FortiIdentity Cloud in Africa
FortiIdentity Cloud Africa gives organisations a cloud-managed way to strengthen sign-ins, control access to business resources and reduce dependence on passwords alone. It combines multi-factor authentication, single sign-on, local identity-provider services, identity-provider proxy functions, adaptive policy controls and passwordless authentication options in a service that can be managed through an intuitive online portal. FourTeck helps buyers turn user counts, application requirements and security goals into a clear licence and deployment request.
◆ MFA and Passwordless Options
🔒 SSO and Identity Federation
↗ Africa Quote Support
Check Africa Availability
Availability and commercial terms depend on user volume, subscription period and selected options.
Quick Product Information
Product Overview
Identity has become one of the most important control points in business security. A firewall can block unwanted traffic and an application can protect its own data, but both still rely on the assumption that the person signing in is genuine. Password theft, phishing, reused credentials, compromised email accounts and unmanaged administrator access can undermine otherwise strong infrastructure. A cloud identity service addresses this problem by adding stronger verification and consistent access policy before users reach sensitive systems.
FortiIdentity Cloud is designed to provide identity and access management as a service. It supports centrally managed multi-factor authentication for FortiGate environments and other supported applications, while also offering single sign-on and identity federation functions for SAML and OIDC applications. The platform can act as a local identity provider, or it can proxy access to a remote SAML or OIDC provider where the organisation already has an established identity source. This flexibility allows the service to fit into a new deployment, a Fortinet-focused network or a broader hybrid identity design.
The service is particularly relevant to organisations that do not want to deploy, power, patch and maintain a dedicated authentication appliance. Administration takes place through a web interface, giving authorised teams a central place to manage users, authentication methods, realms, integrations and usage. FortiToken Mobile support can simplify the user experience through one-time passwords and push approval, while supported options such as SMS, email OTP, hardware tokens and FIDO2 passkeys allow the authentication method to be matched to risk, user type and device readiness.
For a branch network, the first use case may be protecting remote-access VPN users or FortiGate administrators. For a growing enterprise, the project may include SSO for cloud applications, adaptive policy enforcement, third-party application access and multiple user groups. A managed service provider may need a platform that can scale across many Fortinet products and customer environments. In every case, the correct purchase depends on user count, licence tier, subscription period, SMS usage, application compatibility and deployment ownership.
FourTeck supports buyers by reviewing these practical details before quotation. Instead of treating the product as a generic cloud licence, the buying discussion should document who will authenticate, what they will access, which authentication factors are acceptable, how users will be enrolled, which applications need federation and who will handle renewals. This approach helps security, procurement and finance teams understand the full requirement and reduces the risk of ordering the wrong user tier or overlooking implementation work.
Key Business Benefits
The value of cloud identity management is measured by the business risks it reduces and the operational work it simplifies. The following benefits explain how the service can support daily users, IT teams and security governance.
🔒 Stronger User Verification
Multi-factor authentication reduces reliance on a password as the only proof of identity. Even when a credential is exposed, an additional verification step can make unauthorised access more difficult. Businesses can apply stronger methods to administrators, remote users, finance teams and other higher-risk groups instead of using one weak sign-in standard for everyone.
✓ Cloud-Based Administration
A cloud-managed service removes the need to procure and maintain a separate physical authentication appliance for this use case. Authorised administrators can manage the environment through an online portal, helping distributed teams coordinate policies, user onboarding and renewal activity without depending on one local server room.
◆ Better Sign-In Experience
Single sign-on can reduce repeated prompts for approved applications, while push approval and passkeys can make strong authentication easier for users. A smoother process supports adoption because employees are less likely to seek unsafe workarounds when secure access is clear, fast and consistent.
⚙ Flexible Authentication Methods
Different users have different devices, connectivity and risk profiles. Support for mobile OTP, push notifications, SMS, email OTP, hardware tokens and FIDO2 passkeys gives organisations room to choose suitable methods. Final availability and suitability should be confirmed against the planned application and policy.
