Fortinet Document Library
Version:
7.0.4
7.0.3
7.0.2
Version:
7.0.1
7.0.0
6.4.8
Version:
6.4.7
6.4.4
6.4.3
Version:
6.4.2
6.4.1
6.4.0
Version:
6.2.9
6.2.8
6.2.7
Version:
6.2.6
6.2.4
6.2.3
Version:
6.2.2
6.2.1
6.2.0
Version:
6.0.8
6.0.6
6.0.5
Version:
6.0.4
6.0.3
6.0.2
Version:
6.0.1
6.0.0
1.2.5
Version:
1.2.4
1.2.3
1.2.2
Version:
1.2.1
1.2.0
1.0.5
Version:
1.0.4
1.0.3
1.0.2
Version:
1.0.1
1.0.0
Table of Contents
Introduction
FortiClient EMS components
Documentation
What's New
FortiClient EMS 6.0.2
FortiClient EMS 6.0.1
FortiClient EMS 6.0.0
Getting Started
Getting started with managing Windows, macOS, and Linux endpoints
Deploying FortiClient software to endpoints
Pushing configuration information to FortiClient
Relationship between FortiClient EMS, FortiGate, and FortiClient
Standalone FortiClient EMS
FortiClient EMS integrated with FortiGate
Using EMS integrated with FortiGate
Quarantining an endpoint from FortiOS using EMS
Getting started with managing Chromebooks
Configuring FortiClient EMS for Chromebooks
Configuring the Google Admin console
Deploying profiles to Chromebooks
How FortiClient EMS and FortiClient work with Chromebooks
Installation Preparation
System requirements
Licenses
FortiClient EMS
Free trial license
Purchased license
Component applications
Required services and ports
Management capacity
FortiClient Telemetry security features
Server readiness checklist for installation
Upgrading from an earlier FortiClient EMS version
Install preparation for managing Chromebooks
G Suite account
SSL certificates
Installation and Licensing
Downloading the installation file
Installing FortiClient EMS
Installing FortiClient EMS using the CLI
Allowing remote access to FortiClient EMS and using custom port numbers
Customizing the SQL Server Express install directory
Customizing the SQL Server Express install to a local directory
Customizing the SQL Server Express install to a remote directory
Installing FortiClient EMS to specify SQL Server Enterprise or Standard instance
Local existing database
Remote existing database
Starting FortiClient EMS and logging in
Accessing FortiClient EMS remotely
Licensing FortiClient EMS
License status
Extending license expiries
Help with licensing
Specifying different ports
Upgrading Microsoft SQL Server Express to Microsoft SQL Server Standard or Enterprise
Testing the SQL server upgrade
Uninstalling FortiClient EMS
Chromebook-only Setup
Google Admin Console setup
Logging into the Google Admin console
Adding the FortiClient Web Filter extension
Configuring the FortiClient Web Filter extension
Adding root certificates
Communication with the FortiClient Chromebook Web Filter extension
Communication with FortiAnalyzer for logging
Adding SSL certificates to FortiAnalyzer
Selecting certificates for HTTPS connections
Summary of where to add certificates
Uploading root certificates to the Google Admin console
Disabling access to Chrome developer tools
Disallowing incognito mode
Disallowing guest mode
Blocking Task Manager
Verifying the FortiClient Web Filter extension
Service account credentials
Configuring default service account credentials
Adding the default service account client ID to the Google Admin console
Configuring unique service account credentials
Creating unique service account credentials
Adding service account credentials to the Google Admin console
Adding service account credentials to EMS
GUI
Banner
Left pane
Content pane
Dashboard
Viewing the FortiClient Status
System Information widget
FortiClient Status charts and widgets
Viewing the Vulnerability Scan dashboard
Vulnerability Scan charts and widgets
Viewing current vulnerabilities
Viewing the Endpoint Scan Status
Viewing top ten vulnerabilities on endpoints
Viewing Chromebook Status
Endpoint Management
Windows, macOS, and Linux endpoints
Creating groups
Adding endpoints
Adding endpoints using an Active Directory domain server
Connecting manually from FortiClient
Viewing endpoints
Viewing the Endpoints content pane
Using the quick status bar
Viewing endpoint details
Filtering the list of endpoints
Using bookmarks to filter the list of endpoints
Managing endpoints
Running AntiVirus scans on endpoints
Running vulnerability scans on endpoints
Patching vulnerabilities on endpoints
Uploading FortiClient logs
Running the FortiClient diagnostic tool
Updating signatures
Disconnecting and connecting endpoints
Quarantining endpoints
Quarantining an endpoint from FortiOS using EMS
Excluding endpoints from management
Deleting endpoints
Provisioning FortiClient Android endpoints for central management
Google Domains
Adding Google domains
Viewing domains
Viewing the Google Users pane
Viewing user details
Editing domains
Deleting domains
Quarantine Management
Files
Viewing quarantined files
Viewing the Files content pane
Filtering files list
Whitelisting quarantined files
Whitelist
Viewing whitelisted files
Viewing the Whitelist content pane
Filtering whitelisted files
Editing file descriptions
Deleting files from the whitelist
Software Inventory
Applications
Viewing the Applications content pane
Filtering applications
Hosts
Viewing the Hosts content pane
Filtering hosts
Endpoint Profiles
Configuring profiles
Editing the default profile
Configuring profiles for Windows, macOS, and Linux endpoints
Creating profiles to configure FortiClient
Creating profiles to deploy FortiClient
Creating profiles to uninstall FortiClient
Importing FortiGate profiles
Importing FortiClient profiles from FortiManager
Creating profiles with XML
Creating profiles to automatically upgrade FortiClient
Configuring profiles for Chromebooks
Adding new profiles
Enabling/disabling safe search
Viewing profiles
Assigning profiles
Assigning profiles to Windows, macOS, and Linux endpoints
Assigning profiles to Chromebooks
Managing profiles
Editing profiles
Cloning profiles
Syncing profile changes
Editing sync schedules
Deleting profiles
Profile references
Profile Name
AntiVirus Protection
Sandbox Detection
Web Filter
Application Firewall
VPN
Vulnerability Scan
System Settings
XML Configuration
Profile Components
Managing installers
FortiGuard Distribution Network
Downloading FortiClient installers
Adding FortiClient installers
Uploading custom FortiClient installers
Viewing installers
Deleting FortiClient installers
Managing FortiSandbox units
Adding a FortiSandbox
Editing a FortiSandbox
Viewing FortiSandboxes
Deleting a FortiSandbox
Managing CA certificates
Uploading certificates
Importing certificates
Gateway Lists
Creating gateway lists
Exporting gateway lists to XML
Viewing gateway lists
Assigning gateway lists to endpoints
Viewing assigned gateway lists
Deployment
Preparing the AD server for deployment
Configuring a group policy on the AD server
Configuring required Windows services
Creating deployment rules for Windows firewall
Configuring Windows firewall domain profile settings
Preparing Windows endpoints for FortiClient deployment
Deploying FortiClient on endpoints
Deploying initial installations of FortiClient (macOS)
Deploying FortiClient upgrades from EMS
Administration
Administrators
Default user account and permissions
Viewing users
Configuring Administrators
Changing the admin password
Configuring Windows user accounts
Configuring LDAP user accounts
Administrators reference
Configuring User Server
Configuring User Settings
Group assignment rules
Tag group assignment rules
IP address group assignment rules
Group assignment rule priority levels
Adding a tag group assignment rule
Adding an IP address group assignment rule
Enabling/disabling a group assignment rule
Deleting a group assignment rule
Database management
Backing up the database
Restoring the database
License upgrades or renewals
Logs
Viewing logs
Downloading logs
System Settings
Configuring Server settings
Adding SSL certificates to FortiClient EMS
Configuring Logs settings
Configuring FortiGuard settings
Configuring Endpoints settings
Configuring the login banner
Alerts
Configuring EMS Alerts
Configuring Endpoints Alerts
Configuring SMTP Server settings
Viewing Alerts
Customizing the endpoint quarantine message
Creating a Support Package
Home
FortiClient 6.0.2
EMS Administration Guide
