FortiEndpoint (FortiClient integration of FortiEDR agent) 7.4.1
A cloud-based software-as-a-service endpoint management service called FortiEndpoint is available. This is a Fortinet-hosted EMS solution. FortiEndpoint provides the same features as FortiClient Cloud but with an additional FortiEndpoint deployment feature.
See the FortiEndpoint Administration Guide for details.
When the FortiClient EMS and FortiEDR systems are integrated, the EMS Administrator can create a "unified installer" that installs both the FortiClient and FortiEDR components on the endpoint. Because the FortiEDR installer is pre-configured, the FortiClient installation experience is unchanged and no FortiEDR user prompts appear.
Example 1
The following example demonstrates installing FortiClient integrated with the FortiEDR agent using the EMS-create installer. FortiEDR has not been installed beforehand.
The following are required: |
To install FortiClient integrated with the FortiEDR agent:
-
Go to Endpoint Profiles > System Settings.
-
In Endpoint Control, enable Enable Endpoint Detection & Response.
-
Go to Deployment & Installers > FortiClient Installer.
-
Click Add.
-
Configure the General settings:
-
Enter the Online Installer Name.
-
Select the Release and Patch version.
-
Deselect Hotfix.
-
Enter the Invitation.
-
Click Next.
-
-
Configure the Features:
-
Enable Endpoint Detection & Response.
-
Click Next.
-
-
Configure the EDR Feature settings:
-
Select the EDR Engine Version.
-
Click Next.
-
-
Configure the Advanced features.
-
Click Finish. The FortiClient installer with the FortiEDR agent is displayed.
-
When the Status is Ready for deployment, click Generate Zip.
-
Click Confirm.
-
Click Download Zip.
-
Copy the FortiClient installer .zip file to a clean Windows machine, then extract the file and start the installation process using .exe file.
FortiClient and the FortiEDR agent will be installed simultaneously. The FortiTray notification message will be displayed as EDR State: Running once the FortiClient is registered with EMS.
A new profile tab Detection and Response is added on the FortiClient console and shows the FortiEDR agent status. FortiEDR Collector Service will be running along with the FortiClient.
Example 2
The following example demonstrates how FortiClient integrated with the FortiEDR agent can detect and block malicious applications.
To leverage FortiClient integrates with FortiEDR:
-
Enable the FortiEDR feature:
-
Go to Endpoint Profiles > System Settings.
-
In Endpoint Control, enable Enable Endpoint Detection & Response. When enabled, the Detection & Response tab will be displayed on the FortiClient with the status EDR Enabled. When the EDR agent detects a malicious application, it blocks the application and shows a Block Event FortiTray notification message.
The Activity Log count on the Detection & Response page will be updated.
-
In Detection & Response, click the Activity Log count or the settings icon. EDR-blocked events will be shown in the Activity Log table.
-
If available, click > on a detection event to see more details.
EDR detection event logs can be seen on the endpoint at C:\ProgramData\FortiEDR\Logs\Collector in the BlockLog.bin file.
FortiClient can also send EDR event for FortiClient EMS. These events are displayed in the EDR Events tab.