↗ Scalable User Licensing
Annual subscriptions are offered in user-volume tiers, and licences can be stacked and co-termed. This allows an organisation to begin with a suitable quota and add capacity as the workforce, branch network or customer base grows. Correct forecasting still matters because user quotas, renewal timing and SMS consumption affect long-term cost.
● Adaptive Access Decisions
Adaptive policies can help organisations apply authentication requirements according to context rather than treating every sign-in identically. A familiar user and device may follow one process, while a higher-risk event may require additional verification. Policy design should reflect the organisation’s real risk model and support capability.
◇ Fortinet Environment Alignment
Out-of-the-box MFA integration with FortiGate can make the service attractive to organisations already protecting network access through Fortinet. The identity layer can also support third-party applications through federation standards, helping teams avoid a design that works only for one isolated login point.
Product Highlights
The service includes mobile-token capabilities designed to simplify user verification through push approval or one-time passwords. It can also support SMS and email-based authentication where those methods fit the organisation’s policy, although SMS credit use and regional rates should be reviewed carefully. Hardware-token support may be relevant for administrators, users without compatible smartphones or environments that require a separate physical factor.
A major strength is that the service is not limited to one authentication pattern. It can protect FortiGate access, operate as an identity provider for supported applications, proxy federation to another provider and apply adaptive conditions. Exact capabilities depend on the current service version, configured realm, application integration and licence entitlement. Buyers should confirm their priority workflows during scoping rather than assume that every application will behave identically.
Technical Specifications and Licensing Reference
| Area | FortiIdentity Cloud Details |
|---|---|
| Brand | Fortinet |
| Product Type | Cloud-native identity and access management as a service |
| Former Name | FortiToken Cloud |
| Core Functions | MFA, SSO, local IdP, IdP proxy, adaptive authentication and passwordless options |
| Federation Support | SAML and OIDC application scenarios; final compatibility depends on application and configuration |
| Authentication Methods | FortiToken Mobile, mobile OTP, push approval, SMS OTP, email OTP, supported hardware tokens and FIDO2 passkeys |
| Administration | Cloud web portal with central configuration, provisioning and usage visibility |
| Annual Licence Tier 1 | FC1-10-IDCLD-445-02-12 for 25–499 users |
| Annual Licence Tier 2 | FC2-10-IDCLD-445-02-12 for 500–1,999 users |
| Annual Licence Tier 3 | FC3-10-IDCLD-445-02-12 for 2,000–9,999 users |
| Annual Licence Tier 4 | FC4-10-IDCLD-445-02-12 for 10,000 or more users |
| Included SMS Allowance | 125 SMS credits per licensed user per year under listed annual subscriptions |
| Additional SMS Options | Separate SMS credit licences are available; usage varies by destination rate |
| Licence Behaviour | Stackable and co-termed; added subscriptions may be prorated to align expiry dates |
| Support | Annual licence descriptions include FortiCare Premium Support per year; entitlement should be confirmed on the quote |
| Availability | Configuration dependent; contact FourTeck for current commercial options |
How to Read the Licence Table
The user ranges identify the ordering tier, not the number of users automatically supplied by one line item. A buyer should confirm the actual quantity of end-user quotas required and the minimum order rules that apply at the time of purchase. The number of employees is not always the same as the number of licensed identities because contractors, administrators, service accounts or external users may also need authentication.
SMS credits are shared at account level according to the licensed quota, and the number of credits consumed can vary by destination. Organisations expecting frequent SMS use should estimate monthly authentication volume and consider whether mobile push, OTP or passkeys can provide a better long-term user experience. FourTeck can help prepare the required SKU, user quantity and subscription term for quotation.
Configuration and Buyer Guidance
A good cloud identity purchase begins with an access map. Procurement should not ask only for a licence name, because the useful design depends on users, applications, authentication methods and operational ownership. The following questions help technical and commercial teams prepare a complete request.
1. How many identities need access?
Count active employees, administrators, contractors and external users. Include expected growth, seasonal users and planned acquisitions so the licence quantity is not undersized immediately.
2. Which resources are protected?
List FortiGate administration, remote-access VPN, cloud applications, internal portals and third-party services. Identify which integrations require SAML, OIDC or another supported method.
