This article describes why the Dynamic VLAN assignment feature gets disabled
Scope
FortiGate, SSID.
Solution
By default, the Dynamic VLAN assignment is disabled.
This feature is useful when users need to change the VLAN automatically after changing the connected AP.
See the following image for reference:
By default, it is disabled. However, it can be enabled connect to the RADIUS server to authenticate the user continually while the user is moving across different APs.
As shown above, the Dynamic VLAN assignment is enabled.
However, it will get disabled automatically if the Security method of the particular AP is changed.
As shown in the image above, changing the security method disabled the RADIUS server settings, which meant the Dynamic VLAN assignment settings were disabled.