Fortinet FortiToken Mobile

Fortinet FortiToken Mobile for Business MFA

Fortinet FortiToken Mobile is a software-based multi-factor authentication application that turns a supported mobile device into an OATH-compliant one-time-password token. It is designed for organisations that want to strengthen sign-in security for protected services without issuing a separate hardware token to every user. FortiToken Mobile can be used with FortiGate and FortiAuthenticator for device-managed deployments, while FortiIdentity Cloud provides a cloud-managed approach where that model better fits the organisation.

IT teams should confirm the required number of users, the intended authentication server, mobile platform requirements, push-notification needs, and the exact licensing model before ordering. Current device-managed FortiToken Mobile licenses are available in multiple token quantities, and license transfer rules are an important lifecycle consideration for new purchases. FourTeck can help review FortiGate or FortiAuthenticator compatibility, identify the appropriate license quantity, plan activation and user rollout, and prepare a quotation. For Dubai and wider UAE projects, contact FourTeck to confirm current licensing availability, delivery of the electronic entitlement, configuration scope, and any implementation assistance required.

SKU: FORTINET-FORTITOKEN-MOBILE-DUBAI Category:
Mobile multi-factor authentication

Fortinet FortiToken Mobile in Dubai, UAE

FortiToken Mobile gives organisations a practical way to add a second authentication factor by using a supported mobile device as an OATH-compliant one-time-password token. It can support FortiGate- or FortiAuthenticator-managed deployments and can also participate in a cloud-managed identity approach through FortiIdentity Cloud. The right choice depends on user count, management architecture, lifecycle plans, push requirements, and the Fortinet platforms already in place.

Fortinet FortiToken product family showing the FortiToken Mobile application

Buyer focus: confirm whether the deployment will be device-managed on FortiGate or FortiAuthenticator, or cloud-managed through FortiIdentity Cloud, before selecting licenses and planning user activation.

Authentication
OATH TOTP and HOTP
Management fit
FortiGate, FortiAuthenticator or cloud
License planning
5 to 10,000 device-managed tokens
Lifecycle check
New device-managed licenses are non-transferable between appliances except RMA

Direct answer for buyers

Fortinet FortiToken Mobile is a mobile application used to generate one-time passwords and, in supported deployments, receive mobile push authentication requests as part of multi-factor authentication. Businesses should consider it when users already carry supported mobile devices and the organisation wants MFA integrated with FortiGate, FortiAuthenticator, or a Fortinet cloud identity service. Before purchasing, confirm the number of users, which platform will validate and manage tokens, whether push authentication is required, the expected appliance lifecycle, and whether the chosen licensing model matches future migration plans. These points matter because current device-managed FortiToken Mobile licenses are tied to the managing FortiGate or FortiAuthenticator under Fortinet’s present transfer policy.

What FortiToken Mobile does

FortiToken Mobile adds an authentication factor that is separate from the user’s normal password. The application can generate time-based and event-based OATH one-time passwords, allowing the authentication server to validate something the user has in addition to something the user knows. Fortinet also supports mobile push in appropriate configurations, giving users an approve-or-deny interaction instead of manually typing a code for every supported login flow.

For organisations already operating FortiGate, this can reduce the need for a separate RADIUS authentication appliance in straightforward deployments because FortiGate includes an authentication server capable of validating OTPs for supported use cases such as VPN access, captive portal and administrative authentication. Larger or more centralised environments may prefer FortiAuthenticator, which can act as the central token and authentication platform for multiple services and devices.

Who it is designed for

FortiToken Mobile is relevant to businesses that want to strengthen access controls for employees, administrators, contractors or other authorised users without distributing a physical OTP key fob to every person. It can suit small FortiGate deployments that need a limited number of mobile tokens, as well as organisations using FortiAuthenticator for broader central management.