3. Which factors will users use?
Choose between mobile push, OTP, SMS, email, hardware tokens and passkeys according to device access, security level, connectivity, usability and support readiness.
4. Is SSO part of the project?
Document every application that should trust the service, the expected claims or groups, certificate ownership and the process for testing changes before production.
5. How will users be enrolled?
Plan invitations, token activation, device replacement, lost-phone handling, user removal and help-desk escalation. Strong technology still needs an understandable operating process.
6. Who owns renewal?
Record the subscription anniversary, budget owner, technical owner and procurement contact. Co-termed licensing can simplify dates, but only when additions and renewals are tracked properly.
The quote should state the required user quantity, annual term, protected systems, expected SMS consumption, token method, integration scope, support expectation and rollout schedule. Buyers should also clarify whether they need licensing only, guided configuration or a broader deployment service. This information allows FourTeck to review the order codes and prepare a proposal that matches the real identity project.
Ideal Business Use Cases
The service can support several identity scenarios, but each deployment should begin with a defined access risk and a measurable operational goal. The following use cases show where cloud-managed authentication can provide practical value.
Remote-Access VPN Protection
Remote employees and contractors often connect from unmanaged networks, making password-only VPN access a high-risk entry point. Centrally managed MFA can add verification through mobile approval, OTP, tokens or another approved method. The project should include user enrolment, emergency access, device replacement and testing against the relevant FortiGate configuration.
Administrator Sign-In Security
Firewall, network and application administrators hold privileged access that can change security policy or expose sensitive systems. Requiring a second factor or phishing-resistant passkey can reduce the risk associated with stolen administrator credentials. Organisations should keep a controlled recovery path and ensure that shared accounts are replaced where practical.
Cloud Application Single Sign-On
Businesses using many cloud services may want a consistent sign-in experience and central identity policy. SAML or OIDC federation can allow supported applications to trust the identity service. Application owners should verify claim mappings, group assignments, certificate renewal and failure procedures before moving large user populations.
Hybrid Fortinet Environments
A business may operate FortiGate firewalls at several sites while also using third-party applications and a remote identity provider. Local IdP and IdP proxy functions can help coordinate these access paths. The architecture should document which platform is authoritative for each user group and how failures are handled.
Managed Service Provider Operations
Service providers may need to manage authentication across many Fortinet products or customer applications. A scalable cloud platform can reduce appliance overhead, but the service design should still separate customer realms, administrators, policies and reporting responsibilities. Commercial planning should include user growth and renewal coordination across managed accounts.
Phishing-Resistant Access
Organisations concerned about credential phishing can evaluate FIDO2 passkeys for compatible users, devices and applications. Passkeys can reduce dependence on passwords and one-time codes, but adoption requires device readiness, supported browsers, recovery planning and careful communication so users understand the new sign-in process.
Other valid scenarios include securing sensitive finance applications, protecting third-party support access, standardising authentication after a merger and introducing stronger access controls without installing another local appliance. The platform should be selected because it fits the authentication journey, not simply because it is cloud based. FourTeck can help compare the requirement with on-premises FortiAuthenticator and focused FortiToken options where a different model may be more appropriate.
FortiIdentity Cloud — Multi-Factor and Passwordless Authentication
Passwords remain common because they are familiar and widely supported, but they are also copied, reused, phished and shared. Multi-factor authentication adds another test of identity, making a password alone less useful to an attacker. The service supports several authentication approaches, including FortiToken Mobile, mobile one-time passwords, push approval, SMS or email OTP, hardware tokens and FIDO2 passkeys. This range gives security teams the ability to match the factor to the user and the risk.
A remote employee with a managed smartphone may find push approval convenient. A network administrator may need a phishing-resistant passkey or separate token. A user in an area with inconsistent mobile data may rely on a time-based OTP. SMS can be useful in selected situations, but cost and delivery reliability must be considered. The strongest choice is not automatically the most complex method; it is the one that users can operate correctly and the support team can recover safely.
