We use Fortinet FortiAuthenticator, mostly where wireless or wired authentication needs to be integrated between multiple identity stores.
Technology Services Director at a computer software company with 11-50 employees
With a very effective support team in place, the solution provides a good stability
Pros and Cons
- "The most valuable feature of the solution is RADIUS service and the social network integration feature."
- "The GUI has some shortcomings and can be made better. The GUI is not great."
What is our primary use case?
What is most valuable?
The most valuable feature of the solution is RADIUS service and the social network integration feature.
What needs improvement?
The GUI has some shortcomings and can be made better. The GUI is not great.
For the next release, the thing that will be most useful is to integrate with other MFA providers.
For how long have I used the solution?
I have been using Fortinet FortiAuthenticator for four years. My company has a partnership with Fortinet. We are also resellers.
Buyer's Guide
Fortinet FortiAuthenticator
April 2026
Learn what your peers think about Fortinet FortiAuthenticator. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
886,664 professionals have used our research since 2012.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten. I have only ever known one stability problem.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution an eight out of ten.
I think that commercially it is not valid for a very small number of users. It doesn't scale down all the way. I think that although it can be scaled up to thousands of users, it wouldn't be suitable for, like, a mobile network scale if you have got 50,000 or 1,00,000 users.
At the entry point, we have more than 100 users.
How are customer service and support?
I have directly contacted the solution's support. They are very helpful. They do require a lot of supporting information, but they are very effective for what they do. I rate the technical support a nine out of ten.
How was the initial setup?
Regarding setup, I would say that it is straightforward but not simple. It's not a job for the novice, but it is straightforward for an experienced engineer. Also, my clients normally ask for help.
The solution gets deployed on physical, virtual, and SaaS.
What's my experience with pricing, setup cost, and licensing?
On a scale of one to ten, where one is a high price and ten is a low price, I rate the pricing a seven.
Price-wise, it is competitive, but they still charge.
Which other solutions did I evaluate?
For comparing or evaluating Fortinet FortiAuthenticator, the competitors I would normally expect to see would be RSA Security with their SecurID product. Also possibly, I would say that you would compare it against Duo or Okta.
Fortinet FortiAuthenticator is better since it is very much use-case dependent. I think a Fortinet-heavy environment where the customer already has a lot of investment into Fortinet makes it easier since it integrates more closely with their network equipment, like their firewalls. Also, it does not always require an on-premise component to provide services like RADIUS.
What other advice do I have?
People who are looking to implement the product should pay attention to scaling and plan deployment thoroughly before starting, as for many things, once the decision is made, some things are difficult to change.
I rate the overall solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Network admin at Penobscot Valley Hospital
A reasonably priced solution that can be scaled toward different functionalities and offers flexible SMS messaging
Pros and Cons
- "The most valuable feature is the flexibility in using the SMS messages."
- "The solution is an integral part of our security for our email network, and like I said, we'll begin using it for other cloud applications."
- "I would like to see more support from Fortinet with tech support people who have as much expertise on the authenticator as they do on their firewalls."
- "I would like to see more support from Fortinet with tech support people who have as much expertise on the authenticator as they do on their firewalls."
What is our primary use case?
The solution syncs with our active directory and allows configuration for
two-factor authentication. We're using the two-factor authentication for our Office 365 email and cloud. We needed a way to use the authenticator to configure a trusted network so that when the users are in-house, on our network, they don't get prompted for two-factor. We don't want to go through that rigmarole every time, so basically it authenticates through active directory that this trusted network that we're on is going to encrypt the data. Then, when they're not on a trusted network or they're at home and trying to log in, the user gets a SMS message to put in a token to validate their identity for their email username and password.
What is most valuable?
The most valuable feature is the flexibility in using the SMS messages. People give me their cell phone numbers, I put them in the active directory, it syncs over to the authenticator, and then they're able to use the two-factor authentication when they're at home or doing something outside of our network.
