| Description | This article describes the typical circumstances behind the 'Logs user portal password reset event'. |
| Scope | FortiAuthenticator. |
| Solution |
Event ID 50003 refers to an event log entry that records a user portal password reset event. This event applies only to the FortiAuthenticator administrative GUI login ('Forgot password?' option) and is not intended for password resets of remote RADIUS users (e.g., VPN authentication).
The sample system event message will look like below:
date=2026-01-08 time=14:32:55+0000 oid=8888 logid=50003 cat="Event" subcat="User Portal" level="information" nas="" action="" status="" msg="Password reset requested by user "test" (IP: 192.168.1.100, Browser: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.0.0)" user="test"
Any attempt to reset the password for other purposes might fail with the following sample event:
date=2026-01-08 time=14:32:55+0000 oid=8888 logid=50003 cat="Event" subcat="User Portal" level="error" nas="" action="" status="" msg="Can't decrypt password reset data parameter due to error: Invalid base64-encoded string: number of data characters (265) cannot be 1 more than a multiple of 4" user=""
Do consider using the Self-service portal to reset a remote user's password instead of the 'Forgot password?' option on the FortiAuthenticator GUI login page.
These logs can be viewed under Log Access -> Logs -> filter '50003'. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.