FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
kwcheng__FTNT
Article Id 425792
Description This article describes the typical circumstances behind the 'Logs user portal password reset event'.
Scope FortiAuthenticator.
Solution

Event ID 50003 refers to an event log entry that records a user portal password reset event. This event applies only to the FortiAuthenticator administrative GUI login ('Forgot password?' option) and is not intended for password resets of remote RADIUS users (e.g., VPN authentication).

 

The sample system event message will look like below:

 

date=2026-01-08 time=14:32:55+0000 oid=8888 logid=50003 cat="Event" subcat="User Portal" level="information" nas="" action="" status="" msg="Password reset requested by user "test" (IP: 192.168.1.100, Browser: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.0.0)" user="test"

 

Any attempt to reset the password for other purposes might fail with the following sample event:

 

date=2026-01-08 time=14:32:55+0000 oid=8888 logid=50003 cat="Event" subcat="User Portal" level="error" nas="" action="" status="" msg="Can't decrypt password reset data parameter due to error: Invalid base64-encoded string: number of data characters (265) cannot be 1 more than a multiple of 4" user=""

 

Do consider using the Self-service portal to reset a remote user's password instead of the 'Forgot password?' option on the FortiAuthenticator GUI login page.

 

These logs can be viewed under Log Access -> Logs -> filter '50003'.