Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DARSSS
New Contributor

Forti EMS vs FSSO

Hi, We are looking to manage traffic with identity and endpoint based policies. We are also planning on getting EMS to get as much ztna in place as possible. It seems that the best option for managing identities is fsso. Is it compatible/recommanded with EMS ? Which should we go witch ? Any advice before with start going in all directions ?

1 Solution
sjoshi
Staff
Staff

For identity + endpoint-based policy enforcement on FortiGate, EMS and FSSO serve different but complementary roles: FSSO provides real-time user identity mapping from Active Directory for group-based policies, while EMS manages FortiClient endpoints to enforce ZTNA posture checks like AV status, domain join, and OS patching. EMS doesn’t replace FSSO’s granular AD group mapping, but both can integrate so FortiGate policies can require the right user and a compliant device

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi

View solution in original post

1 REPLY 1
sjoshi
Staff
Staff

For identity + endpoint-based policy enforcement on FortiGate, EMS and FSSO serve different but complementary roles: FSSO provides real-time user identity mapping from Active Directory for group-based policies, while EMS manages FortiClient endpoints to enforce ZTNA posture checks like AV status, domain join, and OS patching. EMS doesn’t replace FSSO’s granular AD group mapping, but both can integrate so FortiGate policies can require the right user and a compliant device

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors