You can manually import endpoints from an AD server. You can import and synchronize information about computer accounts with an LDAP or LDAPS service. You can add endpoints by identifying endpoints that are part of an AD domain server.
A video on how to add a domain is available in the Fortinet Video Library.
You can add the entire domain or an OU from the domain.
EMS does not support importing subdomains if you have already imported the parent domain in to EMS.
To add endpoints using an AD domain server:
- Go to Endpoints > Manage Domains > Add. The Domain pane displays.
- Configure the following options:
Enter the domain server IP address or hostname.
Enter the port number.
Enter the distinguished name (DN) (optional). You must use only capital letters when configuring the DN.
Available when Bind type is set to Regular. Enter the username.
Available when Bind type is set to Regular. Enter the user password.
Available when Bind type is set to Regular. Turn on and off to show or hide the password.
Enable a secure connection protocol when Bind Type is set to Regular.
Enter the sync schedule between FortiClient EMS and the domain in minutes. The default is ten minutes.
- Click Test to test the domain settings connection.
- If the test is successful, select Save to save the new domain. If not, correct the information as required, then test the settings again.
After importing endpoints from an AD server, you can edit the endpoints. These changes do not sync back to the AD server.