Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · Network Security

FortiClient (Unified Endpoint Agent)

VPN, ZTNA, endpoint protection, vulnerability scanning and Security Fabric telemetry in one enterprise agent.

Quick answer

FortiClient is Fortinet's unified endpoint agent. IPsec and SSL VPN, Zero Trust Network Access (ZTNA), endpoint protection (EPP), vulnerability scanning, web and video filtering, CASB and Security Fabric telemetry all run inside the same piece of software. Policies are distributed from a single console through FortiClient EMS or the cloud-hosted FortiClient Cloud; the agent installs only the licensed modules.

FortiClient is Fortinet's unified endpoint agent: IPsec and SSL VPN, Zero Trust Network Access (ZTNA), endpoint protection (EPP), vulnerability scanning, web and video filtering, CASB and Security Fabric telemetry all run inside the same piece of software. Central management is handled by FortiClient EMS (Endpoint Management Server) or the cloud-hosted FortiClient Cloud; the agent stays as lightweight as possible by installing only the licensed modules.

This unification is not a matter of preference for simplicity but a necessity imposed by the threat picture. According to Verizon's 2025 Data Breach Investigations Report, vulnerability exploitation reached 20% as the initial access vector in breaches, and 22% of exploitation actions directly targeted edge devices and VPNs — in the previous report that figure was 3% (Verizon DBIR, 2025). The same report measured that organizations were able to fully remediate only around 54% of their edge device vulnerabilities, and that this took a median of 32 days. In other words, the enterprise VPN headend is now targeted as "the way in".

The answer to this picture is to move access from the network layer to the application layer and to re-verify the device's security state on every session. That is precisely FortiClient's ZTNA role; keeping the VPN module in the same agent makes it possible to carry out the transition without turning it into a single, disruptive cutover. Below we detail what FortiClient does, its relationship with FortiEDR and FortiSASE, EMS requirements, and the compliance context in Turkey.

What exactly does FortiClient do, and why is it called a "unified agent"?

FortiClient consolidates into a single piece of software the work of several security agents that would normally be installed separately on an endpoint. Fortinet calls this the "Unified Agent" and states its purpose plainly: reducing agent sprawl. The FortiSASE data sheet notes that FortiClient delivers EPP, ZTNA, SSE, CASB, digital experience monitoring (DEM), Sandbox, vulnerability management and USB device control together in a single agent (Fortinet FortiSASE Data Sheet, 2026).

In practice this means a single package installed on the endpoint takes on the following jobs: providing the user's access to company resources (VPN or ZTNA), measuring the device's security posture before that access, scanning and reporting vulnerabilities on the device, blocking malware and exploit attempts, filtering web and SaaS traffic, and feeding the telemetry of all of it into the Security Fabric. The FortiClient agent also serves as the client component for other Fortinet products such as FortiSASE, FortiNAC, FortiPAM and FortiMonitor (Fortinet FortiClient Data Sheet, 2025).

  • Secure access: MFA-enabled IPsec and SSL VPN, per-application split tunnel, autoconnect and always-on VPN, dynamic VPN gateway selection.
  • Universal ZTNA: an automatically encrypted tunnel to the FortiOS ZTNA application gateway and per-session identity/device verification.
  • Endpoint protection: FortiGuard-powered AI-based NGAV, anti-exploit, application firewall, removable media control, behavior-based ransomware protection and rollback.
  • Vulnerability management: endpoint vulnerability scanning, patch policy enforcement and software inventory.
  • Content inspection: FortiGuard web and video filtering, keyword-based blocking, YouTube channel filters; inline and API-based CASB.
  • Telemetry and compliance: real-time endpoint visibility in the FortiGate console, security posture tags and automatic quarantine.

What is the difference between FortiClient and FortiEDR?

Short answer: FortiClient is the access and prevention layer, while FortiEDR is the detection and response layer. FortiClient connects a user securely to corporate applications, measures the device's compliance and tries to block known malware before it runs. FortiEDR is designed to stop, at runtime, behavior that gets past that block or has no signature at all, to reconstruct the chain of the incident and to respond. The two are not competitors but consecutive layers, and in most enterprise fleets they are positioned together.