It is not automatically the right choice for every user population. Organisations with personnel who cannot use personal or corporate mobile devices, locations where smartphones are restricted, or programmes that require phishing-resistant FIDO2 hardware authentication should compare FortiToken Mobile with Fortinet hardware tokens, FIDO security keys or other identity options. FourTeck can help place the mobile-token requirement in the wider access-control design rather than treating the license as an isolated purchase.

Business problems FortiToken Mobile helps address

Passwords alone are too exposed

Passwords can be guessed, reused, phished or otherwise compromised. Adding a possession factor means successful authentication can require both the credential and a token-generated value or supported push approval. MFA does not remove every security risk, but it raises the barrier compared with relying on a password alone.

Physical token distribution adds overhead

A mobile token uses a device many users already carry. This can simplify distribution compared with issuing, storing and replacing a separate keychain OTP token. The organisation still needs a controlled enrolment process, documented ownership rules, and a process for lost or replaced phones.

Authentication may be fragmented

When Fortinet security infrastructure is already present, FortiToken Mobile can fit into the same ecosystem. Direct FortiGate use may be suitable for a focused deployment, while FortiAuthenticator can centralise token administration across a wider environment. The architecture should be chosen before buying a large token quantity.

User onboarding must be repeatable

Token activation can be performed using activation information sent to the user, including QR-based activation where supported. A consistent process for issuing, testing, revoking, transferring to a replacement phone and supporting users reduces avoidable help-desk work.

Core capabilities to evaluate

OATH one-time passwords

FortiToken Mobile supports both time-based TOTP and event-based HOTP token methods. This allows the application to serve as an OTP generator in supported OATH-based authentication designs.

Mobile push

Supported deployments can deliver authentication details to the mobile device so the user can approve or deny a request. Push requirements depend on the managing platform, network reachability and configuration.

Fortinet platform integration

FortiToken can be used directly with FortiGate and can be centrally managed with FortiAuthenticator. FortiIdentity Cloud offers a cloud-managed route for organisations that prefer SaaS-based identity management.

Controlled provisioning

Fortinet documentation describes dynamically generated token seeds, device binding and encrypted handling of token seeds. Activation should still be handled as a controlled identity process with verified user ownership.

FortiToken Mobile fit matrix

RequirementSuitable whenConfirm before ordering
Small FortiGate MFA rolloutA FortiGate will directly manage users and mobile tokens for a defined set of protected services.FortiOS compatibility, token quantity, VPN or admin authentication design, and future FortiGate replacement plans.
Centralised authenticationMultiple devices or applications need a common authentication platform and FortiAuthenticator is part of the design.FortiAuthenticator capacity, user sources, RADIUS/SAML requirements, redundancy design and license ownership.
Cloud-managed identityThe organisation wants tokens managed through FortiIdentity Cloud rather than tied to a single device-managed appliance.Subscription quantity and term, compatible applications, migration needs and cloud-management policy.
No-phone environmentsFortiToken Mobile is generally not the first option where mobile devices are prohibited or impractical.Compare FortiToken hardware OTP, PKI USB or FIDO security-key options according to the security requirement.

Verified product and licensing information

BrandFortinet
Product nameFortiToken Mobile
Product typeMobile software token application for multi-factor authentication
Token methodsOATH-compliant TOTP and HOTP
Mobile platformsCurrent Fortinet product information identifies iOS and Android for FortiToken Mobile. Confirm current operating-system support before deployment.
Managing platformsDevice-managed with FortiGate or FortiAuthenticator; cloud-managed options are available through FortiIdentity Cloud.
Push authenticationSupported in appropriate FortiToken Mobile configurations. Public reachability, platform version and configuration may affect operation.
ActivationToken activation can use an activation code; QR scanning is supported when activation information is delivered in a compatible format.
Device-managed license SKUsFTM-ELIC-5, FTM-ELIC-10, FTM-ELIC-25, FTM-ELIC-50, FTM-ELIC-100, FTM-ELIC-200, FTM-ELIC-500, FTM-ELIC-1000, FTM-ELIC-2000, FTM-ELIC-5000 and FTM-ELIC-10000.
Device-managed license typePerpetual license according to the current FortiToken ordering guide; purchase quantity determines the number of software tokens added.
License transfer policyFor device-managed FTM-ELIC licenses shipped on or after 4 August 2025, transfer between different FortiGate or FortiAuthenticator devices is not allowed except for RMA replacement. Confirm current Fortinet policy when planning appliance replacement.
SMS creditsThe current ordering guide states two SMS credits per FortiToken Mobile token for the device-managed model. Additional requirements should be confirmed separately.
UAE availabilityContact FourTeck for current license availability, quotation, quantity and vendor lead-time guidance.

