Fortinet FortiAuthenticator VM in Dubai, UAE
Deploy centralized identity, authentication, multi-factor authentication, single sign-on, certificate services and AAA functions as a virtual appliance while keeping control of the hosting environment, sizing and integration design.

Plan the VM before you buy the license
User count is only one sizing input. Buyers should also confirm the virtualization platform, authentication volume, log-retention needs, directory sources, MFA methods, HA requirements and the applications or network devices that will use FortiAuthenticator.
Direct answer for buyers evaluating FortiAuthenticator VM
Fortinet FortiAuthenticator VM is the virtual-appliance edition of FortiAuthenticator, used to centralize identity and access management services such as RADIUS and TACACS+ authentication, MFA, SSO, certificate management, Fortinet Single Sign-On and federation functions. It is suitable for organisations that prefer to host the authentication platform in their own virtual infrastructure or a supported cloud environment rather than use a dedicated physical appliance. Before proceeding, confirm the licensed user count, perpetual or subscription commercial model, virtualization platform, required VM resources, FortiToken or other MFA requirements, directory integration, HA design and support term. These choices determine the correct license combination and deployment plan.
What the virtual appliance does
FortiAuthenticator VM provides a central point for user identity, authentication and authorization workflows. It can act as a RADIUS or TACACS+ server, integrate with LDAP and Active Directory, participate in SAML and OIDC SSO, support certificate services and feed identity information to FortiGate for identity-aware policies.
The value for a buyer is not simply replacing a hardware appliance with a VM. It is the ability to place identity services inside an existing virtualization or cloud operating model, allocate resources according to scale and design redundancy around business requirements.
Who should consider it
It is a practical option for businesses already standardized on VMware, Hyper-V, KVM or another supported environment; organisations consolidating authentication for VPN, wired, wireless and administrative access; Fortinet customers expanding identity-driven security; and mixed-vendor networks that need standards-based RADIUS, LDAP, SAML or OIDC integration.
A buyer that does not want to operate VM infrastructure or manage the underlying platform may instead want to compare FortiAuthenticator Cloud. The decision should follow the desired operating model, regulatory requirements, resilience plan and integration needs rather than product name alone.
Business challenges FortiAuthenticator VM can help address
Fragmented authentication
When separate VPNs, wireless systems, network devices and applications each authenticate users differently, a centralized identity service can reduce policy inconsistency and simplify administration.
Weak password-only access
FortiAuthenticator supports MFA methods including FortiToken, email or SMS OTP options and FIDO2-based passwordless authentication. The exact method and any add-on requirement should be confirmed.
Limited user visibility
FSSO and supported identity sources can associate users and groups with network activity so FortiGate policies can be written with identity context instead of relying only on IP addressing.
Certificate administration overhead
Built-in certificate authority capabilities can support certificate creation, signing, revocation and selected automated enrollment workflows for use cases such as enterprise access and VPN authentication.
Core capabilities buyers should map to real requirements
FortiAuthenticator VM fit matrix
| Requirement | Suitable when | Confirm before ordering |
|---|---|---|
| Centralized network authentication | Multiple FortiGate, VPN, wireless or RADIUS/TACACS+ clients need a shared identity service. | Client count, authentication protocol, user stores and required policy model. |
| Virtual deployment | The organisation has a supported hypervisor or cloud platform and wants to operate the appliance itself. | Platform version, VM resource availability, networking and backup/DR design. |
| MFA rollout | Users require stronger authentication for VPN, administrative access, applications or network access. | Token type, quantity, enrollment workflow, fallback method and licensing. |
| High availability | Authentication is operationally critical and a single VM would create unacceptable risk. | HA mode, second-instance licensing, network placement and failure-domain design. |
| Large or growing user population | The user count can be mapped to a base license plus upgrades or an appropriate subscription tier. | Current users, forecast growth, authentication load and log-retention requirement. |
Verified FortiAuthenticator VM information
The table below separates current platform facts from items that depend on the selected commercial model, user count or deployment design.