Passwordless authentication can improve security and usability when the target applications, devices and browsers support the required standards. It reduces the need to type a reusable secret and can resist common phishing techniques. However, the rollout still needs registration, device trust, replacement procedures and account recovery. Security teams should begin with a controlled group, test failure conditions and document how users regain access without weakening the policy.
FourTeck can help buyers define user groups, preferred methods, expected token quantities and implementation responsibilities before the licence order is prepared. This makes the commercial request reflect the actual authentication programme rather than a simple per-user count.
FortiIdentity Cloud — Single Sign-On and Identity Federation
Single sign-on is valuable because users often work across many applications during the same day. Separate credentials for every service increase password reuse, support calls and account-removal work. Federation allows an application to trust an identity provider, so approved users can access resources through a consistent sign-in process. The service supports local identity-provider and identity-provider proxy roles for SAML and OIDC scenarios, creating flexibility for organisations with new or existing identity infrastructure.
A local IdP design can make the service the authentication authority for supported applications. An IdP proxy design can route authentication to another SAML or OIDC provider while applying the required access flow. This can be useful when different business units, partners or cloud services already depend on separate identity platforms. The architecture must clearly state which provider owns the user record, where groups are managed and how claims are translated.
Federation improves convenience, but it also concentrates dependency. A change to certificates, metadata, group mappings or claims can affect many connected applications. Organisations should maintain expiry calendars, test environments, change approval and emergency access. Application owners need to participate because an identity team cannot validate business workflows alone. Deprovisioning is equally important: a user who leaves the organisation should lose access consistently across connected systems.
Before quotation, buyers should provide the list of applications, federation standards, user groups, current identity provider and intended sign-in journey. FourTeck can use this information to clarify whether licensing, configuration assistance and migration planning should be included in the proposal.
FortiIdentity Cloud — Adaptive Policy and Central Management
Not every authentication event carries the same risk. A user signing in from a familiar environment may present a different risk profile from an administrator attempting access through an unusual device or location. Adaptive authentication allows policy to consider context and require additional verification when conditions justify it. This can improve security without forcing the most demanding sign-in process on every user at every moment.
Adaptive rules should be understandable and testable. Security teams need to define what conditions matter, which actions are triggered and how legitimate users recover when a policy blocks access. Too many rules can create confusing behaviour and help-desk pressure, while rules that are too broad may not reduce risk. A practical deployment begins with a small number of clear controls linked to real business threats.
Central management supports this work by giving administrators an online place to configure MFA, review usage and maintain authentication services. Daily usage information and subscription notifications can help the organisation monitor licence consumption and renewal timing. Cloud administration is especially useful for distributed teams, but access to the management portal itself should be protected with strong administrator controls and limited privileges.
Operational ownership is essential. One team should maintain policies, another may approve access, and the help desk may support enrolment and recovery. FourTeck can help buyers include these responsibilities in the deployment discussion so the service has a sustainable operating model after the initial configuration.
What Buyers Should Check Before Purchase
Before requesting a quote, buyers should confirm the complete access requirement rather than selecting a licence only by product name. The correct order depends on the number of identities, intended authentication factors, application integrations, subscription period and support scope. The checklist below helps procurement and technical teams avoid missing a user tier, renewal responsibility or deployment task.
User and Licence Fit
Count every end user that needs the service and identify the correct volume tier. Confirm the minimum quantity, annual term and whether future users will be added under co-termed licensing.
Application Compatibility
List FortiGate systems and third-party applications. Confirm SAML, OIDC, local IdP, proxy or MFA requirements against the current application version and intended authentication flow.
Authentication Method
Decide whether users need push, mobile OTP, SMS, email, hardware tokens or passkeys. Consider device availability, connectivity, phishing risk, accessibility and recovery procedures.
SMS Consumption
Estimate how often SMS will be used and where recipients are located. Credit consumption can vary by destination, so high-volume deployments may need additional credits or another primary factor.
Deployment Scope
Clarify whether the purchase covers licensing only, guided setup, application federation, policy design, user enrolment, testing, documentation and administrator handover.
Renewal and Ownership
Record who monitors usage, receives expiry notices, approves renewal and owns the budget. Confirm how added licences will align with the existing subscription date.
