FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
btan
Staff & Editor
Staff & Editor
Article Id 413850
Description This article describes how to troubleshoot the issue with endpoints not tagged by the 'CrowdStrike ZTA Score' ZTNA tag rule.
Scope FortiClient EMS v7.4.1 onwards.
Solution

In FortiClient EMS, create a ZTNA tag rule based on 'CrowdStrike ZTA Score'.

 

oct-kb3-1.png

 

In the above example, endpoints should get tagged with the '[CS-ZTA]' tag if their ZTA Score is lower than 80.
However, in some cases, endpoints are not being tagged even though their ZTA Score is lower than 80.

 

To troubleshoot this:

  1. Go to the affected endpoint, navigate to C:\ProgramData\CrowdStrike\ZeroTrustAssessment\
  2. There should be data.zta JSON file in this folder path.
  3. FortiClient will read this data.zta JSON file to retrieve CrowdStrike ZTNA Score.
  4. If the data.zta file is missing or it is blank (0KB), contact CrowdStrike Support and query why it is missing/blank.
Contributors