Troubleshooting Tip: FortiAuthenticator error: Cannot add user from LDAP server
| Description | This article explains how to fix the FortiAuthenticator error: Cannot add user from LDAP server DC-boss because of this error: Failed to import user 'administrator' (rule: TAC-RULE), Mobile number is required if TFA method is SMS.
![]() |
| Scope | FortiAuthenticator. |
| Solution | In the Remote User Sync Rules, 'SMS' as an OTP method has been selected. For using the SMS token code, the user’s mobile number attribute must be specified.
If the mobile number is in the wrong format or is missing, then users will not be imported from the LDAP server into FortiAuthenticator.
Under the Remote User Sync Rules settings -> LDAP User Mapping Attributes, the mobile number attribute must be defined. For example:
Mobile number: mobile
In Active Directory, user's mobile number attribute must be in this format '+ [international number] [mobile number]'.
It is necessary to run the Remote User Sync Rule manually, and this time, it is necessary to see that the username 'administrator' has been imported from the LDAP server with a mobile number for delivering the Token code.
 
It is possible to verify that in FortiAuthenticator GUI logs:
It can be checked in the Debug Logs on FortiAuthenticator:
Related documents: |







