FortiEDR Zero Trust tagging rule and visibility
You can add a Zero Trust tagging rule to dynamically tag endpoints that have FortiEDR installed and running. If FortiEDR is installed, the endpoint details page shows the FortiEDR status. FortiEDR can have one of the following statuses on the endpoint details page:
Status |
Description |
---|---|
Running |
FortiEDR is installed on the endpoint and running. |
Installed |
FortiEDR is installed on the endpoint and not running. |
None |
FortiEDR is not installed on the endpoint. |
To add a FortiEDR Zero Trust tagging rule:
- Add a FortiEDR Zero Trust tagging rule:
- In EMS, go to Zero Trust Tags > Zero Trust Tagging Rules.
- Click Add.
- Click Add Rule.
- For OS, select Windows, Mac, or Linux.
- From the Rule Type dropdown list, select FortiEDR.
- From the FortiEDR dropdown list, select FortiEDR is installed and running.
- Click Save.
- Configure other fields as desired, then click Save.
- On the endpoint, install FortiEDR and check the FortiEDR status on a FortiEDR collector. See Installing FortiEDR Collectors.
- In FortiClient, go to the avatar page. Confirm that the FortiEDR tag appears.
- In EMS, go to Endpoints > All Endpoints.
- Select the endpoint. Under Zero Trust Tags, confirm that the FortiEDR tag appears. Under Third Party Features, confirm that FortiEDR shows as Running.