutes.

  3. Click Test to test the domain settings connection.
  4. If the test is successful, select Save to save the new domain. If not, correct the information as required, then test the settings again.
note icon

After importing endpoints from an AD server, you can edit the endpoints. These changes are not synced back to the AD server.