FortiSAT - Configuration Steps

Modified on Wed, 20 May at 5:50 PM

The FortiSAT product has 2 service components: 

The InfoSec Awareness and Training Service
The Phishing Simulator Service

Customers may purchase one service or the other, or both services. The SKU(s) issued will determine what service(s) you are entitled to.

Account Creation, Initialization and Configuration Steps:

  1. Create a FortiCloud account (if you do not already have one).
  2. Register the product code (to initialize the license / service if you do not already registered a license for a previous version).
  3. Access the service from:  https://fortisat.forticloud.com
  4. Configure the service(s) using the FortiSAT Administration Guide.  
If you have issues attempting to initialize or configure/customize the tenant, you can open a support by following these instructions:  How do I open a support ticket?

Follow these steps to initialize and configure the new FortiSAT service(s). 

STEP 1 - Domain verification and customization 

  1. Once initialized, you will need to verify your email domain(s). You can refer to this article:  Verifying domain ownership
  2. Once completed, you can customize your training URL (create a subdomain to your registered domain) by creating 'A' records using the appropriate url (depending on your licenses level): Coming Soon! (Currently in development.)
  3. Verifying your DNS TXT and 'A' records have been successfully created: Verifying DNS TXT and A record successful propagation

STEP 2 (Optional) - Configuring SSO (SAML2 single sign-on)

Coming Soon! (Currently in development)


STEP 3 (Optional) - Configure an SMTP account for sending of Security Awareness and Training Service communications (training invites, due date reminders, congratulations email, scheduled reports, etc.)

Configuring an SMTP email address for sending training related correspondence


STEP 4 - Managing Users

  1. IMPORTANT: Before importing users, set the default user language:  User Settings - Select Language (The user default language is set during user create (manual or .csv) or user synch (LDAP/S or SCIM (auto-provisioning)).
  2. Managing users via the Users page (importing users via .csv / single user)
  3. User Sync (LDAP Server) 
  4. User Sync (SCIM) - Auto-provisioning using Microsoft Entra/Azure/O365 or Google Workspace Directories

STEP 5 (Optional) - Customizing the appearance and notification templates

  1. You can customize the branding and appearance of your service using this article:  Coming Soon! (Currently in development.) 
  2. You can customize your notification templates using this article:  Coming Soon! (Currently in development.)

STEP 6 - Campaign Management


Nano Videos and Classroom Curriculum - Coming Soon! (Currently in development) 

  1. You can access support by opening a ticket here: Security Awareness and Training Service Support site (Select Infosec/Security Awareness and Training Service from the What is your request related to? drop down OR by sending an email to infosec_awareness@fortinet.com (one email per question / incident / enhancement) and providing a detail description with steps to reproduce and screenshots (if applicable). 
  2. For a description of module content, refer to this document: Fortinet Security Awareness and Training Service Course Modules
  3. For planning your campaigns, refer to these documents (this information is also covered in the Manager modules included in the service)

If you would like our assistance:

  1. Creating your FortiCloud / FortiCare Master Support Account. 
  2. Initializing the service (registering your product code(s)).
  3. Assisting in configuring the service(s).
  4. Assisting in testing the service(s).
  5. Walk you through the service(s).
We are assisting customers on a first come, first served basis. Our deployment coordinators are located in Eastern Time Zone (Ottawa, Ontario Canada). Please take this into consideration when choosing a time.

Could you please provide:
  1. Your time zone.
  2. Several dates and times next week and the week after that work for a 1.5 to 2 hour session to assist with above.
If you are not ready to initialize the service, please reply all with a date and time (as well as your time zone) on when we should next follow up to arrange the meeting.

For the call, we recommend you invite people who: 
  1. DNS TXT Records and A record creation.
  2. Single Sign-on (SAML2) configuration for authenticating learners to the training (if you wish to use an existing SSO solution).
  3. Configure SMTP sending account (if you wish to send training correspondence email from your internal email domain instead of the default:  noreply@ftnt.info
  4. LDAP (Active Directory) / SCIM (auto provisioning) configuration for the import of users (if you wish to import/synch your users from an LDAP Directory or a SCIM compliant auto provisioning solution) // For Active Directory, can create a firewall rule to allow traffic from our service to the Directory in order to harvest user information.
  5. Anyone who will manage training and/or phishing campaigns and would benefit from a demo / walk through of the system.
  6. If you are deploying FortiPhish, we require the individuals that can add exceptions to all smtp and security servers/services in your mail flow to allow FortiPhish emails to arrive well formed in users' inboxes.  
One of our Deployment Specialists can then schedule something in with you.

NOTE:  This onboarding service is only available in English. We do not provide translation services. If you do not have an English speaking resource, please invite a bilingual representative from your organization. If you do not have one, perhaps your partner or your Fortinet Account Owner can assist (copied)

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article