Skip to main content
kwcheng__FTNT
Staff
Staff
July 24, 2025

Technical Tip: Understanding the log message 'FortiToken Status Change'

  • July 24, 2025
  • 0 replies
  • 156 views
Description This article describes the typical circumstances behind the 'FortiToken Status Change'.
Scope FortiAuthenticator.
Solution

Event ID 10103 refers to an event log entry indicating the status of the FortiToken had changed. This log only relates to any FortiToken status which is caused by an authorized FortiAuthenticator administrator from GUI.

 

The sample system event message will look like below:

 

An administrator unlocked a FortiToken

 

date=2025-07-17 time=20:13:33+0000 oid=8888 logid=10103 cat="Event" subcat="Admin Configuration" level="notice" nas="" action="" status="" msg="Unlocked FortiToken "FTKMOBXXXXXXXXXX"" user="admin"

 

If the administrator is interested in knowing who enabled/disabled the FortiTokens, it can be viewed under Log Access -> Logs -> filter '10103' by tracing the 'user' field.

 

10103.png

More on event IDs and their descriptions can be found in GUI under Logging -> Log Access -> Log Types.