|
In FortiEndpoint environments, the FortiEDR collector is deployed and managed through FortiClient EMS. The FortiClient EMS deployments should sync with FortiEDR collector groups. The collector group synchronization relies on communication between FortiClient and FortiEDR installed on the device. If the endpoint profile assigned to a device has 'Endpoint Detection & Response' disabled, FortiClient and FortiEDR cannot communicate with each other. As a result, the Collector group is not updated, and the endpoint remains in the Default Collector Group in the FortiEDR console, even though the device may appear correctly in FortiClient EMS.
This setting can be found under: Endpoint Profiles -> System Settings -> Assigned Profile -> Enable Endpoint Detection & Response.
Step 1: Verify the profile assigned to the device. From the EMS Endpoints tab, identify which system profile is assigned to the affected device (highlighted with a red box in the screenshot below).

Step 2: Verify the system profile setting. Navigate to Endpoint Profiles -> System Settings, and check whether Enable Endpoint Detection & Response is enabled for the assigned profile (highlighted with a red box in the screenshot below). If the setting is disabled, enable it and allow time for the Collector to resynchronize and update its group assignment.

Further troubleshooting: If the setting is already enabled and the Collector still does not move out of the Default Collector Group, further troubleshooting is required. In some cases, toggling EMS deployments (enable/disable) or creating a new deployment can help. If the issue persists, review FortiEDR logs and collect EMS diagnostic logs for further analysis.
|