Creating an administrator that can be authenticated by an LDAP server
You can configure a least privileges user account (read access only) in Active Directory for FortiProxy admin users which can be authenticated by an LDAP server:
- Configure an LDAP server. See Create or edit an LDAP server. Alternatively, use the
configure user ldap
command. - To allow only a particular group of members to login to the FortiProxy as administrators, configure an LDAP user group under User & Authentication > User Group to limit the access. Alternatively, use the
configure user group
command. - Configure an administrator to authenticate with the LDAP server under System > Administrators. See Administrators. Alternatively, use the
command.config system admin
-
Verify the configuration is successful by accessing the FortiProxy GUI using the credentials of the configured LDAP user(s).