Simple definition
FortiToken is a Fortinet multi-factor authentication solution used to add a one-time code or another authentication factor to a user account.
Technical definition
A token is assigned to an identity and then used during authentication with FortiGate, FortiAuthenticator, or other compatible Fortinet services. Depending on the product and token type, the code can be generated by a mobile application or a hardware token.
How it works / role
During an MFA-protected sign-in, the user provides the first factor and then the required FortiToken factor. The system validates the token assignment, synchronization, and presented code before granting access. The token must therefore be correctly assigned and activated for the intended user.
What is it used for?
Strengthen access to VPNs, administration interfaces, and other Fortinet services by requiring a second factor in addition to the password.
Practical example
A user signs in to a FortiGate SSL VPN with credentials and then enters the FortiToken Mobile code generated on a phone.
Common issues
- The token is not assigned or is assigned to the wrong user
- OTP time or synchronization is incorrect for the token type
- The phone is lost or replaced without a recovery process
- MFA is applied through an unexpected user group or authentication method
Key takeaway: FortiToken strengthens authentication; verify token assignment, the MFA method, and the authentication path actually used by the service.