How To Transfer Fortitoken To New Phone

Transferring FortiToken to a New Phone
This article provides a comprehensive guide on how to transfer your FortiToken Mobile application and its associated tokens to a new mobile device. It outlines the necessary steps and considerations for a smooth and secure transition. The methods described herein are based on official Fortinet documentation and best practices.
Prerequisites
Before initiating the transfer process, ensure you have the following:
- Your old phone with the FortiToken Mobile application installed and active.
- Your new phone where you will be installing the FortiToken Mobile application.
- A stable internet connection on both devices.
- Access to the email account associated with your FortiToken, if applicable.
- Your FortiGate administrator credentials, if required by your organization.
Method 1: Self-Service Transfer (If Enabled)
Some organizations allow users to transfer their FortiTokens independently through a self-service portal or a FortiGate user interface. This method is the most straightforward, provided it's configured by your IT department.
Must Read
Steps for Self-Service Transfer
- Access the Self-Service Portal: Log in to the self-service portal provided by your organization. This URL is typically provided by your IT administrator. Alternatively, you may be able to access it via the FortiGate interface.
- Locate the Token Management Section: Within the portal, find the section dedicated to token management or multi-factor authentication. The exact naming may vary.
- Initiate Token Transfer: Look for an option to "Transfer Token," "Migrate Token," or similar. Select this option.
- Follow On-Screen Instructions: The portal will guide you through the transfer process. This usually involves scanning a QR code or entering a registration code displayed on your new phone.
- Install FortiToken Mobile on New Phone: Download and install the FortiToken Mobile application from the appropriate app store (Google Play Store for Android or Apple App Store for iOS) on your new phone.
- Activate Token on New Phone: Open the FortiToken Mobile application on your new phone.
- Scan QR Code or Enter Registration Code: Use the application to scan the QR code displayed on the self-service portal or manually enter the registration code provided.
- Verify Token Activation: The application should now display your FortiToken. Test the token by using it to authenticate to a resource that requires multi-factor authentication.
- Deactivate Token on Old Phone: Once you've confirmed the token is working on your new phone, deactivate the token on your old phone through the self-service portal. This prevents the old token from being used maliciously.
Method 2: Manual Transfer with Administrator Assistance
If self-service transfer is not available, you will need to contact your FortiGate administrator for assistance. This method involves the administrator revoking the old token and assigning a new one to your account.
Steps for Manual Transfer with Administrator Assistance
- Contact Your FortiGate Administrator: Inform your administrator that you need to transfer your FortiToken to a new phone. Provide them with your user ID and any other information they may require.
- Request Token Revocation: Ask your administrator to revoke the existing token associated with your account.
- Administrator Revokes Token: The administrator will revoke the token using the FortiGate CLI or GUI.
Example CLI command:
execute fortitoken revoke. The serial number can be obtained from the FortiGate's configuration. - Install FortiToken Mobile on New Phone: Download and install the FortiToken Mobile application from the appropriate app store on your new phone.
- Provide Token Activation Details: The administrator may provide you with a new activation code or QR code. They might also instruct you on how to bind the new token yourself using a FortiGate Captive Portal, depending on the configuration.
- Activate Token on New Phone: Open the FortiToken Mobile application on your new phone.
- Scan QR Code or Enter Activation Code: Use the application to scan the QR code provided by the administrator or manually enter the activation code.
- Verify Token Activation: The application should now display your FortiToken. Test the token by using it to authenticate to a resource that requires multi-factor authentication.
- Inform Administrator of Successful Activation: Notify your administrator that the token has been successfully activated on your new phone.
Method 3: Token Seed Import (Less Common, Requires Specific Configuration)
In rare cases, and only if your organization has specifically configured this, you might be able to import the token seed directly into the new FortiToken Mobile application. This method is less common due to security considerations.

Considerations for Token Seed Import
Token seed import is generally discouraged due to the risk of exposing the seed to unauthorized parties. This method should only be used if explicitly instructed by your FortiGate administrator. The seed is a sensitive piece of information that, if compromised, could allow unauthorized access to resources protected by the FortiToken.
Steps for Token Seed Import
- Obtain the Token Seed: Your administrator will provide you with the token seed. This seed is typically a long string of characters. Handle this seed with extreme care.
- Install FortiToken Mobile on New Phone: Download and install the FortiToken Mobile application from the appropriate app store on your new phone.
- Open FortiToken Mobile and Select "Import Token": Look for an option to "Import Token" or "Add Token Manually" within the application.
- Enter the Token Seed: Carefully enter the token seed provided by your administrator. Double-check for accuracy to avoid errors.
- Verify Token Activation: The application should now display your FortiToken. Test the token by using it to authenticate to a resource that requires multi-factor authentication.
- Inform Administrator of Successful Activation: Notify your administrator that the token has been successfully activated on your new phone.
- Securely Delete the Seed: Once the token is active, immediately and securely delete any record of the token seed.
Troubleshooting
If you encounter issues during the transfer process, consider the following troubleshooting steps:

- Incorrect Activation Code/QR Code: Ensure you are using the correct activation code or QR code. Double-check for typos.
- Time Synchronization Issues: Verify that the time and date are correctly set on your new phone. FortiToken relies on accurate time synchronization.
- Network Connectivity Problems: Ensure you have a stable internet connection.
- Application Conflicts: Close any other applications that might be interfering with the FortiToken Mobile application.
- Contact Your Administrator: If you are unable to resolve the issue, contact your FortiGate administrator for assistance. Provide them with details about the error messages you are receiving.
Security Best Practices
When transferring your FortiToken, adhere to the following security best practices:
- Use Strong Passwords: Ensure you are using strong, unique passwords for all your accounts.
- Enable Multi-Factor Authentication: Keep multi-factor authentication enabled on all accounts that support it.
- Keep Your Phone Secure: Protect your phone with a strong passcode or biometric authentication.
- Report Suspicious Activity: If you suspect that your account has been compromised, immediately report it to your IT department.
- Regularly Update Your Software: Keep your FortiToken Mobile application and your phone's operating system up to date with the latest security patches.
Conclusion
Transferring your FortiToken to a new phone can be a simple process, depending on your organization's configuration and the level of self-service options available. Always prioritize security throughout the transfer. If self-service is unavailable, prompt communication with your FortiGate administrator is crucial for a secure and efficient transfer. Remember to always verify the successful activation of your token on the new device and deactivate the token on the old device, when possible. By following these steps and security best practices, you can ensure a smooth transition and maintain the security of your accounts.
