Hi, We are looking to manage traffic with identity and endpoint based policies. We are also planning on getting EMS to get as much ztna in place as possible. It seems that the best option for managing identities is fsso. Is it compatible/recommanded with EMS ? Which should we go witch ? Any advice before with start going in all directions ?
Solved! Go to Solution.
For identity + endpoint-based policy enforcement on FortiGate, EMS and FSSO serve different but complementary roles: FSSO provides real-time user identity mapping from Active Directory for group-based policies, while EMS manages FortiClient endpoints to enforce ZTNA posture checks like AV status, domain join, and OS patching. EMS doesn’t replace FSSO’s granular AD group mapping, but both can integrate so FortiGate policies can require the right user and a compliant device
For identity + endpoint-based policy enforcement on FortiGate, EMS and FSSO serve different but complementary roles: FSSO provides real-time user identity mapping from Active Directory for group-based policies, while EMS manages FortiClient endpoints to enforce ZTNA posture checks like AV status, domain join, and OS patching. EMS doesn’t replace FSSO’s granular AD group mapping, but both can integrate so FortiGate policies can require the right user and a compliant device
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.