Licensing, compatibility and lifecycle dependencies

A FortiToken Mobile purchase should start with the management architecture, not simply the number of users. Device-managed FTM-ELIC licenses are applied to a FortiGate or FortiAuthenticator. Fortinet’s current ordering guide lists perpetual token increments from five through ten thousand. For new licenses shipped on or after 4 August 2025, Fortinet states that license transfer between different managing FortiGate or FortiAuthenticator devices is not permitted except for RMA scenarios. This means an organisation that expects to replace, consolidate or redesign its authentication appliance should include lifecycle planning in the buying decision.

The policy is different from moving a user’s token to another mobile phone. Fortinet documentation distinguishes appliance-license transfer from reprovisioning or token transfer on the end-user device. Administrators should maintain clear records of which token license belongs to which FortiGate or FortiAuthenticator and should document the procedure for users who replace phones, lose devices or need to be re-enrolled.

FortiIdentity Cloud changes the model again. Instead of device-managed perpetual licenses tied to the managing appliance, cloud-managed tokens are included with the relevant subscription. Organisations with several Fortinet devices, planned appliance changes, distributed administration or broader identity requirements may therefore want to compare device-managed FortiToken Mobile against FortiIdentity Cloud before committing to a large purchase.

Compatibility should be verified at several levels: the FortiGate or FortiAuthenticator software release, the mobile operating system and FortiToken Mobile app version, the protected service or authentication protocol, push-notification reachability where used, and the organisation’s user-enrolment process. A license alone does not configure MFA. The authentication flow, user source, policies, fallback process and operational ownership must also be designed.

A practical purchase and deployment journey

1

Define the protected access

Identify whether MFA is required for FortiGate administration, remote-access VPN, captive portal, application access, RADIUS-based services or a broader identity programme. The use case determines where authentication should be enforced.

2

Choose the management model

Decide whether one FortiGate can manage the requirement, FortiAuthenticator should centralise tokens and authentication, or FortiIdentity Cloud better matches the desired lifecycle and administration model.

3

Size users and licenses

Count active users, planned growth, administrators, temporary users and any separate token populations. Select the nearest appropriate license increment rather than assuming a small starter pack will cover the full rollout.

4

Plan enrolment and support

Define how activation messages are delivered, how the user’s identity is verified, how the first login is tested, and what the support team does when a user loses or replaces a mobile device.

5

Test before wider rollout

Pilot with representative users and authentication paths. Confirm OTP and push behaviour, network reachability, recovery procedures, logging and help-desk documentation before enabling the policy for a large population.

Using FortiGate as the authentication point

For a focused environment, FortiGate can be the natural place to manage FortiToken Mobile because Fortinet integrates an authentication server into FortiGate. Fortinet documentation identifies OTP validation for use cases including SSL VPN, IPsec VPN, captive portal and administrative login. This can reduce architecture complexity where a separate central identity appliance is not required.

The buying question is not simply whether FortiGate supports FortiToken Mobile, but whether the chosen FortiGate is the correct long-term owner of the tokens. New device-managed licenses are subject to Fortinet’s current transfer restriction between appliances, so planned hardware refreshes, consolidation projects or a move to a different central authentication design should be considered before assigning a large perpetual license to a specific unit.