| Brand | Fortinet |
|---|---|
| Product | FortiAuthenticator VM |
| Product type | Virtual Identity and Access Management / authentication appliance |
| Perpetual base SKU | FAC-VM-BASE |
| Perpetual base user capacity | Up to 100 users before user-license upgrades |
| User upgrade examples | 100, 1,000, 10,000 and 100,000-user upgrade blocks are documented; the required combination depends on total licensed users. |
| Subscription VM | Available by user band; exact SKU and support bundle should be confirmed for the required term and population. |
| Supported platform families | VMware ESXi/ESX, Microsoft Hyper-V, KVM, Xen, Microsoft Azure, AWS, Nutanix AHV, Oracle OCI and Alibaba Cloud are listed in current Fortinet material. Confirm the exact release/platform combination before deployment. |
| Virtual CPUs | Current Fortinet 8.0 private-cloud documentation specifies a minimum of 8 and maximum of 64 vCPUs. Licensing and technical resource ceilings are separate considerations. |
| Virtual memory | 16 GB minimum, up to 1 TB in current 8.0 system requirements; actual sizing depends on usage. |
| Virtual NICs | 1 minimum / 4 maximum |
| Virtual storage | 60 GB minimum / 16 TB maximum; Fortinet sizing guidance recommends larger allocations according to users and log-retention needs. |
| High availability | Active-passive HA and configuration-sync HA are supported. |
| Key authentication protocols | RADIUS, TACACS+, LDAP, SAML, OIDC and supported 802.1X/EAP workflows; use depends on design and version. |
| MFA methods | FortiToken Mobile, hardware tokens, email/SMS OTP options, client certificates and FIDO2 are among supported methods; token or service purchases may be additional. |
| Availability | Contact FourTeck for current UAE licensing, lead time and quotation options. |
Licensing, platform and compatibility dependencies
FortiAuthenticator VM should not be quoted as a single universal part number without first deciding how it will be licensed. The perpetual route starts with FAC-VM-BASE, which covers the initial 100 users, and user capacity is expanded with stackable upgrade licenses. Fortinet also offers subscription VM options grouped by user bands. Support contracts are separate line items in the perpetual model, while subscription SKUs can include a defined support level. Because commercial packaging can change, the final bill of materials should be checked against the current Fortinet ordering guidance at the time of quotation.
Platform compatibility also needs version-level confirmation. The current datasheet lists major private-cloud and public-cloud platforms, but a broad platform name is not enough for production planning. The exact FortiAuthenticator software release, hypervisor release, image format and target infrastructure must be matched. For example, deployment packages differ across OVF-based, KVM, Hyper-V and Xen-style environments. Public-cloud deployments introduce additional infrastructure and networking considerations that are separate from the FortiAuthenticator license itself.
MFA should also be scoped separately. FortiAuthenticator provides the authentication platform, but the selected token method may require FortiToken licenses, hardware tokens, SMS service costs or other components. If the project uses FIDO2, certificates, SAML federation, OIDC, SCIM, guest access or third-party RADIUS clients, confirm the intended workflow and any limits before placing an order.
A practical deployment and purchase journey
Define authentication scope
List users, directories, VPNs, wireless systems, network devices, applications, SSO targets and administrative-access use cases.
Choose licensing model
Compare perpetual base plus upgrades with subscription user bands, then add the appropriate support or token components.
Size the VM
Plan vCPU, memory, storage, NICs and log retention from the user count and real authentication activity, not from minimum resources alone.
Design resilience
Decide whether HA is required, where nodes will run, what dependencies they share and how authentication should behave during infrastructure failures.
Implement and validate
Deploy the image, apply licensing, integrate identity sources, configure services, test success and failure cases, and document operational ownership.
Centralized AAA for network, VPN and administrative access
One of the strongest reasons to deploy FortiAuthenticator VM is to remove authentication policy from individual network devices and place it in a service designed for identity decisions. FortiAuthenticator can provide RADIUS and TACACS+ services, allowing organisations to centralize authentication, authorization and accounting for supported network workflows. That is particularly useful when an environment includes multiple FortiGate firewalls, VPN gateways, wired or wireless access infrastructure and administrative interfaces that would otherwise maintain separate user stores or policies.
