FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
preznik_FTNT
Staff
Staff
Article Id 194900

Description

 

The article describes how to unlock a 'locked out' user who is locked out again during the next password expiration check.

 

Scope

 

FortiAuthenticator.

 

Solution

 

When an administrator unlocks a 'locked out' user without changing the user's password, the user will be locked out again during the next password expiration check, which runs every 24 hours.


There are two ways to resolve this problem.

 

Either:

 

  1. Disable 'Enable password expiry' under Authentication -> User Account Policies -> Passwords -> User Password Change Policy.

 

KBedit.png
Or:

 

  1. Be sure to change a user's password after unlocking the user. See the related KB article for details.

  2. To view the locked-out users, go to Monitor -> Authentication -> Locked-out Users.

     


Lockout_Users.jpg

 

  1. To unlock a user from the list, select the user and select Unlock. The list can be refreshed by selecting Refresh, and searched using the search field.

  2. Note that there is no command to unlock the locked-out user like there is in FortiGate. The user must be unlocked in the GUI by navigating to Monitor -> Authentication -> Locked-out Users.

 

Related article:
Technical Tip: Force password change for local users
Locked-out users 
Troubleshooting Tip: How to debug FortiAuthenticator Services