DimensionFortiClientFortiEDRFortiSASE
Product typeUnified endpoint agentEDR / XDR platformCloud-based SASE service
Primary jobSecure access (ZTNA, VPN), preventive endpoint protection, vulnerability scanning, compliance and telemetryPost-infection detection, blocking, forensic timeline and automated responseInspecting user traffic in the cloud: SWG, ZTNA, CASB, FWaaS, SSPM, secure browser, secure SD-WAN, end-to-end DEM
Where it runsWindows, macOS, Linux, iOS, Android, ChromeOSWindows XP SP2 through Windows 11, Windows Server 2003 SP2 through Server 2025; Android 9.0+, iOS 15.0+Fortinet's global PoP network; on the endpoint, again FortiClient as the client
ManagementFortiClient EMS (on premises) or FortiClient CloudFortiEDR console; RBAC and a REST API covering all console operationsFortiSASE portal; the EMS instance inside it registers and manages the FortiClients
How they relateA FortiSASE licence includes the FortiClient licencePositioned alongside FortiClient on the same endpointUses FortiClient as its endpoint agent
When it is neededOn every client fleet with remote/hybrid workersWhen there is SOC maturity or a need for managed responseWhen distributed user traffic must be inspected without backhauling it to central hardware

Two data points make the difference concrete. The first is coverage: FortiEDR supports legacy operating systems going back as far as Windows XP SP2 and Windows Server 2003 SP2, which is decisive for unpatchable machines on a production line or next to a medical device (Fortinet FortiEDR Data Sheet, 2025). The second is footprint: according to the same data sheet, the FortiEDR agent uses 1–2% CPU, 200–350 MB of memory and 750 MB–1 GB of disk, meaning the cost of running a second agent alongside FortiClient is measurable.

On detection performance, in its own assessment of the fourth round of the MITRE Engenuity ATT&CK Evaluations (the Wizard Spider and Sandworm scenarios) Fortinet stated that FortiEDR blocked 100% of the attacks, detected 97% of the 90 non-Linux steps and reported 93% of the sub-steps at the "technique" level (Fortinet Blog, 2022). These figures are Fortinet's own statement; they come from the vendor's interpretation of the results rather than from MITRE's independent publication, and should be read that way. For FortiEDR's capabilities in detail, see our FortiEDR page.

How do FortiClient and FortiSASE work together?

FortiSASE does not introduce a separate agent; it uses FortiClient as its endpoint agent, and the FortiSASE licence covers the FortiClient licence. In this scenario you do not deploy EMS yourself: an EMS instance running inside FortiSASE registers and manages all the FortiClients. Automatically encrypted tunnels are established between FortiClient and the FortiSASE PoPs, and the vulnerability assessment performed by FortiClient is passed to FortiSASE as an input to ZTNA application access decisions (Fortinet FortiClient Data Sheet, 2025).

The decision point is this: where do you want inspection to happen? If you want to bring traffic back to a FortiGate firewall in the corporate data center and inspect it there, the FortiClient + FortiGate pair is sufficient. If users are distributed, the number of branches is low and pulling traffic to headquarters creates latency, moving inspection to the cloud makes sense; FortiSASE delivers SWG, ZTNA, CASB, FWaaS, SSPM, secure browser, secure SD-WAN and end-to-end DEM on a single platform, and Fortinet states that as of August 2026 it serves through more than 200 PoPs (Fortinet FortiSASE, 2026). Fortinet also states that it commits to a latency-guaranteed 99.999% SLA for FortiSASE and that the service holds SOC 2 Type II certification against the AICPA Trust Services criteria (Fortinet FortiSASE Data Sheet, 2026).

In practice we see three scenarios: FortiClient + FortiGate only (the classic enterprise network), FortiClient + FortiSASE (distributed users, cloud inspection) and a mixed model (head office through FortiGate, mobile users through FortiSASE). Because the same agent runs in all three, the user experience and the policy language do not change.

How does ZTNA work, and can it really replace the enterprise VPN?

ZTNA connects the user not to the network but directly to a single application, and re-evaluates the connection on every session. The Fortinet architecture has three components: FortiClient as the ZTNA agent, FortiClient EMS as the source of identity and device posture, and FortiGate as the ZTNA application gateway that enforces the access decision. This architecture was introduced with FortiOS 7.0 (Fortinet Document Library, FortiOS 7.0).