RADIUS is commonly associated with VPN access, Wi-Fi, 802.1X network access and other AAA use cases. FortiAuthenticator can also participate in certificate-based EAP methods where the deployment requires device or user certificates rather than passwords alone. TACACS+ is useful when the project requirement is centralized authentication and command-oriented control for administrators accessing network equipment. The exact scope of authorization and accounting should be mapped to the network devices involved, because third-party equipment may support different attributes or command-control behavior.
For Fortinet-centric environments, identity can also be shared with FortiGate through Fortinet Single Sign-On. FortiAuthenticator can collect identity through sources such as Active Directory polling, supported agents, RADIUS accounting and explicit authentication, then provide user and group context that FortiGate can use in policy decisions. This does not remove the need for good directory hygiene: group design, username formats, duplicate identities, stale accounts and domain connectivity all affect the quality of the resulting identity information.
A buyer should therefore scope AAA around transactions as well as users. Ask how many network access points, VPNs, switches, firewalls and administrator sessions will rely on the service, whether authentication spikes occur at shift changes or business opening times, and how long logs need to remain available locally. Those answers influence resource sizing, network placement and the case for HA much more than a simple employee count.
MFA and passwordless access without treating every user the same
FortiAuthenticator supports several methods for strengthening authentication beyond a username and password. Fortinet documents FortiToken Mobile and hardware tokens, email and SMS one-time passwords, certificates and FIDO2-based passwordless authentication among the supported options. This breadth matters because a workforce rarely has one identical access pattern. Office employees, privileged administrators, contractors, remote users, field staff and users in restricted environments may need different factors, enrollment methods and fallback procedures.
FortiToken-based MFA is a natural fit for organisations already using FortiGate for VPN or identity-aware access, but the token quantity and token type must be included in the commercial design. FortiAuthenticator user licensing and FortiToken licensing are not automatically the same thing. SMS can introduce gateway or message charges and may not suit every security policy. Email OTP depends on access to the mailbox during the authentication process. FIDO2 can reduce reliance on passwords for supported applications, but the relying parties, browser/device environment and registration lifecycle must be planned.
Adaptive authentication adds another layer by using context to decide whether a login should proceed normally, require a stronger challenge or be denied according to policy. Buyers should view this as a policy-design capability rather than a magic risk engine. The quality of the outcome depends on the conditions configured, the available context and the business rules applied. A sensitive administrative application may warrant stricter conditions than an internal low-risk portal, while a user population with shared workstations may need a different enrollment model than users with personally assigned devices.
Before ordering, define which services actually need MFA, the expected user enrollment process, how lost or replaced authenticators will be handled, whether offline or isolated environments are involved and who will approve exceptions. FourTeck can use these answers to help separate the FortiAuthenticator VM license from token, implementation and support requirements so the quotation reflects the full authentication workflow.
SSO, federation and certificate services for mixed environments
FortiAuthenticator is not limited to traditional RADIUS authentication. It can act as a SAML Identity Provider, operate as an IdP proxy and provide OIDC provider functions for supported applications. This makes the VM relevant when a business wants to reduce repeated sign-ins, connect internal identity to SaaS or web applications, or bridge between different identity domains. It also supports SCIM functions for user provisioning scenarios. The right design depends on which system will remain the authoritative identity source and where authentication policy should be enforced.
For many organisations, Active Directory or LDAP remains the source of users and groups. FortiAuthenticator can integrate with these directories rather than requiring the business to recreate every identity locally. That can simplify administration, but it makes directory connectivity and group structure critical dependencies. When SAML or OIDC is introduced, buyers should document each service provider, required claims or attributes, certificate requirements, redirect URLs, logout behavior and testing process. An apparently small SSO project can become complex if different applications expect different identity attributes.
