Troubleshooting Tip: LDAP user not synchronizing to FortiToken Cloud
Description | This article describes a possible case of why an LDAP user is not synchronizing to FortiToken Cloud. |
Scope | FortiGate, FortiToken Cloud. |
Solution | The two-factor-filter option in the LDAP setting is the filter string that controls which Active Directory users will be synchronized to FortiToken Cloud for two-factor authentication.
 Users are automatically synchronized to the FortiToken Cloud portal, however, the synchronization process can be manually triggered by running the below command on the FortiGate:   To verify the list of users that are synchronized to FortiToken Cloud, run the given command:   If the expected users are not added to FortiToken Cloud, run the following commands to check the FortiGate connectivity to the FortiToken Cloud server:   If the FortiToken Cloud service status is verified connected and ready, run the below debug and trigger a manual sync:   The debug output will show the sync status and the number of users that are successfully synchronized or failed to synchronize.  ![]()  If there are LDAP users that are not getting synchronized, the 'fortitoken-cloud debug' will also show if the user was skipped during synchronization. From the given output below, the LDAP users were skipped due to missing or not valid email assignments.  ![]()  Ensure that the user has a proper email address assigned on the AD server as this is where the FortiToken Cloud activation email will be sent. |