The flow works like this: EMS assigns zero trust tags to the device based on measurements such as operating system version, patch state, antivirus activity, disk encryption and running/stopped services. When FortiClient establishes a connection it carries these tags along with a client certificate; the FortiGate's ZTNA access proxy grants or denies access based on the tags. The same logic applies on the FortiSASE side: the FortiSASE Endpoint Management Service applies the ZTNA tagging rules and the access decision is made according to the client's tags (Fortinet FortiSASE Architecture Guide, 2026).

The honest answer to "does it replace the VPN?" is: in most access scenarios yes, in all of them no. For web and TCP-based applications, ZTNA offers both a narrower access surface and a better user experience. But for legacy protocols, management workstations that require very broad network access, or cases where third-party tools operate at the network level, IPsec/SSL VPN is still needed. Fortinet's design choice points the same way: having VPN and ZTNA in the same agent makes it possible to migrate application by application rather than all at once, and to spread the risk.

Which FortiClient edition includes which functions?

The ordering information table in the current FortiClient data sheet defines four editions: VPN/ZTNA, VPN/ZTNA + EPP/ATP, Managed and Chromebook. One common misreading deserves attention here: "Zero Trust Security" in the bundle table is not an edition name but the heading of the feature group that comes with the VPN/ZTNA edition. The frequently repeated claim that "the FortiClient Free version is enough for VPN" is out of date: no edition named "Free" is listed in the data sheet. The free, VPN-only client that existed in the past does not appear in today's product matrix; for enterprise use, EMS or FortiClient Cloud is required for central management in any case (Fortinet FortiClient Data Sheet, 2025).

EditionScopePlatform
VPN/ZTNAZero Trust agent with MFA, security posture tagging rules, central management with EMS or FortiClient Cloud, dynamic Security Fabric connector, vulnerability agent and remediation, SSL and IPsec VPN with MFA, FortiGuard web and video filtering, inline and API-based CASB, FortiPAM support, central logging and reportingWindows, macOS, Linux
VPN/ZTNA + EPP/ATPEverything in the VPN/ZTNA scope plus potentially unwanted application (PUA) control, AI-powered NGAV, removable media control, automatic endpoint quarantine, application firewall, software inventory, ransomware protection, FortiClient Cloud Sandbox and FortiSandbox integrationWindows, macOS, Linux
ManagedThe VPN/ZTNA + EPP/ATP scope plus services delivered by Fortinet: initial cloud provisioning, endpoint onboarding, Security Fabric setup and integration, vulnerability monitoring, endpoint security monitoringWindows, macOS, Linux
ChromebookCentral management with EMS or FortiClient Cloud, FortiGuard web and video filtering, central logging and reportingChromeOS

Two footnotes matter. The central logging and reporting function requires FortiAnalyzer; FortiClient on its own does not provide long-term log retention and reporting. The CASB row covers both inline CASB on the FortiGate and the API-based FortiCASB service. All editions include 24/7 support. The on-premises and air-gapped installation option, however, is not valid for every edition: the Managed edition is by definition built on Fortinet's team provisioning the FortiClient Cloud environment. We clarify at the quotation stage whether your hosting preference is compatible with the edition you choose.

Which features work on which operating systems?

FortiClient covers desktop, server and mobile platforms together; however, not every module works to the same degree on every platform. The table below summarizes the list of supported operating systems in the current FortiClient data sheet and the limitations noted in the official footnotes (Fortinet FortiClient Data Sheet, 2025).

PlatformSupported versionWhat to watch out for
WindowsWindows 10 (32- and 64-bit), Windows 11 (64-bit), Windows Server 2019 and laterBehavior-based ransomware protection and rollback are supported on Windows only. ARM-based processor support is in beta and offers a limited feature set.
macOSmacOS 10.15 and laterZero Trust and EPP modules are supported; ransomware rollback is Windows-specific.
LinuxUbuntu 22.04 and later, Red Hat 9 and later, CentOS 9.0 and later (with the KDE or GNOME desktop)The Linux build does not support Sandbox integration.
iOSiOS 9.0 and laterMobile scope focuses on access and telemetry.
AndroidAndroid 5.0 and laterMobile scope focuses on access and telemetry.
ChromeOSAll Chromebook versionsLicensed through a separate Chromebook edition; scope is limited to management, web/video filtering and logging.
FortiClient EMS (server)Windows Server 2022 and later, or Ubuntu 22.04 / 24.04 LTS ServerRequires a minimum of 6 virtual CPUs, 12 GB RAM, 80 GB free disk and a Gigabit Ethernet interface.

