Technical Tip: Minimum permissions for FortiGate operations
Description
This article provides the minimum permissions required to perform several common or important operational activities.
Scope
FortiGate v7 and later.
Solution
| Function | Minimum required permissions | Related documents |
| Backup or restore the global configuration | super_admin | |
| View or edit super_admin accounts | super_admin | Technical Tip: Admin cannot see super-admin profile when create another Admin user |
| Backup VDOM configuration | VDOM scope and all read permissions | |
| Restore VDOM configuration | VDOM scope and System Configuration read/write | |
| Backup configuration without super_admin accounts | Read/Write: System -> Administrator Users
All other sections. | Technical Tip: Restrict admin users to take configuration backup only on FortiGate |
| Backup limited configuration | Read/Write: System -> Administrator Users Read: Any required sections. | |
| Trigger a manual FortiGuard update | Read/Write: | Technical Tip: Verifying and troubleshooting FortiGuard updates status and versions |
| Upgrade firmware from the GUI | Read/Write: System -> Maintenance Read: | |
| Manually upgrade the IPS attack engine or AV engine | Read: System -> Configuration | Technical Tip: How to manually upgrade the IPS Engine Technical Tip: How to downgrade or rollback IPS engine or FMWP Database
|
| Log in to the HA secondary device using ‘execute ha manage’ | Read/Write: System -> Maintenance
‘execute’ CLI commands | Technical Tip: Managing individual cluster units with the CLI command 'execute ha manage' |
| Reboot or shut down the device | Read/Write for System -> Configuration | Technical Tip: How to properly shut down or reboot a FortiGate |
| Factory Reset | Read/Write: System -> Administrator Users ‘execute’ CLI commands | |
| Rollback to the previous boot partition | Read/Write: System -> Configuration ‘execute’ CLI commands | Technical Tip: Selecting an alternate firmware for the next reboot
|
| Download debug logs or ‘execute tac report’ | super_admin | |
| Initial troubleshooting steps for dropped traffic | Read:
CLI commands. | Troubleshooting Tip: Initial troubleshooting steps for traffic blocked by FortiGate |
| TFTP firmware load from the boot menu | No administrator permissions required- acts as a 'reset of last resort' in case of system or credential loss.
Requires serial console access during boot as well as FortiGate access to a managed TFTP server. | Technical Tip: Formatting and loading FortiGate firmware image using TFTP |
| Read/Write administrator access when the FortiGate is managed by FortiManager | Read/Write: | Technical Tip: Custom admin profiles show read-only access on FortiGate when managed by FortiManager |
| View SSID Passphrase | Starting FortiOS v7.4.10 and v7.6.5: super_admin
Previous firmware versions: Read/Write: WiFi & Switch
| |
| Enable or disable private-data-encryption | Starting FortiOS v7.2.11, v7.4.6, and v7.6.1:
'config' CLI commands. |
Administrator permissions are configured by creating and assigning an Administrator Profile, see Administrator profiles.

