Active Directory server
Using Microsoft Active Directory, you can register the firewall as a Windows domain and create an object for it on the primary domain controller.
The firewall can then query user and resource information on the Windows domain network.
You can import Active Directory user groups through the import group assistant. Go to Authentication > Servers and click Import for the Active Directory server. If a user is a member of more than one group, the policies of the first matching group will apply.
When users sign in for the first time, they're added to these groups under these conditions:
Default group: When they're members of a group that hasn’t yet been imported.
Open group: When they're part of an organization unit (OU) but aren’t part of a directory group.