Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Recover FortiGate administrator access

From Tech-Wiki
(Redirected from Recovering lost password)


Recover administrative access to a FortiGate when the normal administrator credentials are unavailable.

ⓘ
Validation status
Reviewed against current Fortinet documentation and Fortinet Community guidance on 27 September 2026. The recovery method is strongly dependent on the installed FortiOS release and whether an alternative administrator or FortiGate Cloud management path is available.
!
FortiOS 7.2.4 changed password recovery
Starting with FortiOS 7.2.4, Fortinet removed the legacy maintainer account. Do not rely on the old console maintainer procedure for current FortiOS releases.

First identify the FortiOS version

If the appliance is still reachable through another administrative account, FortiManager, FortiGate Cloud or an existing management session, confirm the installed FortiOS release before choosing a recovery method.

The recovery paths differ substantially between releases before 7.2.4 and current releases.

FortiOS 7.2.4 and later

The legacy maintainer account is no longer available.

Fortinet documents several possible recovery paths depending on the environment:

  • Use another administrator with sufficient privileges to reset the affected account.
  • Where the appliance is connected to and appropriately licensed for FortiGate Cloud management, use the supported FortiGate Cloud recovery process.
  • If no administrative path remains, physical recovery can require returning the appliance to factory defaults or restoring firmware and then restoring an approved configuration backup.
!
Factory recovery is destructive
Factory reset or firmware recovery can remove the running configuration. Confirm that a usable configuration backup, firmware image, console access and an approved recovery plan exist before using a destructive recovery method.

Releases earlier than FortiOS 7.2.4

Older FortiOS releases supported a special console-only maintainer account after a hard reboot.

Because the behaviour and availability of this account changed across releases, use the Fortinet recovery article for the exact installed version rather than treating the historical Tech-Wiki procedure as universal.

ⓘ
Why the old Tech-Wiki procedure changed
The original article stated that a cold boot followed by the maintainer account was the standard recovery method. That stopped being true when Fortinet removed the maintainer feature beginning with FortiOS 7.2.4.

Reduce the chance of lockout

  • Maintain more than one controlled super-admin recovery path.
  • Protect and test configuration backups.
  • Ensure console access is available for physical appliances where operationally required.
  • Document FortiManager/FortiGate Cloud ownership and recovery access.
  • Test privileged-account recovery as part of the platform operating procedure.

Official references

See also