High availability also deserves attention. Fortinet states that FortiToken can be used directly with FortiGate including high-availability configurations, but the exact HA design, token registration process, firmware compatibility and operational recovery procedure should be validated for the customer’s environment. Administrators should also confirm the protected user groups and avoid enabling MFA without a documented recovery method for authorised administrators.

When FortiAuthenticator becomes the better fit

FortiAuthenticator is designed to centralise authentication services and FortiToken management, which becomes useful when a business must apply MFA across multiple Fortinet devices or other supported services. Instead of distributing token administration across several independent firewalls, a central authentication platform can provide a more consistent point for user repositories, token assignment, policy and integration.

Centralisation does not remove the need for sizing. The FortiAuthenticator model or virtual appliance resources, user count, token count, authentication rate, directory integration, redundancy and supported protocols must all be considered. A token license is only one part of the solution. If the project will integrate Microsoft Active Directory, LDAP, RADIUS clients, SAML applications or other identity components, those dependencies should be documented during design.

Push authentication may also require additional reachability and configuration considerations. Fortinet documentation for FortiAuthenticator specifies configuration of public IP or FQDN information before enabling certain FortiToken Mobile push scenarios. FourTeck can help review the intended flow and include configuration work in the quotation where required rather than leaving deployment assumptions until after licensing is purchased.

Mobile user experience, activation and privacy considerations

The end-user experience matters because authentication is repeated every day. FortiToken Mobile can display generated OTPs and, where push is enabled, present an approval or denial action. QR-based activation can simplify enrolment when the activation information is delivered by email, while manual entry remains useful when scanning is not practical. The exact enrolment message and method depend on the issuing platform and configuration.

Fortinet’s product documentation describes safeguards around token provisioning, including dynamically generated seeds, device binding and encryption of seeds at rest and in motion. It also states that FortiToken Mobile is not designed to read browser history, record audio, read or send emails, remotely wipe a phone or change device settings without permission. Permissions such as camera access are used for functions such as QR-code scanning; internet access is relevant for activation and push notifications. These details can help an IT team answer common employee questions during rollout.

Mobile policies should nevertheless be determined by the customer. If employees use personal devices, the organisation should define whether BYOD is permitted for authentication, what happens when an employee leaves, how tokens are revoked, and whether a managed corporate device is required for privileged users. If the organisation does not want authentication dependent on a smartphone, Fortinet hardware token or FIDO options may be more appropriate.

Ideal business environments and common use cases

Remote-access users

Organisations can use a mobile token as the additional factor in a supported remote-access authentication design. The VPN architecture, FortiOS version, user directory and exact client workflow should be confirmed before rollout. MFA should be tested with the actual remote-access method rather than assuming all login paths behave identically.

Firewall administrators

Privileged administrative accounts are a high-value MFA use case because compromise can expose security configuration. The team should establish an emergency-access procedure and ensure that legitimate administrators are not locked out during mobile-device loss, network failure or token replacement.

Distributed branch teams

A business with multiple locations may use mobile tokens for staff who access central services from branches or while travelling. If many Fortinet devices require authentication, central management through FortiAuthenticator or a cloud identity service may be easier to operate than independent token ownership on each firewall.

Contractor and temporary access

MFA can strengthen temporary access, but the organisation should also control account expiry, group membership and token revocation. Licensing should be sized around active token needs and the process for reclaiming access when a contract ends.

Central application authentication

Where applications authenticate through FortiAuthenticator or supported identity integrations, FortiToken Mobile can be part of a broader access design. Exact application compatibility and protocol support should be verified for the target system rather than inferred from a generic MFA requirement.

Security-policy modernisation

Businesses moving away from password-only access can introduce MFA in phases, starting with privileged users and remote access before expanding. A staged approach can reveal enrolment and help-desk issues early and allows the organisation to choose the right authentication method for different user populations.