Support Expectations
Confirm the support entitlement, escalation route and responsibilities between Fortinet, the supplier, the implementation team and the customer’s internal help desk.
Quote Preparation
Provide user count, subscription term, application list, factor preference, SMS estimate, rollout date and delivery or billing requirements so the commercial response is complete.
Buyers comparing cloud and on-premises options should also consider control, internet dependency, integration depth and internal skills. An on-premises FortiAuthenticator appliance may suit organisations that need dedicated local identity services, while FortiToken may fit a narrower MFA requirement. FourTeck can help review these alternatives so the selected approach matches the business environment rather than being chosen only by licence price.
Africa Availability and Service Support
FourTeck supports product inquiries across Africa with assistance for licence selection, user-count review, authentication-method planning, quote preparation, delivery coordination and warranty or support guidance. Availability can vary according to the current supplier position, selected subscription period, required quantity, destination and implementation scope. Buyers should request a current commercial response rather than assume that an online reference reflects the final order.
A useful inquiry should include the number of licensed identities, preferred annual term, protected FortiGate devices or applications, expected authentication methods, approximate SMS use and desired rollout date. It should also state whether the organisation needs licensing only or assistance with configuration, federation, user enrolment, adaptive policy, testing and administrator handover.
FourTeck can help check the appropriate order code and identify related requirements such as hardware tokens, additional SMS credits, on-premises identity alternatives or Fortinet firewall integration. Commercial terms, support entitlement and delivery coordination should be confirmed in writing on the final quotation.
Africa Country and Regional Coverage
Businesses across Africa, including Kenya, Uganda, Nigeria, Ghana, Tanzania, Rwanda, Ethiopia, South Africa, Zambia, Botswana, Senegal and other regional markets can contact FourTeck for product availability, licence guidance and quote assistance. Support is relevant to private companies, public institutions, educational organisations, healthcare groups, financial services, hospitality businesses, system integrators, resellers and managed service providers.
Regional projects should identify where users are based, which applications are hosted centrally and whether the authentication service will protect one organisation or several managed customers. Procurement teams should also state billing requirements, project quantity and deployment timing. FourTeck can help prepare a consistent commercial request while allowing user counts, support responsibilities and rollout phases to vary by business unit.
GCC, Middle East and Africa Availability
FourTeck Africa can support identity-service inquiries for organisations operating across Africa while coordinating wider regional requirements through selected FourTeck platforms. Businesses with project stakeholders in the UAE, Saudi Arabia, Qatar, Oman and Bahrain may need a common authentication policy for users, administrators and applications across several offices.
Cross-regional planning should standardise user definitions, authentication methods, application ownership, support processes and renewal dates. One region may host the primary applications while another manages security operations or procurement. The service design should account for internet dependency, help-desk coverage, local user communication, data policy and the process for replacing lost devices or tokens.
Availability, delivery options, warranty handling and configuration support can vary by country, supplier status, subscription tier and order quantity. Buyers can review FourTeck Africa, the Kenya support platform, the Uganda service platform and the UAE procurement desk for the most relevant regional contact path.
Other Options Buyers May Consider
Identity security works best when the cloud service, firewall, local authentication platform and reporting tools are selected as one architecture. The following related options may be useful depending on the required control level, deployment model and existing Fortinet environment.
Fortinet Identity Security Solutions
Review the wider Fortinet identity family, including cloud and on-premises authentication, tokens, privileged access and network access control.
FortiAuthenticator FAC-3000F
A dedicated identity appliance for large organisations that need extensive local authentication, RADIUS, certificate and high-availability capabilities.
FortiGate 50G
A compact branch firewall option that can form the network enforcement point for VPN and administrator authentication projects.
FortiGate 31G
A smaller Fortinet firewall discussion for compact sites that need secure access, VPN planning and stronger administrator verification.
FortiAnalyzer FAZ-800F
A related security-operations platform for central log collection, reporting and investigation across Fortinet-focused environments.
