Technical Tip: Restricted administrators on FortiAuthenticator cannot manage tokens after the upgrade
Description
This article describes an issue encountered when upgrading to FortiAuthenticator v8.0.
Scope
FortiAuthenticator.
Solution
Restricted Admin functionality worked as expected before the upgrade, based on the FortiAuthenticator admin profile integration guide, Admin Profiles.
The pre-upgrade admin profile test1 on FortiAuthenticator had the following permissions configured:
Figure 1. Permission sets:

After upgrading to FortiAuthenticator v8.0, the following error has been observed when trying to assign a token to users.
Figure 2. Error assigning token:

Â
Even with full read-write permissions assigned to this admin profile, the behavior remains unchanged.
Note: For custom 'User and Device' profile make sure custom profile must have read-write permission and in permission set 'can view FortiToken' is included in order to view the Tokens.
Custom profile:

Permission set:

Solution:
This is a known issue tracked under engineering ticket 1224409: Restricted admins cannot manage tokens after upgrade. Known issues (FortiAuthenticator v8.0.1).
This issue is resolved in version 8.0.2: Release notes.