Integration and operational considerations

FortiToken Mobile should be treated as part of an authentication system rather than a standalone mobile app. The managing FortiGate, FortiAuthenticator or FortiIdentity Cloud service must know the token and user association, and the protected service must send the authentication request through the correct path. If an external directory is involved, user identity and group mapping must also be reliable.

Time synchronisation matters for time-based OTP systems. Administrators should ensure relevant infrastructure has accurate time and that mobile devices are not significantly out of sync. Push authentication adds other dependencies, including internet connectivity and notification delivery. A fallback OTP workflow can be valuable when push is unavailable, subject to the security policy and supported configuration.

Logging should be included in the design so the support team can distinguish incorrect passwords, expired or invalid token values, unassigned tokens, connectivity issues and policy problems. During rollout, document expected login prompts and common troubleshooting steps. A clear user guide reduces calls caused by users not understanding whether to enter a six-digit OTP, approve a push notification, or complete an activation step.

Finally, confirm how the organisation will handle device loss, replacement and employee offboarding. The operational process should include verification of the person requesting a reset or token transfer, removal of old access, re-enrolment on the replacement device and confirmation that protected services still enforce the intended second factor.

Questions to resolve before requesting a quotation

Which platform will own the tokens?

Identify the specific FortiGate, FortiAuthenticator or FortiIdentity Cloud design. This single decision influences licensing, administration and future migration.

How many active users are required?

Count production users and expected near-term growth, then map the requirement to the current device-managed license increments or the applicable cloud subscription.

Is push authentication required?

Push can improve convenience, but its platform, network and configuration dependencies should be checked before it becomes a mandatory user-experience requirement.

Is an appliance replacement planned?

New device-managed license transfer restrictions make hardware lifecycle especially important. A planned refresh may change whether device-managed or cloud-managed licensing is more suitable.

What services will enforce MFA?

List VPN, administrative access, portals, RADIUS clients, applications and other access paths so the implementation can be designed and tested end to end.

Who will manage onboarding?

Decide whether internal IT, a managed-service team or a project partner will issue activations, validate users, support phone replacement and maintain token records.

Procurement checklist

  • Confirm the exact FortiToken Mobile license quantity or cloud subscription requirement.
  • Record the managing FortiGate or FortiAuthenticator serial and lifecycle plan for device-managed deployment.
  • Confirm the number of active users and expected growth.
  • Verify current FortiOS or FortiAuthenticator compatibility.
  • Confirm supported mobile operating systems and app versions for the user population.
  • Decide whether OTP only or supported mobile push is required.
  • List VPN, admin, RADIUS or application authentication flows that must be protected.
  • Confirm directory and identity-source integration.
  • Plan activation-message delivery and user verification.
  • Document lost-phone and replacement-phone procedures.
  • Review the post-August-2025 license transfer restriction for new device-managed licenses.
  • Include configuration, testing and documentation services in the quotation if required.

How FourTeck can assist

FourTeck can review the planned MFA use case, current Fortinet environment, user count and operational model before a license is selected. This is especially useful when the requirement sits between a simple FortiGate-managed rollout and a central FortiAuthenticator or FortiIdentity Cloud design. The aim is to align the token purchase with the authentication architecture and lifecycle rather than simply matching the current headcount.

Assistance can include license-quantity selection, FortiGate or FortiAuthenticator compatibility review, configuration scope, user-enrolment planning, testing, migration discussion and quotation coordination. Where implementation help is required, describe the existing environment and expected outcomes so the service scope can be included clearly.

You can also review FourTeck security products, explore technology services and implementation support, or see the wider Fortinet firewall guidance for Dubai when FortiToken Mobile is part of a larger FortiGate project.

Information that speeds up a quote

Share the required user quantity, preferred management platform, existing FortiGate or FortiAuthenticator model and software version, authentication use case, deployment location, whether configuration support is needed, and the desired project timeframe. If the business is replacing an existing Fortinet appliance, mention that at the start because current device-managed FortiToken Mobile transfer rules may affect the recommended route.

