I am facing issue in FortiPAM email approval workflow. We don't have any mail server in our organization. We use Microsoft Mail Exchange Server for mail service. Let's say, there are user1(approver), user2(requester) and user3. If user2(requester) request a secret, a mail sent to approver inbox. If approver click "approve button", it created new mail. but it doesn't any approve at requester end.
We also cannot use email test connection to gmail account for 2FA purpose.
Hello henry63,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Hello again henry63,
I found this solution. Can you tell us if it helps, please?
When FortiPAM is configured to send and process approval emails, it relies on SMTP for sending messages and IMAP or POP3 for retrieving reply emails. Since your organization uses Microsoft Exchange Server instead of an internal mail relay, the issue arises when FortiPAM cannot fully process the approval because Exchange restricts how reply messages are composed or authenticated.
Typical Cause of the Problem:
smtp.office365.com, Port 587 (STARTTLS).outlook.office365.com, Port 993 (SSL/TLS).
/var/log/fortipam/fortipam.log for parsing or SMTP/IMAP errors.
If testing with Gmail fails, it is due to Gmail’s OAuth 2.0 enforcement and removal of basic authentication. You can workaround this by:
If mail-based approval remains unfeasible:
These options eliminate the dependency on external mail flow while maintaining secure, auditable approval workflows.
Summary
Your specific issue occurs because Exchange causes FortiPAM’s reply parsing to fail when a new email is created instead of replying inline. Configure exclusive IMAP access for a dedicated service account, use App Passwords or relays if 2FA is enabled, and ensure the system is upgraded to a fixed release. If email cannot be reliably used, switch to portal- or token-based approvals for a stable workflow.
Hello Jean-Philippe_P,
Thank you very much for your solutions, I will test it and get back to you soon. What about there is a concern that enabling IMAP on Microsoft Exchange server. Do we have alternative way? Customer doesn't want to enable IMAP on Microsoft Exchange Server, cause they don't want to sync data to cloud.
Please understand me for my typo.
Best Regards,
Henry
Created on 12-16-2025 03:35 AM Edited on 12-16-2025 03:36 AM
Hello Henry :)
I found this answer, does it help you?
FortiPAM’s email approval workflow is dependent on IMAP access to retrieve approval responses from a mailbox. When IMAP cannot be enabled on Microsoft Exchange due to security or compliance restrictions (such as avoiding cloud data synchronization), there are alternative solutions:
Approvers can log in to the FortiPAM web interface and approve or deny requests directly from the Request Events → Request Event Log page. This method fully bypasses Exchange or IMAP connectivity while maintaining full auditability within FortiPAM.
FortiPAM can send outbound notification and approval request emails through a secure SMTP relay like FortiMail. This ensures delivery of email notifications while relying only on SMTP (not IMAP). To set this up:
For automation and integration purposes, FortiPAM provides REST API endpoints that allow programmatic approval or denial of requests without any email workflow. API users can be created with restricted roles for security, enabling integration with ticketing systems, custom approval dashboards, or third-party workflow platforms.
Although primarily used in FortiGate, Fortinet’s automation fabric supports webhook-triggered workflows that can extend to FortiPAM environments. This enables triggering actions or notifications via REST calls rather than relying on email.
If enabling IMAP on Microsoft Exchange poses data residency or compliance issues, the recommended approach is to:
Hello Jean-Philippe_P,
Could you kindly explain me about Gmail and 2FA Test connection failures case in details. Is there any reference docs or guide? I would like to get to study and refer.
Thank you very much for your strong support.
Best Regards,
Henry
| User | Count |
|---|---|
| 2880 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.