Created on
05-19-2022
06:21 AM
Edited on
12-30-2024
02:03 AM
By
Jean-Philippe_P
Description |
This article describes the scenario when the admin access is lost to the FortiGate, and the possibility to recover access with a maintainer account (reset password) exists. However, this procedure will not allow changing the two-factor authentication (for example: in case FortiToken Mobile is lost). |
Scope | FortiGate. |
Solution |
If the unit is configured to connect to FortiCloud and Management Connectivity is UP, there is a possibility to add a new admin account from FortiCloud.
The second requirement for the procedure is to have a FortiCloud subscription (the Configuration management is not included in the free version). If the above conditions are met, it is possible to create a new admin user in the FortiCloud management and push the configuration to the FortiGate.
This procedure will regain local access and can modify the original admin account.
The guide on how to change the config on the unit: Config.
Select FortiGate Cloud -> Select the device -> Group Management -> Run script.
To add a new admin create and execute a new script: Script.
Use the following syntax:
config system admin
If the FortiGate is running a multi-VDOM configuration, use the following syntax instead:
config global
Alternatively, enabling the SSO FortiCloud administration access makes it possible to regain access to the FortiGate. Use the following syntax:
config system global set admin-forticloud-sso-login enable set admin-forticloud-sso-default-profile "super_admin" end
If the unit is not yet added to the FortiCloud, but there is physical access to the unit, it is possible to add it with the FortiCloud key: Deployment. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.