FortiEDR
Blocks at execution rather than alerting after the fact
- Licensing
- Per endpoint, subscription term
- Platforms
- Windows, macOS, Linux (see FortiClient platform matrix)
- Deployment
- Cloud-managed or on-premises management
FortiEDR combines pre-execution prevention with post-execution detection and blocks malicious activity at the moment it runs. It can neutralise a threat while leaving the machine online, which matters when the machine is a clinical workstation or a production controller you cannot simply isolate.
For ransomware the window between execution and encryption is seconds, and that is the entire argument for blocking rather than detecting. Buy it as a managed service if you do not have 24/7 capacity to adjudicate detections, an EDR console nobody opens is not a control.
Highlights
- Blocks at execution, not detect-then-alert
- Neutralises threats without taking the host offline
- Feeds FortiXDR for cross-Fabric correlation
- Available as a managed service through DynaScale's SOC
Typical deployments
- Ransomware prevention on endpoints and servers
- Protecting legacy systems that cannot be patched
- Replacing signature antivirus with behavioural prevention
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Per endpoint, subscription term |
|---|---|
| Platforms | Windows, macOS, Linux (see FortiClient platform matrix) |
| Deployment | Cloud-managed or on-premises management |
| Response | Block at execution, isolate, remediate, roll back |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | Per endpoint, subscription term |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.