On ARM-based Windows devices, the beta feature set is limited to the Security Fabric agent (EMS connection and telemetry), remote access (VPN), web filtering and vulnerability scanning. If a mixed fleet contains ARM devices, they should be managed as a separate EMS group and policy expectations set accordingly. On the authentication side, RADIUS, LDAP, local database, xAuth, TACACS+, digital certificates in X.509 format and FortiToken are supported.

What is FortiClient EMS and what resources does it require?

FortiClient EMS is the central brain of the agent fleet: policy distribution, remote installation and controlled upgrade, inventory, the vulnerability dashboard, zero trust tagging rules and quarantine management are all handled here. In an on-premises installation, EMS runs on Windows Server 2022 and later or on Ubuntu 22.04 / 24.04 LTS and requires a minimum of 6 virtual CPUs, 12 GB RAM and 80 GB of free disk; managed endpoints are expected to run FortiClient 7.2 or later (Fortinet FortiClient Data Sheet, 2025). The same functions are also offered as FortiClient Cloud for organizations that do not want to host a management server.

  • Identity integration: Active Directory and Microsoft Entra ID synchronization; using AD organizational units directly as endpoint groups.
  • Automatic grouping: automatic group assignment for dynamic access control and custom group definitions.
  • Software inventory: visibility of installed applications and licences; narrowing the attack surface by detecting and removing unnecessary or outdated software.
  • Vulnerability dashboard: listing vulnerable endpoints on a single screen and enforcing patch policy on devices even when they are off the network.
  • Central quarantine and remote actions: disconnecting a suspicious device from the network, remote scanning and reconfiguration.
  • Deployment: creating custom FortiClient installation packages, pushing configuration to thousands of clients with one click, automatic email alerts.

Sizing EMS correctly is the step most often skipped in a project. Your endpoint count, telemetry frequency, vulnerability scanning interval and log destination all directly affect EMS's disk and memory requirements. In enterprise fleets we recommend deploying EMS redundantly and separating the log stream onto FortiAnalyzer.

What does Security Fabric telemetry deliver in practice?

Telemetry is FortiClient's least discussed function but the one with the highest operational value. The agent passes device identity, user, installed software, vulnerability state and security events to FortiGate and FortiAnalyzer; in the FortiGate console, endpoints become visible on a per-user basis. The virtual groups produced by EMS can be used directly in FortiGate firewall policies — meaning a rule such as "a device with antivirus disabled cannot reach the finance application" turns into an enforceable policy line without maintaining lists by hand.

The payoff of this loop shows up in incident response: an endpoint that matches an indicator of compromise (IOC) can be automatically quarantined while the related sessions are cut on the FortiGate at the same moment. On the FortiAnalyzer side, the FortiGuard IOC service provides forensic data with 500,000 IOCs per day (Fortinet FortiAnalyzer Data Sheet, 2026). The Security Fabric, the broader context of this integration, provides unified visibility across an ecosystem that spans more than 500 third-party solutions in addition to Fortinet products, and FortiGuard Labs processes and analyzes more than 100 billion events every day (Fortinet About Us, 2026).

The same telemetry also connects to the wired and wireless access layer. In networks built with FortiSwitch and FortiLink, endpoint posture can feed into port-level segmentation and quarantine decisions. You can review the whole Fortinet product family together on our Fortinet solutions page.

Where does FortiClient fit in KVKK and PCI DSS compliance?

FortiClient on its own does not provide a compliance certificate; it does, however, directly produce several technical measures for which evidence is requested in audits: up-to-date anti-virus systems, network security controls, access logs, vulnerability tracking and intrusion detection. All of these items are listed in the technical measures table of the Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law), and the guide explicitly requires regular vulnerability scanning across information networks and regular logging of user transaction activity (KVKK Personal Data Security Guide, 2018).

