Technical Tip: How to provision FortiIdentity Cloud (previously known as FortiToken Cloud)
Description
Related documents:
FortiToken Cloud
FortiToken Cloud - Admin Guide
Scope
FortiToken Cloud, FortiIdentity Cloud.
Solution
Important Note: The service FortiToken Cloud is now named FortiIdentity Cloud.
FortiToken Cloud can be provisioned to FortiGate administrators as well as local firewall users.
First, enable this feature in the CLI:
On FortiOS v6.0.x and earlier:
config system global
set fortitoken-cloud-service enable
end
On FortiOS v7.0.x and later:
config system global
set fortitoken-cloud enable
end
Note: It might be required to log out and log back in for the change to take effect.
To assign FortiToken Cloud two-factor authentication to an administrator:
- Go to: System -> Administrators. The list of administrators appears.
- Select an administrator to edit the configuration (in this example: ftm-cloud).
- Select the toggle to enable Two-factor Authentication. There are two authentication types available: FortiToken(mobile) and FortiToken Cloud.
- Select FortiToken Cloud as the Authentication Type.
- Select 'OK'.

- Go to: User & Device -> User Definition. The list of users appears (Users must have valid email addresses in the configuration).
- Select all the users.
- 'Right-click' on the selected users (in this example: test4 and test6).
- From the drop-down list, select 'Assign Cloud Token'.
- Select 'OK' on the prompt that appears to confirm the cloud token assignment
A detailed guide to activate FortiToken Mobile on a phone can be found in this document: Activating FortiToken Mobile
From v7.4.9, the number of included FortiToken Cloud (FTC) tokens has increased from 2 to 3. Additionally, they no longer expire after one month; instead, they remain valid as long as the connected FortiGate has an active support contract.
Related document:
