Fortinet black logo

EMS Administration Guide

Windows, macOS, and Linux endpoint licenses

Windows, macOS, and Linux endpoint licenses

The following are the latest license bundles for FortiClient EMS:

License name

Description

Endpoint protection platform (EPP)

Full license that offers all FortiClient features. Includes all features detailed for the zero trust network access (ZTNA) license, as well as:

  • Antivirus (AV)
  • Antiransomware
  • Antiexploit
  • Cloud-based malware detection
  • Application Firewall
  • Software inventory
  • Advanced threat protection via FortiClient Cloud Sandbox

ZTNA

Includes support for Fabric Agent for endpoint telemetry, security posture check via ZTNA tagging, remote access (SSL and IPsec VPN), Vulnerability Scan, Web Filter, threat protection via Sandbox (appliance only) and USB device control.

Each purchased ZTNA license allows management of one FortiClient Windows, macOS, Linux, iOS, Android, or Chromebook endpoint. You must purchase a minimum of 25 endpoint licenses, and you can have these EMS licenses for a maximum three year term. You can specify the number of endpoints and the term duration at time of purchase.

If you do not apply a ZTNA license applied to EMS, no endpoints can register to EMS.

The following shows a more comprehensive comparison between the features included in the EPP and ZTNA licenses:

Feature

EPP

ZTNA

Zero Trust Security

Zero Trust Agent

Yes

Yes

Central management via EMS

Yes

Yes

Dynamic Fortinet Security Fabric connector

Yes

Yes

Vulnerability agent and remediation

Yes

Yes

SSL VPN with multifactor authentication (MFA)

Yes

Yes

IPsec VPN with MFA

Yes

Yes

Sandbox appliance

Yes

Yes

Next Generation Endpoint Security

AI-powered next generation AV

Yes

FortiClient Cloud Sandbox

Yes

Automated endpoint quarantine

Yes

Application inventory

Yes

Application Firewall

Yes

Software Inventory

Yes

The following are individual licenses that you can purchase for FortiClient EMS:

License name

Description

Fabric Agent with Endpoint Protection and Cloud Sandbox

Full license that offers all FortiClient features including endpoint protection and Sandbox Cloud.

Includes all features detailed for the Fabric Agent with Endpoint Protection and Sandbox Cloud licenses.

Fabric Agent with Endpoint Protection

Includes support for Telemetry and endpoint protection and management (AV, on-premise FortiSandbox, Web Filter, Application Firewall, Vulnerability Scan, Fortinet Single Sign-On (FSSO), and FortiGate registration).

Each purchased Fabric Agent license allows management of one FortiClient Windows, macOS, or Linux endpoint. You must purchase a minimum of 25 endpoint licenses, and you can have these EMS licenses for a maximum three year term. You can specify the number of endpoints and the term duration at time of purchase.

The Fabric Agent license also applies for iOS and Android endpoints.

You can also use the Fabric Agent license to license Chromebooks if no Chromebook license is present on the EMS instance.

Sandbox Cloud

Adds support for FortiSandbox Cloud for Windows and macOS endpoints.

When using both Fabric Agent and Sandbox Cloud licenses, you must purchase the same number of licenses for both license types:

  • If you already have purchased Fabric Agent licenses for 1000 endpoints, then decide to add the Sandbox Cloud licenses, you must also purchase 1000 Sandbox Cloud licenses.
  • If you have purchased Sandbox Cloud licenses for 500 endpoints, then decide to add the Fabric Agent licenses, you must also purchase 500 Fabric Agent licenses.
  • If you purchase both Fabric Agent and Sandbox Cloud licenses at the same time, you must purchase the same number of both licenses.
  • If the license amounts differ, the lowest common number of licenses is available. For example, if you purchase 500 Fabric Agent licenses and 300 Sandbox Cloud licenses, EMS only has 300 licenses available.

You must purchase a license for each registered endpoint.

Windows, macOS, and Linux endpoint licenses

The following are the latest license bundles for FortiClient EMS:

License name

Description

Endpoint protection platform (EPP)

Full license that offers all FortiClient features. Includes all features detailed for the zero trust network access (ZTNA) license, as well as:

  • Antivirus (AV)
  • Antiransomware
  • Antiexploit
  • Cloud-based malware detection
  • Application Firewall
  • Software inventory
  • Advanced threat protection via FortiClient Cloud Sandbox

ZTNA

Includes support for Fabric Agent for endpoint telemetry, security posture check via ZTNA tagging, remote access (SSL and IPsec VPN), Vulnerability Scan, Web Filter, threat protection via Sandbox (appliance only) and USB device control.

Each purchased ZTNA license allows management of one FortiClient Windows, macOS, Linux, iOS, Android, or Chromebook endpoint. You must purchase a minimum of 25 endpoint licenses, and you can have these EMS licenses for a maximum three year term. You can specify the number of endpoints and the term duration at time of purchase.

If you do not apply a ZTNA license applied to EMS, no endpoints can register to EMS.

The following shows a more comprehensive comparison between the features included in the EPP and ZTNA licenses:

Feature

EPP

ZTNA

Zero Trust Security

Zero Trust Agent

Yes

Yes

Central management via EMS

Yes

Yes

Dynamic Fortinet Security Fabric connector

Yes

Yes

Vulnerability agent and remediation

Yes

Yes

SSL VPN with multifactor authentication (MFA)

Yes

Yes

IPsec VPN with MFA

Yes

Yes

Sandbox appliance

Yes

Yes

Next Generation Endpoint Security

AI-powered next generation AV

Yes

FortiClient Cloud Sandbox

Yes

Automated endpoint quarantine

Yes

Application inventory

Yes

Application Firewall

Yes

Software Inventory

Yes

The following are individual licenses that you can purchase for FortiClient EMS:

License name

Description

Fabric Agent with Endpoint Protection and Cloud Sandbox

Full license that offers all FortiClient features including endpoint protection and Sandbox Cloud.

Includes all features detailed for the Fabric Agent with Endpoint Protection and Sandbox Cloud licenses.

Fabric Agent with Endpoint Protection

Includes support for Telemetry and endpoint protection and management (AV, on-premise FortiSandbox, Web Filter, Application Firewall, Vulnerability Scan, Fortinet Single Sign-On (FSSO), and FortiGate registration).

Each purchased Fabric Agent license allows management of one FortiClient Windows, macOS, or Linux endpoint. You must purchase a minimum of 25 endpoint licenses, and you can have these EMS licenses for a maximum three year term. You can specify the number of endpoints and the term duration at time of purchase.

The Fabric Agent license also applies for iOS and Android endpoints.

You can also use the Fabric Agent license to license Chromebooks if no Chromebook license is present on the EMS instance.

Sandbox Cloud

Adds support for FortiSandbox Cloud for Windows and macOS endpoints.

When using both Fabric Agent and Sandbox Cloud licenses, you must purchase the same number of licenses for both license types:

  • If you already have purchased Fabric Agent licenses for 1000 endpoints, then decide to add the Sandbox Cloud licenses, you must also purchase 1000 Sandbox Cloud licenses.
  • If you have purchased Sandbox Cloud licenses for 500 endpoints, then decide to add the Fabric Agent licenses, you must also purchase 500 Fabric Agent licenses.
  • If you purchase both Fabric Agent and Sandbox Cloud licenses at the same time, you must purchase the same number of both licenses.
  • If the license amounts differ, the lowest common number of licenses is available. For example, if you purchase 500 Fabric Agent licenses and 300 Sandbox Cloud licenses, EMS only has 300 licenses available.

You must purchase a license for each registered endpoint.