For organizations processing card data there is a more specific requirement. PCI DSS v4.0 requirement 1.5.1 mandates that security controls be implemented on devices that can connect both to an untrusted network and to the cardholder data environment (CDE) — typically the laptop of a user working from home (PCI Security Standards Council, PCI DSS v4.0). FortiClient's security posture tags, application firewall and ZTNA access policy respond directly to this requirement; thanks to ZTNA, the remote user connects not to the whole network but only to the application they are authorized for, which also simplifies the scope discussion.

In the Turkish context, three practical headings stand out: documenting the installation and policy design in Turkish, pre-templating the log and vulnerability reports requested in KVKK audits, and — in institutions within BDDK (Turkey's banking regulator) scope — retaining access control records in an auditable form. Designing all three during deployment costs far less than leaving them to audit season.

How does FortiClient licensing work?

There are two models and both offer the same functions: traditional device-based licensing and user-based FortiTrust licensing. In the FortiTrust model, a single user can install FortiClient on at most three devices; for an employee using a laptop, a phone and a tablet, one licence is enough (Fortinet FortiClient Data Sheet, 2025). For managed service providers there is also a subscription-based FortiFlex option.

The second decision is where EMS will sit: cloud-hosted EMS (SaaS) or an on-premises installation? Organizations with data residency or air-gapped network requirements prefer an on-premises installation; for those prioritizing rapid rollout, cloud hosting is more practical. The third decision is the edition: secure access only (VPN/ZTNA), or endpoint protection as well (VPN/ZTNA + EPP/ATP)? The fourth is who will handle deployment and monitoring — the Managed edition includes Fortinet's onboarding and monitoring services; alternatively, Sora Yazılım takes on the same work as a managed service.

There are two further subscriptions: the Best Practice Service (BPS), which provides remote guidance on deployment and operations, and the FortiClient Forensics Analysis Service, which gives access to FortiGuard Labs forensic analysts during an incident. The latter is sold as an annual subscription rather than per incident. We do not publish prices on this page; for a quote configured to your user count, edition, term and hosting preference, get in touch with us.

How is a VPN-to-ZTNA migration project planned?

Trying to do the migration in one go is the most common mistake. Because FortiClient hosts VPN and ZTNA in the same agent, it is possible to build a phased plan that advances application by application; no new software installation is needed on the user side, only the policy changes. Our typical project flow is as follows:

  • Inventory and classification: establishing who accesses which applications from which device; separating web/TCP-based applications for ZTNA from those that will remain on VPN.
  • Posture policy design: defining zero trust tags based on operating system version, patch level, antivirus state, disk encryption and vulnerability threshold.
  • EMS deployment and AD/Entra ID integration: deriving groups from the identity source and producing custom installation packages.
  • Enabling the ZTNA gateway on the FortiGate: certificate infrastructure, access proxy configuration and publishing the first application.
  • Pilot: validation with a limited user group under real workloads; distinguishing whether access denials are policy errors or genuine non-compliance.
  • Phased rollout and narrowing the VPN: removing each application moved to ZTNA from the VPN access list; leaving VPN only for mandatory scenarios.

The duration varies with the size of the organization, the number of applications and the maturity of the identity infrastructure; a schedule that can be committed to is only possible after the inventory has been produced. If a model needs to be chosen on the FortiGate side for the ZTNA gateway, mid-range models such as the FortiGate 100F cover most branch and medium office scenarios.

What does Sora Yazılım provide in FortiClient projects?

As a Fortinet authorized channel partner, we provide FortiClient and FortiClient EMS licensing, deployment, migration from the existing VPN infrastructure and the subsequent managed service from a single source. Our scope extends from choosing the edition and licence model to sizing EMS, from writing zero trust tag policies to configuring the FortiGate ZTNA gateway, and from the user onboarding campaign to reporting templates ready for a KVKK audit. For organizations that want a comparison with a different vendor on the endpoint side, we also evaluate alternatives such as Bitdefender at the same table.

If integration is needed on the identity, directory and automation side, our DevOps and infrastructure services come into play: connecting EMS installation packages to deployment tools, feeding inventory and vulnerability data into your existing reporting pipeline, and automating the endpoint lifecycle. For organizations that also want to cover phishing risk on the email side, we position FortiMail alongside it.

Next step: share your current VPN user count, your operating system distribution and the list of applications being accessed, and let us prepare a proposal covering the FortiClient edition that suits you, the EMS architecture (cloud or on premises) and a phased ZTNA migration plan. To evaluate it together with deployment, migration and managed service options, contact us through our contact page.

