AUTH AD AND NAC

Iqbal Hermawan Lv1Posted Feb-12-2026 19:52

I would like to ask. Our IAG device has already been integrated with Active Directory (AD) and NAC. However, for the online users, only NAC users are being detected. The AD users are not appearing in the online user list.
Previously, the AD users were visible, but after one day they disappeared again.
Could you please advise on how to make the AD users consistently appear as online users?
Thank you in advance for your support.

By solving this question, you may help 633 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Muhammad Abid Lv2Posted Feb-13-2026 13:51
  
On Sangfor IAG, this usually happens when AD SSO mapping stops syncing, so only NAC-authenticated users remain visible.

Check AD Server status (User Authentication → AD) → make sure it’s Connected.
Verify SSO method (AD Agent / WMI / LDAP) is running properly.
Restart the AD SSO service/agent on the AD server.
Check User IP–Username binding aging time (increase binding timeout).
Make sure users are generating traffic (IAG only shows active/bound users).

If users disappear after one day, it’s usually:


Humayun Ahmed Lv3Posted Feb-13-2026 12:23
  
There is 3 common root cause causing certain AD users to be unable to synchronize with Sangfor IAG online user:
1. Check if there are any local users available, if yes, it will not sync again as the AD users
2. Check the authentication policy if the target object is the user.
3. Check on the AD user group, Sangfor IAG got limited on the maximum nested AD user group that can synchronize.

I Can Help:

Change

Moderator on This Board

917
183
94

Started Topics

Followers

Follow

Board Leaders