Certificate management is another important capability. FortiAuthenticator can function as a certificate authority, create and sign certificates, handle revocation and support protocols such as SCEP for automated certificate enrollment in appropriate designs. That can support certificate-based VPNs, 802.1X, client authentication and other PKI use cases. A buyer should still define the certificate policy, validity periods, renewal workflow, secure key handling, revocation process and integration boundaries before production use.
The commercial implication is that federation and PKI projects often need more professional-services effort than the VM deployment itself. Installing the virtual appliance may be straightforward, but mapping identities, certificates, application metadata and failure scenarios requires coordination between network, security, directory and application owners. Include that implementation scope in the quotation if internal teams do not already have the required experience.
Where FortiAuthenticator VM can fit well
Multi-site enterprises
Centralize authentication for remote offices, VPN users and network infrastructure while retaining a consistent identity model across locations.
Virtualized data centres
Use existing virtualization operations, monitoring and infrastructure processes rather than introducing a dedicated physical identity appliance.
Secure remote-access programs
Combine directory authentication with MFA for remote users and administrators accessing VPN or supported applications.
Identity-aware FortiGate policy
Collect user and group context through FSSO-related methods and make identity available to FortiGate policy decisions.
Wired and wireless access
Support RADIUS and 802.1X authentication designs where network access should be tied to user, device or certificate identity.
Application federation
Use SAML or OIDC capabilities when selected internal or cloud applications need centralized sign-on and identity assertions.
Integration and operational considerations
An authentication platform becomes a dependency for many other systems, so its network design deserves the same care as the license choice. Place the VM where it has reliable connectivity to required directories, DNS, NTP, FortiGate devices, network access servers, mail or SMS services, certificate endpoints and applications. Management access should be restricted to trusted administrator networks, and secure management protocols should be used. Authentication depends heavily on accurate time, so NTP design is especially important for token and certificate workflows.
Logging and reporting needs can materially change storage requirements. Fortinet allows a broad storage range for the VM, but the minimum value is not a recommendation for every environment. If FortiAuthenticator will retain extensive authentication records locally, size storage for the required retention period and expected event volume. If logs are forwarded to another platform, confirm what still needs to remain on the appliance for troubleshooting and audit purposes.
High availability should be evaluated whenever failure of authentication would stop users from connecting to VPN, Wi-Fi, critical applications or administrative interfaces. A second node alone does not create resilience if both VMs share the same storage, hypervisor host, network path or identity dependency. Design failure domains deliberately and test what clients do when a RADIUS or SAML endpoint is unavailable. Some network devices support multiple authentication servers; application federation may require different continuity planning.
Version maintenance should also be part of the operating model. Before upgrades, review the FortiAuthenticator release notes, supported hypervisor information, integrations and backup procedures. Businesses that need help planning the surrounding Fortinet environment can review FourTeck’s technology services and deployment assistance or discuss the broader security product portfolio.
Questions to resolve before requesting a quotation
Include employees, contractors, remote accounts and other user populations that will authenticate through the platform.
The commercial model changes the SKU structure, support packaging and renewal planning.
Provide the platform and version so the correct image and support status can be checked.
List FortiGate, VPN, wired, wireless, network administrators, SaaS applications and third-party RADIUS/TACACS+ clients.
Clarify FortiToken, FIDO2, certificates, email or SMS and how users will enroll and recover access.
Define acceptable authentication downtime and whether a second VM or separate failure domain is needed.
Procurement checklist for FortiAuthenticator VM
How FourTeck can assist with sizing and configuration planning
A FortiAuthenticator VM request is most accurate when it starts with the authentication design rather than a generic quantity of one. FourTeck can review the user population, deployment platform, current identity sources, FortiGate environment, MFA method, expected integrations and resilience requirement, then help turn those requirements into a quotation-ready bill of materials. This is particularly useful when the project needs both FortiAuthenticator licensing and FortiToken, support, implementation or related Fortinet components.
