Technical Tip: Joining FortiGate to FortiGate Cloud without the FortiCloud master account using an IAM user
| Description | This article describes methods to connect a FortiGate to FortiGate Cloud without using the master account. It is best practice to restrict the use of the FortiCloud master account credential. |
| Scope | FortiGate Cloud. |
| Solution | To join the device to FortiGate Cloud without the master account credentials, the device must first be registered to FortiCloud and provisioned to FortiGate Cloud using the FortiGate Cloud portal. An IAM user must be used to provision these devices.
The administrator should log in to FortiGate Cloud using an IAM user, following Logging in as an IAM user.
If an administrator does not have an associated IAM user, another IAM user with FortiGate Cloud and user management permissions can create an appropriate one, see IAM users.
See this document: Cloud provisioning v25.4.a.
If the device is not yet present in the Inventory, select 'Import FortiGate' using the FortiCloud or FortiDeploy key and select 'Provision after Import'.
If the device is already registered to FortiCloud, a key is not needed. Select the unit and select 'Provision to FortiGate Cloud'.
The device is provisioned in the currently selected FortiGate Cloud region.
After provisioning, join the device to FortiGate Cloud using one of the following:
config system central-management set type fortiguard end This method only works successfully once per FortiDeploy key. If the unit is later removed from FortiGate Cloud and then repovisioned, use the FortiCloud key (printed on a sticker on the top of the device) or see the following methods.
config system central-management set type fortiguard end
config system central-management set type fortiguard end
Each of these methods requires the device to be already provisioned in the FortiGate Cloud portal, and the device must have DNS and Internet connectivity. Organizations that are managing assets on behalf of several clients may benefit from leveraging IAM users in conjunction with FortiGate Cloud Organizations. See this document: Organization Portal. |



