Fortinet white logo
Fortinet white logo

Overview

Overview

With the integration of FortiEDR and Active Directory, when a security policy assigned to a FortiEDR-protected endpoint triggers the “Reset user password” and “Disable user account” Automated Incident Response (AIR) playbooks, FortiEDR sends an API update to the Active Directory server and automatically resets the user password or disables the user account to prevent further misuse of the compromised account.

After the security incident is resolved and the affected endpoint becomes compliant, the administrator must manually re-enable the account.

Overview

Overview

With the integration of FortiEDR and Active Directory, when a security policy assigned to a FortiEDR-protected endpoint triggers the “Reset user password” and “Disable user account” Automated Incident Response (AIR) playbooks, FortiEDR sends an API update to the Active Directory server and automatically resets the user password or disables the user account to prevent further misuse of the compromised account.

After the security incident is resolved and the affected endpoint becomes compliant, the administrator must manually re-enable the account.