What needs improvement?
It was very hard to find the right people to help us set up the solution. We hired a third party, but they were not as helpful as they could have been. After that, we got a higher level of support through Fortinet, and they engaged with us and worked out the final bit. The connectivity between Microsoft Office and the authenticator is very tricky when it comes to certificates and you need more expertise for that, so if you don't have the experience, you need a higher level person to help with it.
I would like to see more support from Fortinet with tech support people who have as much expertise on the authenticator as they do on their firewalls. They don't have enough people with that expertise.
Once you get comfortable, you want to ask questions like "Okay, what if I do this, what is the impact?" You don't know what changes you can apply until they happen. It's better to have somebody who knows what they're doing, and knows what changes you apply are going to make a difference. Once I was able to talk to the second level Fortinet person I said, "Well, what does this do? What does that do?" Then he helped me and I said, "Okay." That makes a difference, because it's new and you don't know what you're supposed to do.
For how long have I used the solution?
I have been using this solution for about five months.
What do I think about the stability of the solution?
The stability of the solution has been very good. I haven't had any issues.
The funny thing is, when I first got the authenticator there was a problem with it and I couldn't get it configured. I had to go through Fortinet to troubleshoot the fact that it was basically inoperable. I had to send it back and then they sent me another one, and that one has worked fine, so that was just one of those freak things that happens.
What do I think about the scalability of the solution?
I think you can scale it toward different functionalities. For example, we have a Fortinet firewall and I could have used 40 tokens to configure the authenticator for that usage, but I chose to use it just for the email. In the same vein, there's scalability for other applications, servers, and cloud servers to set up a two-factor configuration on this authenticator. For other applications you have to pony up with the vendor who's doing it and log into their application in the cloud, then they have to be able to coordinate this thing, so that's kind of hard to figure out.
We use the solution for anybody who wants to have remote access to their email, so pretty much anybody who says, "Yeah, I'm going to be checking my email from home," I configure it so that they can do that. I'd say most everybody in our company has it. Whether they use it or not is a different story, but I have to buy SMS messages licenses for every person who wants the option to use it.
You only need one person, like myself, for maintenance. Once it's up and running, people can log in and get their email, and if there are issues I can look at the log and say, "Well, it's telling me you're putting the wrong password in or username." Or it shows, "Oh, you got it right. Success."
The solution is an integral part of our security for our email network, and like I said, we'll begin using it for other cloud applications. We signed a three-year contract for the solution, so it's here to stay.
How are customer service and support?
The tech support is okay. If you have complex problems, there are not enough people to help, and you have to get to a higher level of support, so it can be a little challenging to get to the right person. That's on Fortinet as a company, though; what they provide is excellent. It's just getting to the right person.
Which solution did I use previously and why did I switch?
We used to use an authenticator called Duo, but we're a small rural hospital, and that solution is a lot more expensive. It was probably at least three times the cost of Fortinet. The other thing was that I already had a Fortinet firewall, so I wanted something in conjunction with that to work alongside it.
How was the initial setup?
It was complex when it came to the active directory portion of the product. Knowing what was required to have the active directory integration with the authenticator was a little tricky, and figuring out how the users' email addresses were going to be displayed. When you go to Office 365, it redirects it back to the authenticator and you have to make sure you have the right configuration and the right domain because it inputs it based on your domain name. It was difficult to get that figured out.
What about the implementation team?
We used a third party in conjunction with higher level Fortinet support for deployment. We had to get a certificate and the third party helped us with that, and then we had to talk with Microsoft too, so it was tricky.
During setup it was hard to make sure that the solution was doing what it was supposed to do. There were different factors that made it difficult, but it might have been because the person who was trying to implement the solution didn't understand it fully. There were some inconsistencies in standards for active directory account names, for example, usually you'd have first initial, last name, and that would be your domain name. However, we had some older users, myself included, that had a different format that included their department name, like 46-JMoore for example, and the authenticator didn't understand that. You'd have to tell the user, "Okay, you're using this old formatting for your username, but you need to put it in differently so the authenticator can understand it." It wasn't really the authenticator's problem, but more so had to do with fitting the environment into the authenticator's configuration.
