Skip to main content
vpolovnikov
Staff & Editor
Staff & Editor
January 28, 2026

Troubleshooting Tip: How to verify whether FortiClient EMS site-wide endpoint disconnection was caused by 'Mark All Endpoints as Uninstalled' feature

  • January 28, 2026
  • 0 replies
  • 297 views
Description This article describes how to verify if a result of all FortiClients getting disconnected was caused by invoking 'Mark All Endpoints as Uninstalled' feature on FortiClient EMS.
Scope FortiCllient EMS.
Solution

Marking all endpoints as uninstalled is a feature that removes all endpoints from FortiClient EMS as described in

Marking all endpoints as uninstalled document in the administration guide.

 

Even though, there may be other reasons for endpoints getting disconnected from FortiClient EMS, this article focuses specifically on how to verify whether invoking 'Mark All Endpoints as Uninstalled' caused the disconnect event.

 

Note, uninstalling all endpoints in FortiClient EMS prior to v7.4.5 (7.4.0-7.4.4) can be done from under Endpoints -> All Endpoints by selecting Mark All Endpoints as Uninstalled from the Action drop-down list.

 

Screenshot 2026-01-27 at 3.24.13 PM.png

 

FortiClient EMS v7.4.5 has moved this feature to the Settings section and named it Uninstall All Endpoints.

 

Screenshot 2026-01-27 at 2.19.14 PM.png

 

Follow the steps below to validate whether endpoints disconnect has been caused by marking all endpoints as uninstalled:

  1. Collect FortiClient EMS Diagnostics Logs as described in the Generate Diagnostics Logs document.
  2. Open the archive and navigate inside the python_logs folder.
  3. Locate and open the most recent debug log file (i.e. debug_2026-01-18.log).
  4. Filter for the following line inside the file: 'marked FortiClients as uninstalled'.

If, indeed, the endpoints got disconnected due to FortiClient EMS administrator invoking 'Uninstall All Endpoints' feature, then a log similar to the one below will be shown (note the number of endpoints marked as uninstalled):

 

2025-12-18 21:33:56,200 DEBUG [PID:3411866] [TID:140083478574656] ems_logger 6 6 EMSAdmin@xyzcompany.com marked FortiClients as uninstalled on 176 Endpoints.

 

For efficiency, above steps may be performed with Notepad++, where a user may search through the whole FortiClient EMS diagnostics folder. Example below:

 

Notepad++.png

 

In the screenshot above, the 'Marked FortiClients as uninstalled' phrase was used to search throughout the whole directory where FortiClient EMS diagnostics have been unarchived to ('EMS diagnostics folder' in the screenshot above). Note that the Find in Files search option has to be used to search for the key phrase across all files in the specified directory.

 

In order to connect the endpoints back to FortiClient EMS a user can issue the following command on Windows CMD:


FortiESNAC.exe -r|--register <address/invitation> [-p|--port <port>] 

 

For macOS and Linux CLI options refer to the official documentation below:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!