Discuss Your Requirement

UAE availability and support guidance

For a FortiToken Mobile requirement in the UAE, contact FourTeck to confirm current license availability, the exact token quantity, vendor lead time and any configuration services needed. FortiToken Mobile device-managed licenses are electronic entitlements, but the commercial and fulfilment process still depends on the chosen SKU, quantity, customer account requirements and current vendor policy. Do not assume that an app download by itself provides the required licensed token capacity for a production FortiGate or FortiAuthenticator deployment.

For projects covering Dubai, Abu Dhabi, Sharjah and Ajman, FourTeck can coordinate requirement review, quotation, deployment planning and the definition of remote or on-site assistance where applicable. Installation or configuration scope should be agreed in the quotation. Availability, scheduling and service scope can vary by project, so the exact managing platform and user count should be confirmed before rollout dates are set.

GCC Availability

Organisations planning FortiToken Mobile deployments across the GCC can work with FourTeck on requirement review, licensing quantity, authentication architecture, quotation coordination and implementation planning. A regional project may involve users in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman, but the same SKU should not be assumed to have identical commercial availability or project conditions in every destination. The managing FortiGate, FortiAuthenticator or FortiIdentity Cloud model should be identified first, followed by user count, token quantity, deployment location, desired schedule and support expectations. Product availability, licensing, service visits, delivery of electronic entitlements and vendor lead times can vary by country, model, quantity and customer requirement. For Kuwait requirements, buyers can also review FourTeck technology support in Kuwait. Share the destination country and exact requirement so the quotation can reflect the correct commercial and implementation context rather than relying on assumptions from another GCC market.

Africa Availability

For organisations deploying Fortinet authentication across Africa, FourTeck can help evaluate FortiToken Mobile quantities, licenses, supporting platforms, user-enrolment needs and configuration scope before procurement. Regional planning is particularly important when a central IT team supports offices across several countries, because the preferred design may be a central FortiAuthenticator, cloud-managed identity service or a defined set of FortiGate-managed token deployments. Availability and fulfilment can depend on destination country, required license quantity, vendor lead time, project schedule, local infrastructure and the need for remote or on-site assistance. Buyers should share the exact destination, number of users, managing platform, intended authentication use cases and preferred rollout timeline. FourTeck’s Africa technology resources can provide a regional starting point, while individual project terms should be confirmed for the actual country and scope rather than assuming uniform inventory, customs outcomes or service coverage.

Related Fortinet and FourTeck options

FortiGate

Suitable when the firewall itself will directly manage FortiToken Mobile for a focused set of users and services. Confirm model, FortiOS release and lifecycle before assigning new device-managed licenses.

Explore firewall options

FortiAuthenticator

Consider central authentication when several devices, applications or user sources require coordinated MFA and token administration. Capacity and integration scope must be sized for the environment.

FortiIdentity Cloud

A cloud-managed alternative for organisations that want broader identity management and token administration without tying new mobile-token ownership to one device-managed appliance.

Hardware and FIDO tokens

Compare physical OTP or FIDO security-key options when smartphones are not allowed, phishing-resistant authentication is required, or policy calls for a dedicated authenticator rather than a mobile app.

Why businesses contact FourTeck for FortiToken planning

FortiToken Mobile looks simple at the user level: install an app, activate a token and provide an additional factor. The procurement decision is more involved because the license is connected to an authentication platform, user population and lifecycle. FourTeck can help clarify those dependencies before purchase, including whether direct FortiGate management is sufficient, whether FortiAuthenticator would centralise the environment more effectively, or whether a cloud-managed identity model should be compared.

The practical value of this review is avoiding mismatched quantities, unclear ownership and unexpected redesign when an appliance is replaced. FourTeck can also help define configuration, testing, documentation and migration tasks so the quotation reflects what the business actually needs. For company background and broader technology coverage, visit about FourTeck.