For an existing environment, share the current FortiGate models, FortiOS versions, directory architecture, current RADIUS or SSO services, hypervisor platform and planned authentication use cases. For a new environment, provide the user count, site count, remote-access strategy, wireless or 802.1X plans, applications requiring SSO and any high-availability target. These details help avoid buying the right product with the wrong capacity or missing a required license line.
You can also review FourTeck’s Fortinet firewall options and the dedicated Fortinet solutions in the UAE when FortiAuthenticator is part of a larger identity-aware security project.
UAE availability and support guidance
Contact FourTeck to confirm current UAE availability for the required FortiAuthenticator VM license, user upgrades, subscription tier, FortiCare support and any FortiToken components. Software licensing may depend on the exact SKU, user band, support term, region and current vendor ordering structure, so availability should be checked against the final requirement rather than assumed from a generic product listing.
For projects in Dubai, Abu Dhabi, Sharjah and Ajman, FourTeck can coordinate requirement review, quotation preparation, deployment planning and any requested configuration scope from one consolidated project brief. Delivery or license activation timing should only be discussed after the exact bill of materials is agreed. Where installation, migration, integration testing or administrator handover is needed, include that scope in the quotation so licensing and professional services can be planned together. Use the FourTeck contact team to share the target user count, platform and required timeline.
GCC Availability
Organisations planning FortiAuthenticator VM across the GCC can ask FourTeck to review the requirement before the license is selected. This is useful for projects that span the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman because user count, license structure, deployment location and implementation scope may differ between entities even when the technical design is similar. FourTeck can help consolidate the intended authentication services, VM platform, FortiToken requirement, support term and project responsibilities so each destination receives an appropriate quotation rather than a copied bill of materials.
Product licensing, service availability, delivery schedules, support options and vendor lead times can vary by country, quantity, commercial term and current policy. Buyers should provide the destination country, total users, perpetual or subscription preference, required integrations, deployment platform and expected schedule. If the project includes Kuwait, the FourTeck Kuwait technology portal can be used alongside the central requirement discussion. Customs, local stock, installation dates and country-specific certifications should be confirmed separately where they apply.
Africa Availability
For African deployments, FortiAuthenticator VM can be attractive when the customer already has virtual infrastructure and wants to avoid shipping a physical identity appliance, but the complete requirement still needs regional planning. FourTeck can assist organisations evaluating the base VM license, user-capacity upgrades, FortiToken options, support, configuration scope and deployment prerequisites for projects in East Africa, West Africa, Southern Africa or other supported markets. The destination, hosting model and expected support arrangement should be known before the bill of materials is finalised.
Availability and fulfilment may depend on the exact license, destination country, quantity, vendor lead time, license region, payment and shipping arrangements for any physical token components, as well as local project conditions. Buyers should share the destination country, user count, preferred deployment schedule, virtualization platform, high-availability expectations and whether remote or on-site assistance is being considered. FourTeck’s Africa technology coverage can support broader regional discussions. Local inventory, customs outcomes or country-wide onsite coverage should not be assumed without confirmation.
What buyers are usually trying to determine before choosing FortiAuthenticator VM
Is FAC-VM-BASE the whole solution?
FAC-VM-BASE is the starting perpetual license for FortiAuthenticator VM and covers up to 100 users. For more users, the design needs one or more FortiAuthenticator VM user-upgrade licenses. MFA tokens, support and implementation services are separate considerations. A quote should therefore show the base VM, the capacity extension required for the real user count, any FortiToken or other authentication components and the selected support coverage.
Does a bigger user license automatically size the VM?
No. Licensing determines the allowed user population, while infrastructure sizing determines how the virtual appliance is resourced. Current Fortinet guidance starts at 8 vCPUs and 16 GB RAM for the 8.0 private-cloud platform, with higher memory, CPU and storage recommendations as deployments scale. Authentication patterns, log retention and enabled features can change resource requirements, so use the sizing guidance as a baseline rather than a substitute for capacity planning.