EMS Administration Guide
Introduction
FortiClient EMS components
Documentation
What's New
FortiClient EMS 6.0.2
FortiClient EMS 6.0.1
FortiClient EMS 6.0.0
Getting Started
Getting started with managing Windows, macOS, and Linux endpoints
Deploying FortiClient software to endpoints
Pushing configuration information to FortiClient
Relationship between FortiClient EMS, FortiGate, and FortiClient
Standalone FortiClient EMS
FortiClient EMS integrated with FortiGate
Using EMS integrated with FortiGate
Quarantining an endpoint from FortiOS using EMS
Getting started with managing Chromebooks
Configuring FortiClient EMS for Chromebooks
Configuring the Google Admin console
Deploying profiles to Chromebooks
How FortiClient EMS and FortiClient work with Chromebooks
Installation Preparation
System requirements
Licenses
FortiClient EMS
Free trial license
Purchased license
Component applications
Required services and ports
Management capacity
FortiClient Telemetry security features
Server readiness checklist for installation
Upgrading from an earlier FortiClient EMS version
Install preparation for managing Chromebooks
G Suite account
SSL certificates
Installation and Licensing
Downloading the installation file
Installing FortiClient EMS
Installing FortiClient EMS using the CLI
Allowing remote access to FortiClient EMS and using custom port numbers
Customizing the SQL Server Express install directory
Customizing the SQL Server Express install to a local directory
Customizing the SQL Server Express install to a remote directory
Installing FortiClient EMS to specify SQL Server Enterprise or Standard instance
Local existing database
Remote existing database
Starting FortiClient EMS and logging in
Accessing FortiClient EMS remotely
Licensing FortiClient EMS
License status
Extending license expiries
Help with licensing
Specifying different ports
Upgrading Microsoft SQL Server Express to Microsoft SQL Server Standard or Enterprise
Testing the SQL server upgrade
Uninstalling FortiClient EMS
Chromebook-only Setup
Google Admin Console setup
Logging into the Google Admin console
Adding the FortiClient Web Filter extension
Configuring the FortiClient Web Filter extension
Adding root certificates
Communication with the FortiClient Chromebook Web Filter extension
Communication with FortiAnalyzer for logging
Adding SSL certificates to FortiAnalyzer
Selecting certificates for HTTPS connections
Summary of where to add certificates
Uploading root certificates to the Google Admin console
Disabling access to Chrome developer tools
Disallowing incognito mode
Disallowing guest mode
Blocking Task Manager
Verifying the FortiClient Web Filter extension
Service account credentials
Configuring default service account credentials
Adding the default service account client ID to the Google Admin console
Configuring unique service account credentials
Creating unique service account credentials
Adding service account credentials to the Google Admin console
Adding service account credentials to EMS
GUI
Banner
Left pane
Content pane
Dashboard
Viewing the FortiClient Status
System Information widget
FortiClient Status charts and widgets
Viewing the Vulnerability Scan dashboard
Vulnerability Scan charts and widgets
Viewing current vulnerabilities
Viewing the Endpoint Scan Status
Viewing top ten vulnerabilities on endpoints
Viewing Chromebook Status
Endpoint Management
Windows, macOS, and Linux endpoints
Creating groups
Adding endpoints
Adding endpoints using an Active Directory domain server
Connecting manually from FortiClient
Viewing endpoints
Viewing the Endpoints content pane
Using the quick status bar
Viewing endpoint details
Filtering the list of endpoints
Using bookmarks to filter the list of endpoints
Managing endpoints
Running AntiVirus scans on endpoints
Running vulnerability scans on endpoints
Patching vulnerabilities on endpoints
Uploading FortiClient logs
Running the FortiClient diagnostic tool
Updating signatures
Disconnecting and connecting endpoints
Quarantining endpoints
Quarantining an endpoint from FortiOS using EMS
