| Description |
This article describes how to configure an admin that can only download FortiGate configuration from FortiManager. |
| Scope | FortiManager. |
| Solution |
Least privilege access is a best practice for security hardening configuration that is widely suggested. It means that the admin account is provided with the lowest possible privilege access that does not affect functionality.
In this case, the requirement is admin can only download the FortiGate configuration backup. The following steps can be taken:
Additional tips: if any of these highlighted fields are required, the Manage Device Configurations needs to be at least Read-only, as it is necessary to display the device database. Without it being enabled, the admin user cannot see the device database, as shown in the picture in step 4:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.