1. FortiAuthenticator 6.4 Administration Guide
Page 171
"High Availability" > "Synchronization".
This section provides a list of data that is not synchronized: "The following information is not synchronized between cluster members: FSSO logon events
RADIUS accounting data
Syslog data
Debug logs." This directly supports that FSSO events (C) are not synchronized.
The same section lists data that is synchronized
including: "Configuration"
"User data (local users
remote user sync data...)"
and "User certificates". This directly refutes option B and indirectly refutes A (as group mappings are part of the configuration).
2. FortiAuthenticator 6.2 Administration Guide
Page 160
"High Availability" > "Synchronization".
This guide contains the same lists
confirming that FSSO logon events (C) are not synchronized
while "User certificates" (B) and "FortiTokens" are synchronized. The synchronization of FortiTokens implies their essential data is replicated
but system-level seeds (D) for other cryptographic functions remain node-specific.