What's my experience with pricing, setup cost, and licensing?
First you have to buy the unit, then you have to buy the license for it. I think we have a 100-user license. The price depends on the model. We have a FAC 300, which channels X number of users, so if you have a lot more users, you're going to buy a higher model, like with any other solution.
We got the reseller price, so we paid $3,450 for the authenticator model itself. The support contract is about $2,900 for three years, which is a pretty good deal.
Then you've got to pay the fee for their help with the installation. That was like $6,000, but it varies depending on the vendor. So between paying them to help with the configuration, the box itself, and the support, it came to like $12,500, including a three-year service agreement.
The only other cost is for the SMS messages, which are not expensive. It's under $30 for like 100 SMS messages, so it's not a big deal.
What other advice do I have?
My advice to people considering this solution is that I think you need somebody who has experience with FortiAuthenticator, and most places are going to have to use a third party to get it installed correctly. I also think the third parties have some leverage on accessing the higher level of Fortinet support, which helps. I think you can do certain parts yourself, like preparing the device for your active directory, but when it comes to actually getting comfortable with the commands and knowing what you're doing, you need a third party to help you get it installed correctly.
I would rate this solution as a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiAuthenticator
April 2026
Learn what your peers think about Fortinet FortiAuthenticator. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
886,664 professionals have used our research since 2012.
Senior Manager, Network & Cloud Security Architect at a computer software company with 1,001-5,000 employees
Scalable platform with efficient technical support services
Pros and Cons
- "The product's on-premise version doesn't have recurring costs."
- "Fortinet FortiAuthenticator's initial setup process could be easier."
What is our primary use case?
We use the product for multi-factor authentication, single sign-on, and FIDO integration. We utilized it while logging into Windows and remote SSL VPN with MFA.
What is most valuable?
The product's on-premise version doesn't have recurring costs.
What needs improvement?
Fortinet FortiAuthenticator's initial setup process could be easier.
For how long have I used the solution?
We have been using Fortinet FortiAuthenticator for two years.
What do I think about the stability of the solution?
It is a stable platform.
What do I think about the scalability of the solution?
It is a scalable platform.
How are customer service and support?
Fortinet provides excellent support services. A level-one engineer will attend your first call if you have a basic support contract. However, your call will be transferred to a specialist if you have an advanced-level support contract.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used Duo before. It is a cloud solution and has recurring costs. Thus, we switched to Fortinet FortiAuthenticator as it is an on-premise solution and comparatively inexpensive without recurring costs. They only charge a nominal fee for support.
How was the initial setup?
The initial setup is complex. It would be helpful if customers get assistance from professional services. They can customize it depending on the architecture visibility. It is easy to design if they hire a knowledgeable architect. It takes less than a week to complete.
What about the implementation team?
Our company provides professional software development services to different clients.
What was our ROI?
The product generates a lower ROI than other vendors.
What other advice do I have?
I rate Fortinet FortiAuthenticator a nine out of ten. I advise others to have clarity on the visibility and scope of the design and then start with the deployment.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Architect at IT Systems and Solutions sp. z o.o.
Provides efficient access management features and has a helpful technical support team
Pros and Cons
- "The implementation has significantly improved access management within our organization."
- "Improvements in the product could start from the dashboard, overall customization, and configuration."
What is our primary use case?
Our primary use case for the product is to enable two-factor authentication for our VPN solutions within FortiGate. Additionally, we utilize it to secure our FortiWeb tool security portal with two-factor authentication.
What needs improvement?
Improvements in the product could start from the dashboard, overall customization, and configuration. FortiAgent, installed on an end user's computer, provides two-factor authentication but lacks centralized management. This particular area needs improvement.
