Getting started
FortiPAM is a privileged access management solution that delivers credential vaulting, privileged account access control, and privileged activity monitoring and recording.
Planning
Plan your FortiPAM deployment by reviewing requirements, licensing, and learning more about the product.
Requirements
Ensure the following requirements are met for FortiPAM 1.7.0:
|
Requirement |
Description |
|---|---|
|
Supported Environments |
FortiPAM 1.7.0 supports virtualization environments such as:
Note: FortiPAM supports both Linux and Windows environment. |
|
FortiClient Compatibility |
FortiPAM 1.7.0 requires FortiClient 7.4.0 or above to offer the full set of functionalities. |
|
Browser Support |
Chrome or Edge web browsers are suggested for use, as there are limitations with Firefox extension-only deployment. |
|
Network Ports |
FortiPAM listens on default ports:
Note: Ensure these ports are open if using a firewall before FortiPAM. |
|
VM Resources |
For evaluation mode, FortiPAM requires less than 2 CPUs and 2048 MB of RAM. For a formal license, when using (v)TPM and disk encryption, it requires 4 GB of memory. |
|
Disks |
FortiPAM requires two disks to work; one for logs and another for video. |
Licensing
FortiPAM requires a subscription-based license.
-
Evaluation mode
FortiPAM platforms work in evaluation mode until licensed. In this mode, a maximum of 2 users are allowed (a default Super Administrator and one additional user), and the evaluation license expires after 15 days.
Note: All features are available except Antivirus Scan and DLP.
-
License activation
After purchasing, a license registration code is sent to your email. You must register it on FortiCloud and download the license file (
.lic).The
.licfile must then be uploaded to FortiPAM to activate it and obtain a valid serial number. -
License expiration
FortiPAM provides license expiration notifications 30 days before expiry by default.
Once the license expires, only a user with Super Administrator role can log in to the FortiPAM GUI, and FortiPAM goes into maintenance mode.
In maintenance mode, secrets/folders are read-only, and critical processes like password changing are suspended.
-
Renewal
To renew a license, purchase a new one and register the contract code via the FortiPAM GUI or directly on FortiCloud.
-
Floating license
FortiPAM supports a floating license model for VM instances, primarily for HA setup, allowing the total user seats to be the sum of seats on primary and secondary units (e.g., 50+50=100 seats).