What buyers are trying to understand before choosing FortiToken Mobile

A common buying question is whether FortiToken Mobile is simply an authenticator app or whether a Fortinet license is also required. The app is the end-user component, while production deployment depends on tokens being issued and managed by the appropriate Fortinet platform. For device-managed deployments, current Fortinet ordering information provides FTM-ELIC license increments beginning with five tokens and scaling through much larger quantities. The correct quantity should therefore be based on active users and the managing appliance, not on the number of app downloads.

Another frequent question is whether FortiAuthenticator is mandatory. It is not mandatory for every FortiToken Mobile deployment. FortiGate can directly validate FortiToken OTPs and is often sufficient for a limited environment where the firewall is the natural authentication point. FortiAuthenticator becomes more relevant when an organisation wants central management across multiple devices or needs a broader authentication service. A buyer should compare architectural simplicity today against management and lifecycle needs over the next several years.

Buyers also search for the difference between a generated OTP and mobile push. OTP means the application generates a code that the user supplies to the authentication process. Mobile push can present an authentication request that the user approves or denies on the phone. Push is convenient, but it has network and configuration dependencies that a locally generated OTP does not share in the same way. For that reason, organisations should test both the intended primary flow and the recovery flow before a wide deployment.

License transfer is now one of the most important questions in FortiToken Mobile procurement. Fortinet changed the device-managed transfer policy for licenses shipped on or after 4 August 2025. Under the current rule, those licenses cannot be transferred from one FortiGate or FortiAuthenticator to another except in an RMA replacement scenario. This does not mean a user can never change phones; it means the entitlement attached to the managing Fortinet appliance has a different lifecycle rule. If a firewall refresh is expected soon, discuss that before buying a large FTM-ELIC pack.

Buyer insight: choose architecture before quantity

The user count determines license size, but the management model determines where the entitlement lives and how the system will be administered. Decide FortiGate, FortiAuthenticator or cloud management first.

Buyer insight: plan for the next appliance change

A perpetual device-managed token license does not mean unrestricted movement between appliances. Current transfer rules make future firewall or FortiAuthenticator replacement part of today’s licensing conversation.

Buyer insight: test the real login path

A successful token activation is not the same as a validated production workflow. Pilot the exact VPN, administrative or application login path that users will follow.

Businesses also want to know how phone replacement works. FortiToken Mobile provides token-transfer and reprovisioning mechanisms, but the exact method depends on the token type and issuing platform. The operational rule should be that a replacement request is verified before the old association is removed or a new activation is issued. Help-desk staff should have a documented process for a user who still has the old phone and for a user whose phone is lost or unavailable.

Another practical issue is whether FortiToken Mobile can protect more than VPN. Fortinet documents direct FortiGate use for SSL VPN, IPsec VPN, captive portal and administrative login, and FortiAuthenticator can support broader authentication services. However, support for a particular business application should be confirmed based on its authentication protocol and the chosen integration. It is better to list every required application during design than discover after purchase that an application uses a different identity flow.

Finally, buyers often compare mobile tokens with hardware tokens or FIDO keys. FortiToken Mobile is attractive where users already have approved smartphones and the organisation wants a familiar OTP or push workflow. Hardware tokens can be better where smartphones are prohibited, shared-device policies make mobile enrolment difficult, or a dedicated authenticator is preferred. FIDO security keys serve a different security goal and can support phishing-resistant or passwordless authentication in compatible systems. A mixed environment may use more than one authentication method rather than forcing every user into the same form factor.

Decision questions that improve the final design

Do we need FortiAuthenticator if we have only one FortiGate?

Not necessarily. A FortiGate can directly manage and validate FortiToken Mobile for supported authentication scenarios. FortiAuthenticator is worth considering when the environment needs centralised identity services, multiple authentication clients, common user repositories or a design that should not be centred on one firewall. The right answer depends on scope rather than a fixed user threshold.

What happens if the FortiGate is replaced next year?

