Known issues
The following issues have been identified in FortiEndpoint 26.1.b. For inquiries about a particular bug, contact Customer Service & Support.
Endpoint control
|
Bug ID |
Description |
|---|---|
| 1252180 | Endpoints on subnet 172.17.0.0/16 cannot register telemetry with FortiEndpoint. |
Deployment and installers
|
Bug ID |
Description |
|---|---|
| 1247941 | FortiEndpoint deployment to update FortiClient feature sets for the same FortiClient version fails unless the initial deployment was done using the FortiEndpoint-generated FortiClient EXE installer or the MSI file (rather than the MST file). |
Endpoint control
|
Bug ID |
Description |
|---|---|
|
1213829 |
FortiClient auth-period registry is not reset to 0 after User Verification Period is disabled in FortiEndpoint. |
Endpoint management
|
Bug ID |
Description |
|---|---|
|
1127493 |
FortiEndpoint displays inaccurate user information for endpoints running on the Windows Server operating system. |
|
1211682 |
Unable to delete ADDS authentication server when it is not reachable. |
Endpoint policy and profile
|
Bug ID |
Description |
|---|---|
| 1089889 | Chromebooks intermittently receive error Failed to retrieve user profile from FortiEndpoint. |
|
1219573 |
FortiEndpoint fails to apply Entra ID policies to Entra ID-joined devices that use an alias domains instead of the primary UPN domain. |
GUI
|
Bug ID |
Description |
|---|---|
|
1186739 |
Back button in endpoint vulnerability details page returns to Dashboard instead of previous page. |
EDR
|
Bug ID |
Description |
|---|---|
|
1050795 |
No message to explain why the user cannot set the UI to prevention mode when all policies are in simulation mode. |
|
733592 |
Number of destinations under communication control is limited to 100 IP addresses. |
|
733598 |
Safari 11.1 on macOS malfunctions when viewing events. |
|
757253 |
EDR Connect cannot be used to run commands that are user-interactive. |
|
765648 |
On Linux, threat hunting exclusions only work in kernel space mode, not in user space mode. |
|
771630 |
Device internal and external IP is missing from Threat Hunting events of Linux devices. |
|
777707 |
Linux Collector content file is large and uploads slowly to the Central Manager. |
|
807930 |
Application Control search only works by exact match |
|
809060 |
EDR Connect session may be disconnected due to inactivity of the EDR Console, even though the Connect session is active. |
|
833152 |
Raw data IDs appearing in the Collector tray and Incidents view may differ. |
|
837038 |
Application Control cannot remove multiple tags in one action. |
|
842110 |
In some network configurations, a rare issue might cause Collectors to be detected as IoT devices. |
|
885691 |
Threat Hunting: The tooltip displayed when hovering might prevent access to adding a filter. |
|
889410 |
When switching to Threat Hunting from Incidents > Automated Analysis, queries malfunction when more than one device is involved Workaround: Filter by the same Collectors directly from Threat Hunting, which brings results. |
|
890339 |
"Query Parsing Failed" in Threat hunting pops up multiple times after invalid query. |
|
891668 |
Free text query in threat hunting, when using invalid text, no error message is displayed. The query returns empty results. |
|
892109 |
Unable to filter by empty registry names in facets in Threat Hunting. |
|
894384 |
In Threat Hunting, clicking Retrieve Target File for "File Rename" events retrieves the old file name instead of the renamed one. |
|
899736 |
In a threat hunting search, if you search for "Target.Registry.Path:" AND "Registry.Path" the results will be empty Workaround: Use either "Target.Registry.Path" or "Registry.Path" in a specific search. |
|
909654 |
IoT filter by ״First connection=Today״ brings empty results. |
|
914348 |
Investigation View: Incident response data is inaccurate. |
|
914792 |
Unarchiving all events in large environments might cause the EDR console to malfunction. Workaround: Filter events before unarchiving to reduce unarchive size. |
|
915698 |
In the Investigation View, the message is wrong in the Block address on firewall window when you click Firewall Block. |
|
935001, 938847, 1048422, 1064821, 1066657 |
System event page default filtering is required. |
|
939481 |
In some cases, the communication control feature does not work due to unforeseen technical issues. |
|
954553, 969494 |
Some event log entries in threat hunting display logged event values in incorrect logged event fields. |
|
988884 |
Incorrect threat hunting profile order of Fortinet pre-defined application profiles. |
|
994324 |
Improve "file permission change" text in Threat Hunting Exclusions display. |
|
994334 |
Added Threat Hunting columns are inaccessible unless the columns are narrowed. |
|
994348 |
Log does not contain concrete helpful errors for API. |
|
994359 |
Threat Hunting Collection Profiles - rule name and icon not aligned. |
|
1001334 |
Security events fully covered by an exception retains the full coverage indication icon even after new uncovered raw data items come in. |
|
1003257, 1025493 |
Missing field in Checkpoint firewall integration. |
|
1014489, 1035403 |
Failure to delete aggregations in big bulks over 20K. |
|
1039714, 1041152 |
Confusing error message when uploading a wrong formatted file in Application Control Manager > Upload Applications. |
|
1040055, 1041151 |
Ad hoc network discovery tooltip has a mistake in Japanese. |
|
1040805, 1048215 |
Incident view count changes with sort. |
|
1052668, 1060356 |
Syslog is created with no audit. |
|
1062894, 1063406 |
No validation for SecurityExclusionRepoEntity.path in exclusions configuration. |
|
1079894, 1081873 |
Exceptions report can be slow. |