We have ~100 users with FortiMobile tokens, and in FAC they are setup as local RADIUS users, and dual-factor authenticate against a RADIUS/LDAP server (Microsoft NPS). We did it this way because at the time FAC did not support multiple LDAP domains, but it does now.
I would like to migrate these users to be LDAP authenticated directly against AD domain controllers, added to FAC groups automatically based on the LDAP filter (Remote User Sync Rules).
Is there a way to migrate them without having to re-issue their tokens, which would force them to re-install the token on their smartphone?
I don't see how, since it basically means deleting one account, and re-creating it as a different type. Just hoping there is migrate function I haven't seen.
We did the same thing and now have over 500 users "stuck" in radius. Hoping for a solution to migrate that I don't ever expect to come.
I never found a way to do this automatically, so I ended up having to manually re-assign tokens to users' remote LDAP accounts.
I haven't checked the API documentation for FAC yet, but that may be an option on the server-side.
Users will still have to install the new token which is the biggest hassle of this.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.