This is a critical licensing question. New device-managed FTM-ELIC licenses shipped on or after 4 August 2025 are not transferable to a different FortiGate or FortiAuthenticator except for RMA replacement under Fortinet’s current policy. If replacement is planned, compare licensing and migration options before purchase.

Can users authenticate if push is delayed?

FortiToken Mobile can generate OTP values, but the exact login experience and fallback behaviour depend on how the authentication policy is configured. When push is the preferred user flow, the project should test what happens during mobile-data loss, notification delay or restricted network conditions and document the supported alternative.

How should we calculate the token quantity?

Start with the number of people who need a distinct mobile token, add required privileged or service-specific populations where applicable, and account for planned near-term onboarding. For device-managed licensing, match the total to the current FTM-ELIC increments. Do not purchase based only on today’s pilot group if a larger rollout is already approved.

Should personal phones be allowed?

That is an organisational policy decision. FortiToken Mobile can run on supported mobile platforms, but the business should decide whether BYOD is acceptable for authentication, what privacy information users receive, how devices are removed at offboarding, and whether privileged users require corporate-managed devices.

What information should be sent with a quote request?

Provide the required user count, current FortiGate or FortiAuthenticator model and software release, whether the deployment is new or a migration, protected services, preferred OTP or push experience, expected rollout date and whether configuration assistance is required. This lets FourTeck identify the relevant license quantity and service scope more accurately.

Frequently asked questions

What is Fortinet FortiToken Mobile?

It is a mobile software token application used for multi-factor authentication. It supports OATH-compliant time-based and event-based one-time passwords and can support mobile push in appropriate Fortinet deployments.

Does FortiToken Mobile require FortiAuthenticator?

No. FortiToken Mobile can be used directly with FortiGate for supported use cases. FortiAuthenticator is useful when centralised authentication and token management across a broader environment are required.

What device-managed license sizes are available?

Fortinet’s current ordering guide lists FTM-ELIC quantities of 5, 10, 25, 50, 100, 200, 500, 1,000, 2,000, 5,000 and 10,000 software tokens. Confirm the required quantity and current ordering information when requesting a quote.

Can a new FortiToken Mobile license be moved to another FortiGate?

For device-managed licenses shipped on or after 4 August 2025, Fortinet states that transfer between different FortiGate or FortiAuthenticator devices is not allowed except for RMA replacement. Buyers should include appliance lifecycle in the licensing decision.

Can a user move a token to a replacement phone?

FortiToken Mobile supports token transfer or reprovisioning processes depending on the issuing platform and token type. This is separate from transferring the device-managed license between FortiGate or FortiAuthenticator appliances.

Does FortiToken Mobile support push authentication?

Yes, Fortinet supports FortiToken Mobile push in compatible configurations. The managing platform, software version, public reachability and network conditions should be checked when push is part of the required design.

How is a mobile token activated?

The user receives activation information from the issuing Fortinet platform. Depending on the delivery method, FortiToken Mobile can scan a QR code or accept an activation code manually. Administrators should verify the user before issuing or resetting activation.

Is FortiToken Mobile suitable for every employee?

Not always. Hardware OTP or FIDO security-key options may be more suitable where smartphones are prohibited, where a dedicated device is required, or where phishing-resistant authentication is a specific requirement.

How can I get FortiToken Mobile pricing in Dubai?

Send FourTeck the required user quantity, managing FortiGate or FortiAuthenticator details, preferred licensing model, deployment location and configuration needs. FourTeck can confirm current UAE availability and prepare a quotation for the relevant requirement.

Plan the token license around your authentication architecture

Share your user count, FortiGate or FortiAuthenticator details, protected services and expected rollout. FourTeck can help identify the appropriate FortiToken Mobile licensing route, discuss lifecycle considerations and include configuration support in the quotation where required.

Request Product ConsultationCheck UAE Availability

Reviews

There are no reviews yet.

Be the first to review “Fortinet FortiToken Mobile”

Your email address will not be published. Required fields are marked *

Scroll to Top
Powered by Joinchat