For how long have I used the solution?
We've been using Fortinet FortiAuthenticator for around five years, staying updated with the latest version.
What do I think about the stability of the solution?
I rate the platform's stability as four out of ten. When they release new software, we sometimes encounter issues utilizing the box, and it takes almost 30 days to resolve them.
What do I think about the scalability of the solution?
In just our organization, where we are a partner, there are around 100 Fortinet FortiAuthenticatorusers. However, we have implemented the solution for customers with up to 10,000 users.
I rate the scalability a ten out of ten.
How are customer service and support?
The technical support team is helpful.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Our organization has a diverse portfolio of products, including Check Point and hardware such as switches, Xfinity Networks, Juniper, HP, and Dell.
How was the initial setup?
We typically only need to perform installation updates or implement changes if infrastructure changes occur at the customer's end. This doesn't happen often, once or twice a year. When implemented correctly, it's not complicated to manage, so it isn't required. We have a team of five engineers responsible for deployment, maintenance, and all other operations related to the product.
What's my experience with pricing, setup cost, and licensing?
The platform provides a user-based pricing model rather than a subscription pricing model. For instance, the virtual machine and license for 100 users amount to around $2000. Additionally, there may be additional expenses for features like FortiToken.
I rate the pricing an eight out of ten.
What other advice do I have?
FortiAuthenticator enhances user authentication by integrating a database with user credentials, including logins and passwords. This integration enables the import of user data from various sources such as Active Directory, Microsoft, OpenLDAP, or RADIUS servers. Additionally, FortiAuthenticator supports adding a second factor for authentication, which can include options like Fortinet SMS, email tokens, or other methods.
The implementation has significantly improved access management within our organization. We have exposed certain portals like Avaya and Microsoft Exchange to the public internet by adding a two-factor authentication login process to these portals using the product.
The most critical feature in improving our security is the two-factor authentication feature. It also includes an agent that can be installed on a user's computer, adding another layer of security to the login process for computer access.
For these users, incorporating the second factor poses no problem. However, some less experienced users may need help adding and using the second factor during login. With assistance from our help desk and after a few attempts, these users find the process straightforward.
Integrating FortiAuthenticator with our existing infrastructure has been quite easy, especially considering our experience as a business partner of Fortinet. After several years of using and implementing the product for our customers, we've encountered no major issues. The process is simple, typically taking only a few implementations to become familiar with all the features.
I recommend it to others and rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Network & Security Engineer at Viroka Technology Private Limited
A tool with a user-friendly GUI that is also easy to install and maintain
Pros and Cons
- "The initial setup of Fortinet FortiAuthenticator is easy."
- "For improvement, Fortinet needs to ensure that they provide quick support to users...Fortinet sometimes needs to respond to users facing issues within an hour."
What is our primary use case?
In my company, we use Fortinet FortiAuthenticator as a AAA server. We use it to integrate with LDAP and integrate with FortiGate in multiple locations with centralized authentication. We can authenticate the users since Fortinet FortiAuthenticator allows for two-factor authentication and FortiClient.
What is most valuable?
FortiGuard supports two-factor authentication or FortiToken, but it is only for a centralized location. With Fortinet FortiAuthenticator, we can allow centralized locations and users across the globe to use it.
What needs improvement?
Documentation is an area where Fortinet is constantly trying to improve.
For improvement, Fortinet needs to ensure that they provide quick support to users. Once a ticket gets created by our company with the support team, we have to wait for SLA, which can go up to four or sometimes six hours. Fortinet sometimes needs to respond to users facing issues within an hour. Fortinet needs to improve the part of engineering SLAs.
Automation is a feature I would like to see in the solution since Fortinet has included automation features only in FortiGate. It would be better to see automation features, like backup, interfaces, or statuses, in FortiAuthenticator.
For how long have I used the solution?
I have been using Fortinet FortiAuthenticator for five years. My company has a partnership with Fortinet.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable solution since the tool provides its users with the option to scale up.
