Skip to main content
smkml
Staff
Staff
June 10, 2026

Technical Tip: Auto Enrollment behavior on FortiPortal

  • June 10, 2026
  • 0 replies
  • 27 views

Description


This article describes on expected behavior of FortiPortal using Auto Enrollment feature.

40434df6.png


Scope

FortiPortal and FortiManager.

Solution

  1. Before proceeding to perform the auto enrollment, from the FortiManager side, on each ADOM that needs to be added, create metadata variables for fpc_site, fpc_org, and fpc_org_email, and make sure the default values are filled out.

    For example: In FortiManager, there are 3 ADOMs, named as root, LDC, and SRI.

66a480ae.pngd3d9bded.png1027a947.png


Each ADOMs consist number of managed FortiGates.

fc47a4aa.png


After auto enrollment in FortiPortal, confirm the organizations created are correct as the same metadata variables value for fpc_org in FortiManager. Notice the Sites created are also the same as fpc_site.

87cfdbf6.png135ee65c.pngbec2241e.png30c6ed68.png


  1. Auto enrollment is only executed at the time a FortiManager instance is initially added to FortiPortal. It is not triggered during subsequent FortiManager polls, including manual 'Poll Now' operations.

  2. During a poll, metadata variables on managed devices may have been modified or removed. To avoid unintended removal of devices from FortiPortal, which could result from accidental deletion of metadata variables, auto-enrollment logic has intentionally been excluded from the polling workflow.

  3. Consistent with the behavior described above, new Site creation based on FortiManager ADOM changes is also not supported during polling operations. This limitation applies under the same design rationale.

  4. Auto enrollment currently applies only to FortiGate devices (including VDOMs). FortiSwitch and FortiAP managed by a FortiGate are not included in the auto-enrollment process.