Troubleshooting Tip: FortiGate HA in Azure stops working with client secret keys expired
| Description | This article describes how to fix the expired client keys for Azure FortiGate HA. |
| Scope | FortiGate in Azure. |
| Solution | The Azure application client key may expire. If so, the FortiGate HA will not work, and FortiGate will be unable to communicate with the Azure portal.
From the FortiGate, the Azure Connector status is down.
diag debug application azd -1 azure {"error":"invalid_client","error_description":"aadsts7000222: the provided client secret keys for app are expired.
This is because the Azure client secret default expiry time is six months.
Every time the old client secret expires, a new client secret must be created to apply to the FortiGate.
The FortiGate HA Azure Connector status will be up once the new secret value is applied. |



