Two Essential Components for FSSO Active Directory Polling on FortiGate
An admin wants users to authenticate once via AD and have their network access controlled without repeated logins. Which feature should be used?
⚠ Common exam trap
Many candidates confuse FSSO with captive portal or LDAP authentication, thinking any AD integration provides single sign-on, but only FSSO (polling or agent-based) captures the Windows logon event to avoid repeated authentication prompts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FSSO with Active Directory polling
FSSO with Active Directory polling allows users to authenticate once at Windows logon, and FortiGate polls the AD domain controllers to capture authentication events. This enables transparent network access control without repeated logins, as the user's identity and group memberships are mapped to firewall policies automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local user authentication
Why it's wrong here
Local user authentication stores credentials directly on the FortiGate, requiring each user to have a manually created account. There is no linkage to Active Directory, so a user's AD login cannot be reused, forcing them to present separate credentials to the firewall. This creates administrative overhead and breaks the single sign-on requirement entirely.
- ✓
FSSO with Active Directory polling
Why this is correct
FSSO with AD polling provides true single sign-on by having the FortiGate (via the FSSO agent) monitor the domain controller's security event log for successful logons. When a user logs into the domain, the agent maps the user name to the workstation's IP address and updates the FortiGate's user list, enabling firewall policies to be applied without any user prompt. This transparently authenticates the user for network access and exactly matches the 'authenticate once via AD' requirement.
- ✗
Captive portal with LDAP
Why it's wrong here
Even with LDAP as the authentication source, a captive portal requires the user to interactively enter their AD credentials in a web browser each time a new session starts. It does not consume the existing domain logon event, so every access attempt involves a separate manual authentication step. Therefore, it fails the 'authenticate once' requirement because the user must repeatedly authenticate rather than getting transparent SSO.
- ✗
SSL VPN with certificate authentication
Why it's wrong here
Certificate-based SSL VPN authenticates a remote client using a private key and certificate, typically stored on a smartcard or hard drive, and doesn't consult Active Directory or inspect AD logon events. It only protects the VPN session, not the full network access, and it still requires user interaction to unlock the certificate or enter a PIN. This is not an SSO solution for AD-authenticated network access and adds certificate lifecycle management complexity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Active Directory for user authentication. They want users to automatically authenticate to the FortiGate without entering credentials when accessing the internet. Which authentication method should the administrator configure?
medium- A.LDAP authentication with captive portal
- B.RADIUS authentication with PAP
- C.Local user authentication
- ✓ D.FSSO with Active Directory polling
Why D: FSSO (Fortinet Single Sign-On) with Active Directory polling allows users to be automatically authenticated to the FortiGate based on their existing Windows domain login. The FortiGate polls the domain controllers for user logon events, mapping the user's IP address to their authenticated identity without requiring any additional credential entry. This meets the requirement of transparent internet access authentication.
Variation 2. An administrator wants to use Fortinet Single Sign-On (FSSO) with Active Directory to transparently authenticate users. Which component is responsible for polling Active Directory for user logon events?
medium- A.Active Directory Domain Controller
- B.FortiGate directly with NTLM authentication
- C.FortiAuthenticator
- ✓ D.FSSO Collector Agent
Why D: The FSSO Collector Agent is the component that polls Active Directory domain controllers for security event logs (specifically event ID 4624 for logon events). It then maps these events to user IP addresses and forwards the authentication information to the FortiGate, enabling transparent user identification without requiring client-side software.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.