Fortinet white logo
Fortinet white logo

Administration Guide

Locking an ADOM

Locking an ADOM

If workspace is enabled, you must lock an ADOM prior to making changes in Policy & Objects, AP Manager, VPN Manager, FortiSwitch Manager, and Extender Manager, as well as performing any device-level changes to a device, such as upgrading firmware for a device.

Tooltip

When using the FortiManager API, the ADOM does not need to be locked in order to perform device-level changes.

Note

Policy packages, policies, objects, and devices can be individually locked. See:

In the GUI, the padlock icon shown next to the ADOM name on the banner and in the All ADOMs list will turn green when you lock an ADOM. If it is red, it means that another administrator has locked the ADOM.

When an ADOM is locked, other administrators are unable to make changes in that ADOM until you either unlock the ADOM, or log out of the FortiManager. Optionally, ADOM lock override can be enabled, allowing an administrator to unlock an ADOM that has been locked by another administrator and discard all of their unsaved changes.

To lock the ADOM you are in:
  1. Ensure you are in the ADOM that will be locked.
  2. Click Lock in the banner, next to the ADOM name.

    The padlock icon changes to a locked state, and the ADOM is locked.

To lock an ADOM from System Settings:
  1. Go to System Settings > All ADOMs.
  2. Right-click on the ADOM and select Lock, or select the ADOM then click Lock in the toolbar. You do not need to be in that ADOM to lock it.

    The padlock icon next to the ADOM's name changes to a locked state, and the ADOM is locked.

Locking an ADOM automatically removes locks on devices and policy packages that you have locked within that ADOM.

If you have unsaved changes, a confirmation dialog box will give you the option to save or discard them.

To unlock the ADOM you are in:
  1. Ensure you are in the locked ADOM.
  2. Ensure that you have saved any changes by clicking Save in the toolbar.
  3. Click Unlock in the banner, next to the ADOM name. Only the administrator who locked the ADOM can unlock it. If you have not saved your changes, a confirmation dialog box will give you the option to save or discard your changes.

    The padlock icon changes to an unlocked state, and the ADOM is unlocked.

To unlock an ADOM from System Settings:
  1. Go to System Settings > All ADOMs.
  2. Right-click on the locked ADOM and select unlock, or select the ADOM then click Unlock in the toolbar. You do not need to be in that ADOM to unlock it, but you must be the administrator that locked it. If you have not saved your changes, a confirmation dialog box will give you the option to save or discard your changes.

    The padlock icon next to the ADOM's name changes to a locked state, and the ADOM is unlocked.

All elements are unlocked when you log out of the FortiManager. If you have unsaved changes, a confirmation dialog box will give you the option to save or discard your changes.

To enable or disable ADOM lock override:

Enter the following CLI commands:

config system global

set lock-preempt {enable | disable}

end

Locking an ADOM

Locking an ADOM

If workspace is enabled, you must lock an ADOM prior to making changes in Policy & Objects, AP Manager, VPN Manager, FortiSwitch Manager, and Extender Manager, as well as performing any device-level changes to a device, such as upgrading firmware for a device.

Tooltip

When using the FortiManager API, the ADOM does not need to be locked in order to perform device-level changes.

Note

Policy packages, policies, objects, and devices can be individually locked. See:

In the GUI, the padlock icon shown next to the ADOM name on the banner and in the All ADOMs list will turn green when you lock an ADOM. If it is red, it means that another administrator has locked the ADOM.

When an ADOM is locked, other administrators are unable to make changes in that ADOM until you either unlock the ADOM, or log out of the FortiManager. Optionally, ADOM lock override can be enabled, allowing an administrator to unlock an ADOM that has been locked by another administrator and discard all of their unsaved changes.

To lock the ADOM you are in:
  1. Ensure you are in the ADOM that will be locked.
  2. Click Lock in the banner, next to the ADOM name.

    The padlock icon changes to a locked state, and the ADOM is locked.

To lock an ADOM from System Settings:
  1. Go to System Settings > All ADOMs.
  2. Right-click on the ADOM and select Lock, or select the ADOM then click Lock in the toolbar. You do not need to be in that ADOM to lock it.

    The padlock icon next to the ADOM's name changes to a locked state, and the ADOM is locked.

Locking an ADOM automatically removes locks on devices and policy packages that you have locked within that ADOM.

If you have unsaved changes, a confirmation dialog box will give you the option to save or discard them.

To unlock the ADOM you are in:
  1. Ensure you are in the locked ADOM.
  2. Ensure that you have saved any changes by clicking Save in the toolbar.
  3. Click Unlock in the banner, next to the ADOM name. Only the administrator who locked the ADOM can unlock it. If you have not saved your changes, a confirmation dialog box will give you the option to save or discard your changes.

    The padlock icon changes to an unlocked state, and the ADOM is unlocked.

To unlock an ADOM from System Settings:
  1. Go to System Settings > All ADOMs.
  2. Right-click on the locked ADOM and select unlock, or select the ADOM then click Unlock in the toolbar. You do not need to be in that ADOM to unlock it, but you must be the administrator that locked it. If you have not saved your changes, a confirmation dialog box will give you the option to save or discard your changes.

    The padlock icon next to the ADOM's name changes to a locked state, and the ADOM is unlocked.

All elements are unlocked when you log out of the FortiManager. If you have unsaved changes, a confirmation dialog box will give you the option to save or discard your changes.

To enable or disable ADOM lock override:

Enter the following CLI commands:

config system global

set lock-preempt {enable | disable}

end