Skip to main content
New Member
July 1, 2026
Question

FortiSASE - Device Compliance

  • July 1, 2026
  • 1 reply
  • 25 views

Hi all,

We're looking at FortiSASE to possibly replace Cato SASE (a different debate).

What mechanisms does FortSASE have to ensure only corporate devices connect? Does it support Entra Conditional Access Policies and Compliance checks?

Can we use our machine certificate and authenticate based on that? 

    1 reply

    sjoshi
    Staff
    Staff
    July 2, 2026

    for Entra Conditional Access Policies it can be done at the saml entra id side

    setup sso on the fortisae and enable Conditional Access Policies

    on fortisase side what you can do is to setup ztna tag rule based on certificate or different use case

    if the endpoint has that specific tag, allow internet or SPA traffic else  deny it

    Thanks, Salon