Technical Tip: FTM provisioning error using LDAP sync rule when importing as local user
Description
This article describes an issue encountered when synchronizing users as Local using a Remote User Sync Rule after upgrading to FortiAuthenticator v6.6.6.
Scope
FortiAuthenticator.
Solution
After upgrading to FortiAuthenticator v6.6.6, synchronizing users as Local Users with OTP method assignment = FortiToken Mobile using a Remote User Sync Rule fails - users cannot be imported into FortiAuthenticator.
Steps to reproduce it:
-
Create a new Remote User Sync Rule.
-
Navigate to User Management -> Remote User Sync Rule -> Create New.
-
Figure 1. Remote User Sync Rule
- After creating the sync rule, run it manually to initiate synchronization. The logs indicate that the rule executes successfully; however, the user 'prove123' is not imported into the Local User database on FortiAuthenticator.
Figure 2. Manual Sync
Raw Logs on FortiAuthenticator show more details of this error:
date=2025-09-23 time=14:02:08+0000 oid=34164 logid=30303 cat="Event" subcat="System" level="information" nas="" action="" status="" msg="Successfully synced (rule: Sync rule) with win2019-ldap on Tue Sep 23 16:02:08 2025." user=""
date=2025-09-23 time=14:02:08+0000 oid=34163 logid=30303 cat="Event" subcat="System" level="information" nas="" action="" status="" msg="Found 0 modified FTC users for sync (rule: Sync rule) with win2019-ldap (x.x.x.x)" user=""
date=2025-09-23 time=14:02:08+0000 oid=34162 logid=30303 cat="Event" subcat="System" level="information" nas="" action="" status="" msg="Cannot add user from LDAP server win2019-ldap because of this error: Unable to import valid token for prove123 (rule: Sync rule)" user=""
date=2025-09-23 time=14:02:08+0000 oid=34161 logid=10003 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Delete" status="" msg="Deleted Local User: prove123" user="admin"
date=2025-09-23 time=14:02:08+0000 oid=34160 logid=10003 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Delete" status="" msg="Deleted Local User Profile: prove123" user="admin"
date=2025-09-23 time=14:02:07+0000 oid=34159 logid=30908 cat="Event" subcat="System" level="information" nas="" action="" status="" msg="smtp mail: send to prove123@gmail.com via localhost:25 ok" user="admin"
date=2025-09-23 time=14:02:07+0000 oid=34158 logid=10002 cat="Event" subcat="Admin Configuration" level="information" nas="" action="Edit" status="" msg="Edited Local User: prove123 (changed fields: password)" user="admin"
Solution:
This is a known issue reported with engineering ticket 1192002 and it will be resolved in FortiAuthenticator version 6.6.7 and 8.0.