The correct alternative depends on the objective. A focused FortiToken deployment may be enough for a small group of VPN users. A FortiAuthenticator appliance may be better when local RADIUS, certificates or dedicated identity infrastructure are required. A cloud service is attractive where rapid central management and reduced appliance overhead matter. FourTeck can help buyers review these paths without assuming that one model fits every organisation.
Why Buyers Choose FourTeck
A cloud identity licence affects security policy, user experience and recurring cost, so buyers need more than a line item. FourTeck focuses on the practical buying questions that help organisations prepare a workable order and deployment plan.
FourTeck also helps buyers understand when a different product may be more suitable. Cloud identity is not automatically the answer for every environment. Some organisations need local authentication appliances, hardware tokens, privileged access control or broader network access management. A useful supplier should help clarify those differences before the order is approved.
Frequently Asked Questions
What is FortiIdentity Cloud used for?
It is a cloud-native identity and access management service used to strengthen user authentication and control access to supported resources. Common functions include multi-factor authentication, single sign-on, local identity-provider services, identity-provider proxying, adaptive policy and passwordless authentication. Organisations can use it for FortiGate access, remote users, administrators and compatible third-party applications.
Is FortiIdentity Cloud Africa available for business buyers?
Businesses can contact FourTeck for current availability, licensing and quote assistance. The final commercial option depends on user quantity, annual term, selected order code, supplier status, destination and implementation scope. Buyers should provide a user count, application list and preferred authentication methods so the request can be reviewed accurately.
Does the service require a physical appliance?
The service is cloud managed and is designed to provide identity functions without a dedicated local authentication appliance. The wider environment may still include FortiGate firewalls, hardware tokens or other infrastructure. Organisations that require extensive local RADIUS, certificate or appliance-based services should compare the cloud option with a suitable FortiAuthenticator platform.
How is the subscription licensed?
Annual licensing is based on end-user quotas and volume tiers. Current documentation lists tiers for 25–499, 500–1,999, 2,000–9,999 and 10,000 or more users. Licences can be stacked and co-termed, allowing added user capacity to align with an existing renewal date. Exact quantities and minimum-order requirements should be confirmed during quotation.
Which authentication methods are supported?
Supported methods include mobile one-time passwords, push approval, SMS OTP, email OTP, compatible hardware tokens and FIDO2 passkeys. The correct method depends on user devices, connectivity, security policy, application support and recovery requirements. A mixed-method deployment may be appropriate when administrators and general users have different risk profiles.
Can it provide single sign-on for applications?
The service supports identity-provider and identity-provider proxy functions for SAML and OIDC application scenarios. Compatibility should be confirmed for each application because federation behaviour depends on supported standards, claims, certificates and configuration. Buyers should list the target applications and current identity provider before requesting implementation assistance.
Are SMS messages included with annual licences?
Current annual licence descriptions include 125 SMS credits per licensed user per year. Credits are shared within the account, and the number consumed can vary by destination rate. Organisations expecting regular SMS authentication should estimate usage and consider additional credit licences or alternative factors such as push, mobile OTP or passkeys.
Can FourTeck help with configuration planning?
Yes. FourTeck can help buyers review user quantities, protected systems, authentication methods, federation requirements, SMS usage, renewal timing and deployment scope. The commercial proposal can distinguish between licence supply, guided setup and broader implementation assistance. Final service availability should be confirmed for the project location and schedule.
What information is needed for a quote?
Provide the number of users, required subscription term, FortiGate models or protected applications, preferred MFA methods, estimated SMS use, desired rollout date and destination. Also state whether the project needs hardware tokens, additional credits, federation setup, adaptive policy, user enrolment, testing or administrator training.
Can businesses request bulk or multi-site supply?
Yes. Businesses, system integrators and managed service providers can request pricing for larger user populations or multi-site projects. The request should separate user quantities, customer realms, billing entities, renewal dates and rollout phases where necessary. FourTeck can help structure the commercial requirement so the selected licence tiers and quantities match the planned deployment.
Need Help Planning Secure Cloud Identity?
FourTeck can help review user quantities, authentication methods, application integrations, subscription options, renewal planning and regional procurement requirements. Share your access goals and rollout schedule to receive a practical quote.


Reviews
There are no reviews yet.