Created on
07-24-2025
12:28 AM
Edited on
07-30-2025
02:16 AM
By
Anthony_E
| Description | This article describes the typical circumstances behind the 'FortiToken Status Change'. |
| Scope | FortiAuthenticator. |
| Solution |
Event ID 10103 refers to an event log entry indicating the status of the FortiToken had changed. This log only relates to any FortiToken status which is caused by an authorized FortiAuthenticator administrator from GUI.
The sample system event message will look like below:
An administrator unlocked a FortiToken
date=2025-07-17 time=20:13:33+0000 oid=8888 logid=10103 cat="Event" subcat="Admin Configuration" level="notice" nas="" action="" status="" msg="Unlocked FortiToken "FTKMOBXXXXXXXXXX"" user="admin"
If the administrator is interested in knowing who enabled/disabled the FortiTokens, it can be viewed under Log Access -> Logs -> filter '10103' by tracing the 'user' field.
More on event IDs and their descriptions can be found in GUI under Logging -> Log Access -> Log Types. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.