Another common question is whether FortiAuthenticator VM is only useful with FortiGate. It has strong value inside the Fortinet Security Fabric because it can supply identity to FortiGate and works naturally with FortiToken, but it also supports standards and services used in mixed environments. RADIUS, TACACS+, LDAP, SAML and OIDC allow it to participate in authentication and federation workflows with third-party systems where those systems support the required standards. Buyers should check the specific attributes and behavior expected by each third-party platform instead of assuming that protocol support alone guarantees every advanced feature.
Buyers also compare the VM with FortiAuthenticator Cloud. The VM is appropriate when the organisation wants to operate the FortiAuthenticator instance in its own private virtualization stack or a supported public cloud and retain responsibility for the underlying VM design. FortiAuthenticator Cloud is a Fortinet-hosted service model and changes the infrastructure responsibility and commercial structure. The better choice depends on data residency, operational skills, cloud strategy, integration paths, resilience requirements and whether the customer wants to manage the virtual appliance lifecycle directly.
Two organisations with the same number of licensed users can place very different loads on FortiAuthenticator. A company with employees authenticating once each morning may generate a different pattern from a business using VPN MFA, 802.1X reauthentication, administrator TACACS+, application SSO and certificate workflows throughout the day. When asking for sizing assistance, describe the authentication services and peak usage periods. This helps determine whether minimum VM resources are sufficient and whether storage or HA needs should be increased.
Another frequent purchase-planning issue is the difference between authentication users and tokens. The platform’s user license establishes the FortiAuthenticator capacity, but token-based MFA has its own commercial and operational choices. Decide whether all licensed users need MFA or only a subset, whether mobile or hardware tokens are preferred, whether FIDO2 is part of the policy and what fallback method is acceptable. This avoids overbuying one component while underestimating another.
For migration projects, the most important early task is inventory. Document the current RADIUS clients, shared secrets, directory connections, user groups, MFA enrollments, SAML applications, certificates, network-access policies and reporting dependencies. Authentication migrations often fail at the edges rather than at the core appliance because a legacy switch, an application claim, a certificate chain or a forgotten service account behaves differently. A staged test plan should include both successful and rejected logins, failover behavior and user-recovery workflows.
Finally, pricing seen online for FAC-VM-BASE should not be treated as a complete project cost. Public reseller pricing may refer only to the base 100-user perpetual license and may exclude UAE taxes, support, user upgrades, tokens, professional services or cloud infrastructure. For a useful comparison, ask vendors to quote the same user count, same license model, same support term and the same implementation scope. FourTeck can help normalize those inputs and prepare a requirement-specific quotation instead of comparing unrelated headline prices.
Decision questions that reveal the right FortiAuthenticator design
Do we need a VM or a hosted identity service?
Choose the VM when your team wants control of the deployment location, VM resources, network placement and lifecycle within a supported platform. Compare FortiAuthenticator Cloud when reducing infrastructure ownership is a priority. Data residency, integration routes, operational responsibility and commercial preference should drive the choice.
How should we calculate the licensed user count?
Start with every user identity expected to authenticate through FortiAuthenticator, then account for growth during the planned license or support period. The perpetual base starts at 100 users and expands through user-license upgrades. If the population is uncertain, share the current count and forecast so the quotation can show a sensible capacity path.
What if our environment is not entirely Fortinet?
Mixed environments can still be candidates because FortiAuthenticator supports common identity and AAA protocols. The important question is what the third-party system expects: RADIUS attributes, SAML claims, OIDC behavior, LDAP schema, TACACS+ authorization or certificate trust. Confirm the exact integration instead of relying on a generic interoperability statement.
Can one VM be enough for production?
Technically, a single VM can provide the service, but operationally the answer depends on how much business access depends on authentication. If losing one VM would prevent VPN access, network login or administrator access, evaluate active-passive or configuration-sync HA and ensure the nodes do not share a single infrastructure failure point.
What information produces an accurate quote fastest?
Provide the user count, preferred perpetual or subscription model, hypervisor or cloud platform, directory source, MFA choice, FortiGate or third-party integrations, HA requirement, support term and whether configuration assistance is required. This lets FourTeck identify the base license, capacity upgrades and related components without repeated clarification.
