Skip to main content
trita
New Member
March 2, 2026
Question

Deploying IPsec Profiles via Intune (Without EMS License)

  • March 2, 2026
  • 5 replies
  • 797 views

Hi everyone,

I’m planning to migrate from SSL VPN to IPsec VPN. Here’s the situation:

The FortiClient app is already installed on users’ devices, and I need a way to deploy the IPsec VPN profile to those devices via Intune (all devices are managed by Intune).

I’m currently using the VPN-only version of FortiClient, and as far as I know, deploying VPN profiles centrally requires an EMS license.

Could you please advise if there’s any alternative solution in this case?

Thanks

5 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
March 5, 2026

Hello trita, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
March 6, 2026

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
March 8, 2026

Hello again trita,

 

I found this answer, can you tell us if it helps, please?

 

To migrate from SSL VPN to IPsec VPN using FortiClient and deploy the IPsec VPN profile via Intune, you can follow these steps:

 

Deploying IPsec VPN Profile via Intune

  1. Create a VPN Profile in Intune:

    • Navigate to Devices > iOS/iPadOS > Configuration profiles > Create > New Policy > Templates > VPN in Intune.
    • Configure the necessary fields such as name, description, and select Custom VPN from the connection type dropdown.
    • Enter the VPN Identifier as com.fortinet.forticlient.fabricagent.

  2. Configure VPN Settings:

    • Fill in other required fields such as server address, authentication method, and split tunneling options.
    • Assign the profile to the desired users and groups.

  3. Sync Devices: Once the profile is assigned, ensure that the devices sync with Intune. The FortiClient (iOS) will list the VPN profile under the MDM VPN Gateway section.

 

Considerations

  • VPN-Only FortiClient: The VPN-only version of FortiClient available on the Google Play Store does not require an EMS license. However, it only provides SSL and IPsec VPN features without centralized management.

  • EMS License: For centralized management and deployment of VPN profiles, an EMS license is typically required. This allows for more comprehensive management and configuration of endpoint profiles.

 

Alternative Solutions

  • Manual Configuration: If centralized deployment via Intune is not feasible without an EMS license, consider manually configuring the IPsec VPN settings on each device using the FortiClient app.

  • Standalone Installer: Use the FortiClient Configurator tool to create a standalone installer for IPsec VPN. This can be distributed to users for manual installation.

Jean-Philippe - Fortinet Community Team
New Member
September 2, 2026

Hi Jean-Philippe,

Thank you for the information.

The instructions you provided appear to be for iOS/iPadOS. Our requirement is specifically for Android Enterprise devices managed through Microsoft Intune.

Our current configuration is:

  • Platform: Android Enterprise
  • FortiClient app: FortiClient VPN (com.fortinet.forticlient_vpn)
  • VPN type: IPsec
  • IKE version: IKEv2
  • VPN gateway: vpn1.****.com
  • Authentication: Microsoft Entra ID SAML
  • SAML port: 56417
  • FortiClient EMS: Not used
  • Requirement: Zero-touch deployment of the VPN profile through Intune

We have added FortiClient VPN through Managed Google Play and created an Android Enterprise managed app configuration policy in Intune.

However, the managed configuration schema exposed by the FortiClient Android application only provides the following VPN configuration keys:

  • vpn_name
  • vpn_server
  • vpn_type, with the value exposed as ssl
  • vpn_allowed_apps
  • vpn_client_cert_source
  • vpn_client_cert_path
  • vpn_prompt_username

There are no exposed configuration properties for IPsec/IKEv2, SAML, IPsec SSO or the SAML authentication port.

Could you please confirm whether FortiClient VPN for Android supports zero-touch deployment of an IPsec IKEv2 VPN using SAML authentication through Microsoft Intune without FortiClient EMS?

If this is supported, could you please provide the Android-specific Managed Google Play/Intune JSON schema or configuration keys required to deploy the following profile?

VPN Name: xxxx VPN
Gateway: vpn1.xxxxx.com
VPN Type: IPsec
IKE Version: IKEv2
Authentication: SAML / Microsoft Entra ID
SAML Port: 56417

In particular, can vpn_configuration_list support "vpn_type": "ipsec" on Android, and if so, what are the additional managed properties required for IKEv2 and SAML?

We would like the VPN profile to be provisioned automatically to our Intune-managed Android devices without requiring users to manually configure FortiClient and without deploying FortiClient EMS.

Jean-Philippe_P
Staff & Editor
Staff & Editor
September 2, 2026

Hello Petervanderberg,

I asked our Technical Team if they can help you and they will respond in this thread if they can!

Jean-Philippe - Fortinet Community Team
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!