With Fortinet FortiAuthenticator, I work for medium and large enterprises.
How are customer service and support?
I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of Fortinet FortiAuthenticator is easy.
Fortinet FortiAuthenticator's deployment takes an hour if everything is up and running.
Three to four engineers are required for the deployment of the product.
What about the implementation team?
What other advice do I have?
Everything in the tool, including the tool's GUI, is user-friendly.
The solution is easy to maintain, provided we know about the product. It is not a complicated tool, making learning easy for all. Some skills are required for a person to be able to maintain the solution.
With FortiGate, anyone can access or handle the tool, especially if they have handled other products. With FortiAuthenticator, opportunities to first understand the product to be able to use it.
I rate the overall product a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Manager at a computer retailer with 11-50 employees
Easy-to-configure product with good stability
Pros and Cons
- "The product is good, cost-effective, and functionally efficient."
- "They could expand FortiAuthenticator's capabilities to accommodate a broader range of environments."
What is our primary use case?
We use the product network device authentication for Linux and Windows server integrations.
What is most valuable?
The product is good, cost-effective, and functionally efficient. It has a valuable capability to work as a virtual machine and integrate with Active Directory.
What needs improvement?
They could expand FortiAuthenticator's capabilities to accommodate a broader range of environments. It needs a user-friendly interface and intuitive console for those needing in-house solutions. Additionally, there should be a mobile-centric approach for remote control capabilities while proceeding.
For how long have I used the solution?
We have been using Fortinet FortiAuthenticator for more than ten years.
What do I think about the stability of the solution?
The product is stable in our production environment.
What do I think about the scalability of the solution?
We have 5000 Fortinet FortiAuthenticator users in our organization.
How are customer service and support?
They could improve the response time for severe cases. At present, they reply within a day or two. However, they do provide good solutions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used Cisco's firewall products before. In comparison, Fortinet is more user-friendly and easy to configure.
How was the initial setup?
We require two administration executives to manage the product.
What about the implementation team?
We provide implementation and maintenance support for all our customers.
What's my experience with pricing, setup cost, and licensing?
The product has affordable pricing compared to other vendors. They offer valuable features considering the cost.
What other advice do I have?
Fortinet FortiAuthenticator is a very popular and robust product in the market. They provide integration with third-party applications.
I rate it an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Architect engineer at DGS S.P.A.
A scalable solution that identifies users through a varied range of methods
Pros and Cons
- "The web feature is quite versatile. It serves as the sole server authenticator and is valuable not only with FortiGate products but also within the entire Forti system, making it highly useful for me."
- "The only issue I encounter is that when not using FortiAuthenticator for an extended period, it's typical to encounter some obstacles in the configuration process that you need to address."
What is our primary use case?
In my recent job, I worked in tandem with Fortinet to enable 802.1X authentication for the Wi-Fi environment.
What is most valuable?
The web feature is quite versatile. It serves as the sole server authenticator and is valuable not only with FortiGate products but also within the entire Forti system, making it highly useful for me. However, from my experience, I find the visual data to be less practical. While some features might be more respected than others, it's valuable that, for instance, when a customer has a new lead cluster, I can authenticate or leverage alternative solutions to achieve the desired outcome.
What needs improvement?
The only issue I encounter is that when not using FortiAuthenticator for an extended period, it's typical to encounter some obstacles in the configuration process that you need to address. It's not a consistent problem, and I can't recall all the specifics. This issue is something I face with the entire product. While it's normal for products to require ongoing attention, this can be a challenge when checking the system.
For how long have I used the solution?
I have experience with Fortinet FortiAuthenticator.
What do I think about the stability of the solution?
I recollect instances when customers didn't approach me about their issues, instead opting to submit tickets. From a personal perspective, customer mobility played a role, and sometimes I wasn't fully aware of the problem until later. However, I can't recall many details about these cases.
