ortiGate on Google Cloud Platform (GCP) is a little different from traditional FortiGate deployments in that it integrates with GCP's native features, like OS Login.
Here's a breakdown of your concerns:
-
OS Login Integration: The integration of FortiGate VM with Google Cloud's OS Login feature is likely to facilitate user management by aligning with GCP's security practices. As of there's no direct method on the FortiGate VM to disable OS Login once it's enabled at the GCP level. However, it's crucial to note that OS Login is a GCP-level feature and its behavior is controlled from the GCP console, not the FortiGate itself.
-
Super Admin: Yes, typically, the creator of the VM or the deployment will have the "super_admin" role. This role has the highest set of privileges on the FortiGate. The assignment of the "super_admin" role is usually based on the context of deployment and the user who initiates the deployment.
-
Documentation: Fortinet's documentation is quite extensive. You'd want to check the Fortinet Documentation Library for specifics on how FortiGate VM integrates with GCP. The guide should provide insights into role assignments, integrations, and other VM-specific behaviors.
Fortinet Documentation Library
Remember that cloud documentation can change based on versions and feature updates, so always refer to the documentation associated with your specific FortiOS version and the FortiGate VM version for GCP.
If OS Login does not align with your organization's policies, or if you find it introduces unnecessary complexity, it's crucial to liaise with your security team and Fortinet support. They can provide guidance tailored to your deployment, version, and specific security requirements.
Lastly, always consider testing any changes or configurations in a non-production environment to ensure there are no unintended consequences, especially when working in a cloud environment where certain features might have dependencies or integrations that aren't immediately obvious.