Skip to main content
adriellousada
Staff
Staff
May 21, 2026

Technical Tip: How to configure application exclusions for vulnerability compliance tags

  • May 21, 2026
  • 0 replies
  • 46 views

Description

This procedure details how to exclude vulnerabilities detected on the endpoint for Security Posture TAGs detection.

Scope

 FortiClient EMS.

Solution

  1. To exclude certain applications from the Security Posture Tags check, access EMS, and edit the 'Vulnerability Scan' profile.

  2. Locate the 'Exclusions' section:

  3. Enable the 'Exclude Selected Applications from Vulnerability Compliance Check' option:

  4. Select the applications to be excluded:

    69e6b7c2.png


  5. Next, check the rule configuration for TAG detection.

  6. In this example, the configuration ensures that only computers without 'High or Higher' vulnerabilities receive the TAG:

    f6dedbf5.png


  7. As demonstrated below, some applications present a 'High' severity level, but the following exclusions were created so that the computer can receive the TAG:

    c8056253.png


  8. Thus, even with the detection of vulnerabilities, the computer continues to receive the 'Compliance' tag:

    d7ebd7ce.png


The following example demonstrates that without the exclusion configuration, the 'Compliance' tag is not detected:

e6009e68.png


032174c8.png