Compliance with EMS and FortiOS
In FortiClient 6.4.9, compliance depends on EMS and FortiOS. This feature is only available if using FortiClient 6.4.9 with EMS 6.4.9 and FortiOS 6.4.9.
The administrator can define zero trust tagging rules in EMS based on criteria such as certificates, the logged in domain, files present, OS versions, running processes, and registry keys. When an endpoint registers to EMS, EMS dynamically groups the endpoint based on the zero trust tagging rules. FortiOS can receive the dynamic endpoint groups from EMS and use them to create dynamic firewall policies. The endpoint may be unable to access the network based on the zero trust tagging rules.
See the FortiOS dynamic policies using EMS dynamic endpoint groups.