FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
btan
Staff & Editor
Staff & Editor
Article Id 387376
Description This article describes the FortiClient behavior in an endpoint shared with multiple users when user verification is enabled.
Scope FortiClient v7.0, v7.2, and v7.4.
Solution

In FortiClient EMS, there are user verification methods inthe  Invitation Code: Local, Domain, or SAML.

 

kb-apr3-v.PNG

 

The scenarios below demonstrate FortiClient's behavior when a machine is shared with multiple end users (for example, a computer in a public area like a library or reception area).

 

Case 1: If the Invitation Code does not have any verification method:

  • UserA logs in to PC.
  • UserA inputs the Invitation Code to join EMS.
  • UserA logs out, UserB logins to PC.
  • UserB FortiClient telemetry will stay connected to EMS.

Case 2: If the Invitation Code has a verification method:

  • UserA logs in to the PC. UserA inputs the Invitation Code to join EMS.
  • UserA performed the user verification and connected to EMS.
  • UserA logs out, UserB login to PC.
  • UserB FortiClient telemetry will be in a disconnected state, UserB will need to re-enter the Invitation Code to rejoin back to EMS.

 

Conclusion:

  • FortiClient can only remember one 'User Verification' info at a time.
  • When using FortiClient in a shared computer, do not configure any 'User Verification' to ensure FortiClient telemetry towards EMS is always persistent. Otherwise, another option is to just use EMS IP or FQDN to join EMS.

 

Contributors