What do I think about the scalability of the solution?
It's scalable. If the need arises, you can easily set up a cluster with two or more units. Additionally, if you require more licenses or features, you can expand.
How are customer service and support?
It works well for me. I can review the initial check, explain it thoroughly, outline the subsequent steps, and attempt to address the problem. This often involves quickly escalating to technical levels two or three. In situations where I open a general ticket, it's standard to begin with a level one tech who collects information to understand and resolve the issue. The more detailed and accurate the data is, the easier it becomes to find a resolution.
How would you rate customer service and support?
Positive
How was the initial setup?
It is deployed on-premises. One or two days for initial deployment is insufficient. It typically takes a few more days to set up the specific configurations. The standard device configuration is exceptionally fast.
What other advice do I have?
Based on my experience it's been very good. I don't have much knowledge, for instance, about how it compares to Gartner's system and its current position in the market, or whether there are other systems that might have a better position. I've noticed that Fortinet lacks certain features that other solutions have implemented. This leads me to explore and understand other solutions, looking for differences. I've observed that some solutions offer features that Fortinet may excel in, while others may have strengths in different areas. I would rate it an eight out of ten overall.
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementor
Wireless Network Engineer at Orient Logic
Easy-to-setup platform with good technical support services
Pros and Cons
- "The product’s most valuable feature is integration with FortiGate, FortiToken, FortiTalk, and multi-factor authentication."
- "Fortinet FortiAuthenticator provides only authentication. It should also enable authorization services"
What is our primary use case?
We use Fortinet FortiAuthenticator to maintain security, and access, and monitor authentication and authorization processes. It enables the proper functioning of the CA server. We can use various authentication methods, including EFTOS parameters like PKI (Public Key Infrastructure) for the CA server.
What is most valuable?
The product’s most valuable feature is integration with FortiGate, FortiToken, FortiTalk, and multi-factor authentication. It is inexpensive compared to Cisco and Clear Pass.
What needs improvement?
Fortinet FortiAuthenticator provides only authentication. It should also enable authorization services. There could be a central management point for both the services similar to Cisco and Clear Pass.
For how long have I used the solution?
We have been using Fortinet FortiAuthenticator for around a year.
What do I think about the stability of the solution?
It is a stable product. I rate the stability a ten out of ten.
What do I think about the scalability of the solution?
It is a scalable product. It is suitable for medium and enterprise businesses. Its scalability is a seven or eight out of ten.
How are customer service and support?
Fortinet provides good support services.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Compared to Fortinet FortiAuthenticator, Cisco is a complicated tool to use. It is difficult to configure as it has many features. It is scalable but needs to be a more stable product.
How was the initial setup?
The initial setup is very easy. It takes an hour to complete.
What's my experience with pricing, setup cost, and licensing?
The product is inexpensive compared to Cisco. I rate its pricing a three to five out of ten.
What other advice do I have?
I recommend Fortinet FortiAuthenticator and rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementor
Buyer's Guide
Download our free Fortinet FortiAuthenticator Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
Single Sign-On (SSO) Authentication Systems Identity Management (IM) Multi-Factor Authentication (MFA)Popular Comparisons
Microsoft Entra ID
SailPoint Identity Security Cloud
Okta Platform
Omada Identity
Ping Identity Platform
One Identity Manager
Auth0 Platform
CyberArk Identity
Yubico YubiKey
RSA SecurID
Fortinet FortiToken
Buyer's Guide
Download our free Fortinet FortiAuthenticator Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the differences between FortiAuthenticator and FortiNAC?
- When evaluating Single Sign-On, what aspect do you think is the most important to look for?
- CA SiteMinder vs IBM Tivoli Access Manager
- What single sign-on platform do you recommend?
- How much time does SSO save?
- Why is SSO needed?
- Why is Single Sign-On (SSO) important for companies?
- IBM Tivoli Access Manager vs CA SSO

