Key features

What it offers

  • ZTNA, IPsec VPN and SSL VPN in a single agent
  • MFA-enabled Zero Trust agent and security posture tagging rules
  • FortiGuard-powered AI-based NGAV and anti-exploit
  • Behavior-based ransomware protection and rollback (Windows only)
  • Endpoint vulnerability scanning, patch policy enforcement and remediation
  • Attack surface reduction through software inventory
  • FortiGuard web and video filtering, keyword and YouTube channel filters
  • Inline and API-based CASB (FortiCASB licence included)
  • Per-application split tunnel, autoconnect and always-on VPN
  • FortiClient Cloud Sandbox and FortiSandbox integration
  • FortiGate telemetry, dynamic access control and automatic endpoint quarantine
  • Central management and remote deployment with FortiClient EMS or FortiClient Cloud
  • Active Directory and Microsoft Entra ID integration
  • Shared client component for FortiSASE, FortiNAC and FortiPAM
Tech Summary

Important technical data

Supported client platforms
Windows 10 (32/64-bit), Windows 11 (64-bit), Windows Server 2019+, macOS 10.15+, iOS 9.0+, Android 5.0+, Linux (Ubuntu 22.04+, Red Hat 9+, CentOS 9.0+), all Chromebook versions
Editions
VPN/ZTNA, VPN/ZTNA + EPP/ATP, Managed, Chromebook (the names in the data sheet ordering table)
Central management
FortiClient EMS (on premises) or FortiClient Cloud (cloud-hosted)
EMS operating system
Windows Server 2022 and later, or Ubuntu 22.04 / 24.04 LTS Server
EMS minimum resources
6 virtual CPUs (2.0 GHz 64-bit), 12 GB RAM, 80 GB free disk, Gigabit Ethernet
Managed endpoint requirement
FortiClient 7.2 and later (7.0 for iOS and Android)
Licence models
Device-based licence bundles or FortiTrust user-based licence; FortiFlex for MSSPs
FortiTrust device limit
Maximum 3 devices per user under the user-based licence
Authentication options
RADIUS, LDAP, local database, xAuth, TACACS+, X.509 digital certificate, FortiToken
ZTNA architecture
FortiClient (ZTNA agent) + FortiClient EMS (identity and posture) + FortiGate (ZTNA application gateway); introduced with FortiOS 7.0
Platform limitations
Ransomware protection and rollback on Windows only; the Linux build does not support Sandbox integration; ARM-based Windows support is beta and offered with a limited feature set
Central logging
FortiAnalyzer is required for central logging and reporting
Additional services
Best Practice Service (BPS), FortiClient Forensics Analysis Service (annual subscription), Managed FortiClient Service
Relationship with FortiSASE
A FortiSASE licence includes the FortiClient licence; agents are managed by the EMS instance inside FortiSASE
Use Cases

When would you choose this product?

Finance

Pre-access compliance on branch and head office laptops

In banking and finance institutions, every laptop passes a FortiClient posture check before connecting to a corporate application: operating system patch level, antivirus activity, disk encryption and local firewall state are verified. A non-compliant device is marked with a zero trust tag and FortiGate policy restricts its access.

Retail / E-commerce

Administrator workstations accessing the cardholder data environment remotely

PCI DSS v4.0 requirement 1.5.1 calls for security controls on devices that can connect both to an untrusted network and to the cardholder data environment. With FortiClient ZTNA, the remote administrator connects not to the whole network but only to the application they are authorized for; posture tags and the application firewall produce audit evidence.

Manufacturing

Field engineers and mobile maintenance teams

On the laptops of maintenance teams working outside the company network, FortiClient vulnerability scanning and patch policy are applied without the device ever coming to the office. With per-application split tunnel, traffic that consumes high bandwidth is kept outside the tunnel while corporate traffic remains protected.

Public sector

Phased move to ZTNA for staff connecting from outside the institution

In public institutions with broad SSL VPN access, applications are moved to ZTNA one at a time. Because VPN is present in the same agent, no software change is needed on the user side; each application that is moved is removed from the VPN access list, narrowing the access surface step by step.

