Introduction
FortiSAT is a security awareness and phishing simulation platform designed to reduce the risk of successful social engineering attacks. By combining realistic phishing simulations with targeted educational content, the platform helps your organization build a resilient security culture.
FortiSAT helps your organization identify high-risk individuals and train them to protect the corporate network. The platform includes the following core capabilities.
-
Phishing Simulations: Launch simulated phishing email campaigns to test your employees and analyze how they interact with them. These simulations identify specific behavioral weaknesses and vulnerabilities within your organization.
-
Security Training: Launch training campaigns featuring targeted modules and quizzes to strengthen user knowledge. These campaigns can be assigned as proactive organizational training or as standalone educational initiatives, with users consuming content through a dedicated Learner Experience portal.
-
Remedial Training: Configure training campaigns to automatically enroll users in specific modules the moment they fail a phishing simulation. Enrollment is based on triggers such as opening the email or clicking a link.
-
Smart Groups: Organize users dynamically using rule-based logic. Smart Groups automatically update based on user attributes or campaign performance (such as users with failed phishing attempts), ensuring targeted delivery of content.
-
Monitoring and Analytics: Track the progress of active campaigns through centralized dashboards. These dashboards provide real-time visibility into user behavior, campaign engagement, and training completion rates.
-
Generating Reports: Generate and export audit-ready detailed reports in PDF format to meet compliance requirements.
Existing FortiPhish Users
To ensure your existing configurations continue to function correctly during the transition to FortiSAT, please perform the following:
- Update Safelisting: Add the following IP addresses and domains to your safelist. This is mandatory for LDAP synchronization and ForitSAT Phish Alert Button (PAB) functionality. See Product and IP Safelist.
LDAP Server: Add IP 52.49.221.140 and domain fortisat.forticloud.com
FortiSAT Phish Alert Button: Add IP 99.81.86.32 and domain api.fphplugin.net
-
Update SCIM Base URL: If you have configured SCIM provisioning in Entra ID, you must update the Tenant/Base URL to:
https://api.fortisat.forticloud.com/scim/v2