Access & Endpoint Security
Who gets on, from what device, with what privilege. Endpoint detection and response, the ZTNA agent, multi-factor tokens, identity services and privileged access management.
Where to start
Who gets on the network, from what device, with what privilege, and what happens on the endpoint once they are there. Endpoint detection and response, the ZTNA agent, multi-factor tokens, identity services and privileged access management.
Two things in this section deserve disproportionate attention. The first is that privileged credential compromise is how a foothold becomes a breach, which makes privileged access management one of the highest-leverage controls available and one of the most commonly absent. The second is that multi-factor authentication on firewall administrative access is the cheapest meaningful control on this entire site; it protects the highest-value credential in the estate.
Check the FortiClient platform matrix against your actual device fleet before licensing. Windows and macOS carry the full feature set; Linux and Chromebook support is partial, and mobile platforms carry ZTNA and VPN but not the endpoint-protection options. A Linux-heavy estate gets partial coverage, and that is better known before rollout than during it.
Decide these first
What is your actual device mix?
Platform coverage is not uniform, and the licence tiers differ substantially in what they include. Buying the cheapest tier and discovering it lacks endpoint protection is a common and avoidable mistake.
ZTNA or VPN?
ZTNA grants access per application rather than per network, which removes the lateral movement a VPN permits. For contractors and third parties this is usually the deciding argument; FortiClient does both during migration.
How many privileged accounts exist?
Most organisations do not know, and establishing the number is often the first deliverable of a PAM project.
Does your firewall support the MFA rollout you are planning?
Every FortiGate has a built-in FortiToken ceiling, 500 on entry-level models, 20,000 at the high end. A growing organisation genuinely reaches 500.
Browse access & endpoint security
FortiEDR / FortiXDR
Endpoint detection and response that blocks at execution, not after
2 products →FortiClient (ZTNA / EPP-APT / SASE)FortiClient Fabric Agent
The endpoint agent, VPN, ZTNA, posture and endpoint protection in one client
1 product →FortiToken / FortiToken Mobile / FortiToken CloudFortiToken Multi-Factor Authentication
Two-factor authentication for VPN, admin access and applications
1 product →FortiAuthenticator (FAC-300F / 800F / 3000F / VM)FortiAuthenticator Identity Management
Identity, SSO, certificates and 802.1X for the Fabric
4 products →FortiPAMFortiPAM Privileged Access Management
Control, broker and record the credentials that actually matter
1 product →