Excluding endpoints from management
Deleting endpoints
Provisioning FortiClient Android endpoints for central management
Google Domains
Adding Google domains
Viewing domains
Viewing the Google Users pane
Viewing user details
Editing domains
Deleting domains
Quarantine Management
Files
Viewing quarantined files
Viewing the Files content pane
Filtering files list
Whitelisting quarantined files
Whitelist
Viewing whitelisted files
Viewing the Whitelist content pane
Filtering whitelisted files
Editing file descriptions
Deleting files from the whitelist
Software Inventory
Applications
Viewing the Applications content pane
Filtering applications
Hosts
Viewing the Hosts content pane
Filtering hosts
Endpoint Profiles
Configuring profiles
Editing the default profile
Configuring profiles for Windows, macOS, and Linux endpoints
Creating profiles to configure FortiClient
Creating profiles to deploy FortiClient
Creating profiles to uninstall FortiClient
Importing FortiGate profiles
Importing FortiClient profiles from FortiManager
Creating profiles with XML
Creating profiles to automatically upgrade FortiClient
Configuring profiles for Chromebooks
Adding new profiles
Enabling/disabling safe search
Viewing profiles
Assigning profiles
Assigning profiles to Windows, macOS, and Linux endpoints
Assigning profiles to Chromebooks
Managing profiles
Editing profiles
Cloning profiles
Syncing profile changes
Editing sync schedules
Deleting profiles
Profile references
Profile Name
AntiVirus Protection
Sandbox Detection
Web Filter
Application Firewall
VPN
Vulnerability Scan
System Settings
XML Configuration
Profile Components
Managing installers
FortiGuard Distribution Network
Downloading FortiClient installers
Adding FortiClient installers
Uploading custom FortiClient installers
Viewing installers
Deleting FortiClient installers
Managing FortiSandbox units
Adding a FortiSandbox
Editing a FortiSandbox
Viewing FortiSandboxes
Deleting a FortiSandbox
Managing CA certificates
Uploading certificates
Importing certificates
Gateway Lists
Creating gateway lists
Exporting gateway lists to XML
Viewing gateway lists
Assigning gateway lists to endpoints
Viewing assigned gateway lists
Deployment
Preparing the AD server for deployment
Configuring a group policy on the AD server
Configuring required Windows services
Creating deployment rules for Windows firewall
Configuring Windows firewall domain profile settings
Preparing Windows endpoints for FortiClient deployment
Deploying FortiClient on endpoints
Deploying initial installations of FortiClient (macOS)
Deploying FortiClient upgrades from EMS
Administration
Administrators
Default user account and permissions
Viewing users
Configuring Administrators
Changing the admin password
Configuring Windows user accounts
Configuring LDAP user accounts
Administrators reference
Configuring User Server
Configuring User Settings
Group assignment rules
Tag group assignment rules
IP address group assignment rules
Group assignment rule priority levels
Adding a tag group assignment rule
Adding an IP address group assignment rule
Enabling/disabling a group assignment rule
Deleting a group assignment rule
Database management
Backing up the database
Restoring the database
License upgrades or renewals
Logs
Viewing logs
Downloading logs
System Settings
Configuring Server settings
Adding SSL certificates to FortiClient EMS
Configuring Logs settings
Configuring FortiGuard settings
Configuring Endpoints settings
Configuring the login banner
Alerts
Configuring EMS Alerts
Configuring Endpoints Alerts
Configuring SMTP Server settings
Viewing Alerts
Customizing the endpoint quarantine message
Creating a Support Package
6.0.2
7.0.4
7.0.3
7.0.2
7.0.1
7.0.0
6.4.8
6.4.7
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.2.9
6.2.8
6.2.7
6.2.6
6.2.4
6.2.3
6.2.2
6.2.1
6.2.0
6.0.8
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
Download PDF
Copy Link
Managing profiles
You can manage profiles from the
Endpoint Profiles
pane.
Managing profiles
Managing profiles
You can manage profiles from the
Endpoint Profiles
pane.
Link
PDF
TOC