I have an unusual problem. When I went to add a rest api user I noticed that I am missing options for "REST API Admin" and "SSO Admin". I can only create create system administrators. I have a mix of hundreds of 7.2 and 7.4 systems in my network. This is the only device running 7.2.11 so I dont know if it is specifically for that version. And I cannot downgrade without getting an approved maintenance window.
I tried using the CLI as well...
I cannot type in config system api-user sso-admin... those are missing from the CLI.
Solved! Go to Solution.
Greetings!
The issue you're experiencing with the missing "REST API admin" and "SSO admin" options could be related to the FIPS-CC mode being enabled on your FortiGate device. In FIPS-CC mode, the REST API admin account option is disabled by design.
To verify if FIPS mode is enabled, you can use the following command in the CLI:
get system status
Look for the line, FIPS-CC mode:
Regards!
Greetings!
The issue you're experiencing with the missing "REST API admin" and "SSO admin" options could be related to the FIPS-CC mode being enabled on your FortiGate device. In FIPS-CC mode, the REST API admin account option is disabled by design.
To verify if FIPS mode is enabled, you can use the following command in the CLI:
get system status
Look for the line, FIPS-CC mode:
Regards!
That was it. The only other fortigates we have running in FIPS CC are 6 and 7.4.
I'm glad I could help with your question.
User | Count |
---|---|
2592 | |
1380 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.