Education

Content filtering across a Chromebook and mixed device fleet

In schools and universities, ChromeOS devices with the Chromebook edition and Windows and macOS devices with the standard edition are managed from the same EMS console. FortiGuard web and video filtering, keyword blocking and YouTube channel restrictions are applied with a single policy set.

Who is it for?

Enterprise IT and information security teams with remote and hybrid users that want to reduce SSL VPN dependency and need to prove endpoint compliance in an auditable way; organizations with reporting obligations under KVKK, PCI DSS or BDDK.

Frequently Asked Questions

Frequently asked questions

Is there a free version of FortiClient?
No edition named "Free" is listed in the current FortiClient data sheet. The editions defined in the data sheet's ordering table are VPN/ZTNA, VPN/ZTNA + EPP/ATP, Managed and Chromebook ("Zero Trust Security" is not an edition name but the heading of the feature group that comes with VPN/ZTNA). A free, VPN-only client existed in the past; it does not appear in today's product matrix, and for enterprise use EMS or FortiClient Cloud is required for central management.
What is FortiClient EMS, and does it run in the cloud or on premises?
EMS (Endpoint Management Server) is the central console for FortiClient agents: policy distribution, remote installation and upgrade, software inventory, the vulnerability dashboard, zero trust tagging rules and quarantine management are all handled here. In an on-premises installation it runs on Windows Server 2022+ or Ubuntu 22.04/24.04 LTS; for organizations that prefer the cloud, the same functions are offered as FortiClient Cloud.
What is the difference between FortiClient and FortiEDR, and are both needed?
FortiClient is the access and prevention layer: ZTNA/VPN, endpoint protection, vulnerability scanning and compliance. FortiEDR is the detection and response layer: post-infection behavioral blocking, forensic timeline and automated response. In organizations with SOC maturity or a managed response service, the two are positioned together; they run alongside each other on the same endpoint.
If I buy FortiSASE, do I also need to buy a FortiClient licence?
No. According to Fortinet's FortiClient data sheet, the FortiSASE licence includes the FortiClient licence and FortiClient is used as the endpoint agent. In this scenario the EMS instance inside FortiSASE manages the agents; you do not need to deploy a separate EMS.
Which types of application does ZTNA work with, and can I remove VPN entirely?
ZTNA is designed for web (HTTP/HTTPS) and TCP-based applications and can replace VPN for most access within that scope. IPsec/SSL VPN continues to be needed for legacy protocols, management workstations that require broad network access, and third-party tools that operate at the network level. Having VPN and ZTNA in the same agent makes it possible to migrate application by application.
What does the security posture check look at?
The zero trust tagging rules defined in EMS look at criteria such as operating system version, patch level, antivirus activity and currency, disk encryption, local firewall state, detected vulnerabilities and running/stopped services. The device is tagged, and the FortiGate ZTNA access proxy grants or denies access based on those tags.
What level of Linux and macOS support is there?
macOS 10.15 and later and Linux (Ubuntu 22.04+, Red Hat 9+, CentOS 9.0+) are supported. There are two important limitations: behavior-based ransomware protection and rollback work on Windows only, and the Linux build does not support Sandbox integration. In mixed fleets, policy expectations need to be set per platform.
Is licensing per device or per user?
Both models are available and offer the same functions. Device-based licence bundles are the classic approach; under the FortiTrust user-based licence, a single user can install FortiClient on at most three devices. For managed service providers there is a subscription-based FortiFlex option. Because pricing varies with user count, edition and term, we proceed on a quotation basis.
Where are FortiClient logs stored?
The central logging and reporting function requires FortiAnalyzer; FortiClient and EMS on their own do not provide long-term log retention and compliance reporting. On the FortiAnalyzer side, the FortiGuard IOC service provides forensic data with 500,000 IOCs per day, and ready-made compliance reports such as PCI-DSS can be produced.
Which steps does Sora Yazılım take on in a FortiClient project?
Edition and licence model selection, EMS sizing and deployment (cloud or on premises), Active Directory / Microsoft Entra ID integration, design of zero trust tag policies, FortiGate ZTNA gateway configuration, user onboarding with custom installation packages, phased migration from VPN to ZTNA, and managed service afterwards. For scope and a quote you can reach us through our contact page.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

FortinetFortiClient (Unified Endpoint Agent)
Related Services

Services we deliver alongside this product

FortiClient (Unified Endpoint Agent) licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support