Fortinet black logo

Creating a deployment profile

6.0.3
Copy Link
Copy Doc ID 071aa83e-d7c4-11e8-8784-00505692583a:653950
Download PDF

Creating a deployment profile

Next, you must create a new profile to deploy FortiClient to endpoints. You will assign the installer created in Creating a FortiClient installer to the profile.

note icon

When creating a profile to deploy FortiClient, you must create a new profile. You cannot add an installer to the default profile.

The selected FortiClient installer in a profile controls what tabs are displayed for configuration in the profile. Only the tabs for the features in the selected installer are displayed for configuration in the profile. For example, if the installer includes only the VPN feature, only the VPN tab is displayed for you to configure. The System Settings tab always displays.

You can disable a feature included in the installer, then enable the feature in the profile later. For example, if the installer includes the Web Filter and VPN features, you can disable the Web Filter feature and keep the VPN feature enabled. When FortiClient is installed on the endpoint, the Web Filter is installed, but disabled.

  1. Go to Endpoint Profiles > Manage Profile, and click the Add button.
  2. On the Deployment tab, enable FortiClient Deployment. The FortiClient deployment options display.
  3. Set the following options on the Deployment tab:

    Action

    Assign an

    Click Installer.

    Installer

    In the Installer list, select the FortiClient installer created in Creating a FortiClient installer. The installer options display.

    Schedule

    Start At

    Specify what time to start installing FortiClient on endpoints. In this example, the time is configured for 8:00 PM.

    Reboot When Needed

    Enable to reboot the endpoint to install FortiClient when needed.

    Reboot when no users is logged in

    Enable to allow the endpoint to reboot without prompt if no endpoint user is logged into FortiClient.

    Notify users and let the user decide when to reboot when they are logged in

    Enable to notify the end user if a reboot of the endpoint is needed and allow the user to decide what time to reboot the endpoint. Disable to reboot the endpoint without notifying the user.

    Credentials

    Username

    Enter the username to perform deployment on AD. You must enter the admin credentials for the AD in the profile. Enter the appropriate credentials in the profile to assign to the AD. The credentials allow EMS to install FortiClient on endpoints using AD. If the credentials are wrong, the installation fails, and an error displays in EMS.

    Password

    Enter the password to perform deployment on AD.

  4. Set the options on the remaining tabs if desired. See the FortiClient EMS Administration Guide for details.
  5. Click Save.
note icon

For information on additional profile configuration, see the FortiClient EMS Administration Guide.

Creating a deployment profile

Next, you must create a new profile to deploy FortiClient to endpoints. You will assign the installer created in Creating a FortiClient installer to the profile.

note icon

When creating a profile to deploy FortiClient, you must create a new profile. You cannot add an installer to the default profile.

The selected FortiClient installer in a profile controls what tabs are displayed for configuration in the profile. Only the tabs for the features in the selected installer are displayed for configuration in the profile. For example, if the installer includes only the VPN feature, only the VPN tab is displayed for you to configure. The System Settings tab always displays.

You can disable a feature included in the installer, then enable the feature in the profile later. For example, if the installer includes the Web Filter and VPN features, you can disable the Web Filter feature and keep the VPN feature enabled. When FortiClient is installed on the endpoint, the Web Filter is installed, but disabled.

  1. Go to Endpoint Profiles > Manage Profile, and click the Add button.
  2. On the Deployment tab, enable FortiClient Deployment. The FortiClient deployment options display.
  3. Set the following options on the Deployment tab:

    Action

    Assign an

    Click Installer.

    Installer

    In the Installer list, select the FortiClient installer created in Creating a FortiClient installer. The installer options display.

    Schedule

    Start At

    Specify what time to start installing FortiClient on endpoints. In this example, the time is configured for 8:00 PM.

    Reboot When Needed

    Enable to reboot the endpoint to install FortiClient when needed.

    Reboot when no users is logged in

    Enable to allow the endpoint to reboot without prompt if no endpoint user is logged into FortiClient.

    Notify users and let the user decide when to reboot when they are logged in

    Enable to notify the end user if a reboot of the endpoint is needed and allow the user to decide what time to reboot the endpoint. Disable to reboot the endpoint without notifying the user.

    Credentials

    Username

    Enter the username to perform deployment on AD. You must enter the admin credentials for the AD in the profile. Enter the appropriate credentials in the profile to assign to the AD. The credentials allow EMS to install FortiClient on endpoints using AD. If the credentials are wrong, the installation fails, and an error displays in EMS.

    Password

    Enter the password to perform deployment on AD.

  4. Set the options on the remaining tabs if desired. See the FortiClient EMS Administration Guide for details.
  5. Click Save.
note icon

For information on additional profile configuration, see the FortiClient EMS Administration Guide.