Should we migrate authentication all at once?
A staged migration is normally easier to validate. Start with a controlled user group or service, verify directory lookups, MFA, policy behavior, logging and fallback, then add other RADIUS clients, VPNs or applications. The sequence should be designed around the customer’s risk tolerance and current authentication dependencies.
Related FourTeck options to evaluate
FortiToken MFA
Evaluate mobile or hardware token requirements when FortiAuthenticator is being purchased for multi-factor authentication.
FortiAuthenticator Cloud
Compare the hosted service model when the business prefers not to operate the authentication VM infrastructure itself.
FortiGate firewalls
FortiAuthenticator can provide identity context and strong authentication for FortiGate-centered access designs.
Configuration and migration services
Include planning, deployment, integration testing or migration assistance when internal teams want implementation support.
Why businesses contact FourTeck for this type of requirement
The main benefit of involving FourTeck is requirement clarification. FortiAuthenticator VM can be simple when the project is a 100-user base deployment, but it can also become part of a larger identity design involving user upgrades, support contracts, FortiToken, Active Directory, multiple FortiGate devices, SAML applications, PKI, HA and professional services. A structured review helps distinguish mandatory license items from optional implementation choices.
FourTeck can coordinate model and license selection, bill-of-material review, compatibility questions, quotation preparation, configuration scope and deployment planning without assuming that every customer needs the same architecture. This is especially useful for procurement teams that need a clear commercial breakdown and for IT teams that need the quotation to reflect the intended technical design.
Frequently asked questions
What is Fortinet FortiAuthenticator VM used for?
It is a virtual identity and access management appliance used for centralized authentication, RADIUS/TACACS+ AAA, MFA, SSO, certificate services, Fortinet Single Sign-On and related identity workflows.
What does FAC-VM-BASE include?
FAC-VM-BASE is the perpetual FortiAuthenticator VM base license and supports up to 100 users. Larger deployments require FortiAuthenticator VM user-license upgrades.
Can FortiAuthenticator VM scale beyond 100 users?
Yes. Fortinet provides stackable VM user-upgrade licenses, including 100, 1,000, 10,000 and 100,000-user increments in current licensing documentation. The final combination should match the required total capacity.
Which virtualization platforms are supported?
Current Fortinet material lists VMware ESXi/ESX, Microsoft Hyper-V, KVM, Xen and several public-cloud or cloud-platform options. Confirm the exact FortiAuthenticator release and target platform version before deployment.
What VM resources should I allocate?
Current Fortinet 8.0 private-cloud guidance uses at least 8 vCPUs and 16 GB RAM, with larger CPU, memory and storage recommendations as deployments scale. Actual sizing depends on users, authentication load and log retention.
Are FortiToken licenses included with FortiAuthenticator VM?
Do not assume they are included. The FortiAuthenticator VM license and the chosen MFA token or service requirement should be scoped as separate commercial items unless the specific SKU documentation states otherwise.
Does FortiAuthenticator VM support high availability?
Yes. Fortinet documents active-passive HA and configuration-sync HA for the VM. The deployment design and any additional licensing or infrastructure requirements should be confirmed for the intended topology.
Can it work with Active Directory and third-party systems?
Yes. FortiAuthenticator can integrate with Active Directory or LDAP and supports standards such as RADIUS, TACACS+, SAML and OIDC. Exact interoperability depends on the third-party system and required authentication behavior.
How can I request a Dubai or UAE quotation?
Send FourTeck the user count, preferred licensing model, deployment platform, MFA requirement, integrations, HA requirement and support term. FourTeck can then confirm current UAE availability and prepare a requirement-specific quotation.
Build the right FortiAuthenticator VM bill of materials
Share the expected user count, virtualization platform, MFA method, directory source, FortiGate or third-party integrations and HA requirement. FourTeck can help confirm the correct licensing path and quotation scope for Dubai and the UAE.



Reviews
There are no reviews yet.