FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
kwcheng__FTNT
Article Id 401937
Description This article describes the typical circumstances behind the 'FortiToken Status Change'.
Scope FortiAuthenticator.
Solution

Event ID 10103 refers to an event log entry indicating the status of the FortiToken had changed. This log only relates to any FortiToken status which is caused by an authorized FortiAuthenticator administrator from GUI.

 

The sample system event message will look like below:

 

An administrator unlocked a FortiToken

 

date=2025-07-17 time=20:13:33+0000 oid=8888 logid=10103 cat="Event" subcat="Admin Configuration" level="notice" nas="" action="" status="" msg="Unlocked FortiToken "FTKMOBXXXXXXXXXX"" user="admin"

 

If the administrator is interested in knowing who enabled/disabled the FortiTokens, it can be viewed under Log Access -> Logs -> filter '10103' by tracing the 'user' field.

 

10103.png

More on event IDs and their descriptions can be found in GUI under Logging -> Log Access -> Log Types.