FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
Somashekara_Hanumant
Staff & Editor
Staff & Editor
Article Id 410010
Description This article explains how to create a custom admin user with limited permissions on FortiAuthenticator.
Scope FortiAuthenticator
Solution

Follow the steps below to create a custom admin user with limited permissions:

 

  1. Login as a Super Admin user.
  2. Create an custom administrator profile.

System -> Administration -> Admin Profiles -> Create new.

 

fac_admin_profile.JPG

 

 

  1. Create an Administrator account.

 

 

Go to Authentication -> User Management -> Local Users -> Create new.

 

Under Role, select Administrator and select the previously created custom profile (as per the image below). After selecting the 'Save' option, FortiAuthenticator will ask to verify the information. The user needs to provide the 'super_admin' password.

 

fac_admin_account.JPG

 

fac_admin_account_verify.JPG

 

 

  1. Verify the new account.

 

  • Login from a different browser using the 'custom_admin' user.
  • The user can only see the allowed menus and there is no option to create any local users, since the permissions are set to read-only.

 

fac_admin_account_login.JPG