
Learn how Forticlient EMS automates deployment, provisioning, and central management of Forticlient across endpoints. Explore Forticlient's integrated antivirus, anti-malware, web and application filtering, VPN, and removable media controls.
Explore the architecture and capacity management of Forticlient EMS, and identify essential services and ports for deployment, including Active Directory integration and FortiGate integration.
Learn forticlient deployment options, including standalone and security fabric, and how EMS uses zero-trust tagging to dynamically group endpoints for FortiGate policies.
Build a lab with an active directory domain and DNS, install FortiClient EMS on Windows 10, integrate Active Directory with EMS to auto-import users and push configurations to 40 endpoints.
Configure EMS licenses, including free trial and paid options, and enable remote web access. Integrate Active Directory with EMS to auto-import OUs, enable LDAP logins, and manage AD-based administrators.
Prepare Windows endpoints for Forticlient deployment with essential services and firewall rules, then apply the default profile and policy via Forticlient EMS group policy.
Explore Forticlient EMS endpoints by configuring policies and profiles, assigning deployment packages, and adjusting priorities. See how to upgrade 40 clients from 6.2.5 to 6.4.3 with one click.
Install forticlient on non-domain joined computers by preparing windows services and firewall rules, downloading the deployment package, and connecting endpoints to the EMS over ports 8013 and 443.
Learn how to uninstall 40 Forticlient endpoints from EMS by creating a server group, configuring deployment, and managing reboots to complete the uninstallation.
Learn the essential Forticlient EMS communication ports and services, including 8013 for endpoint management, 80/443 for downloads and web access, 389 for active directory, and 8000 for FortiGate integration.
Create domain and work groups, move endpoints, and apply policies, then automate grouping with group assignment rules based on IP, installer ID, or OS.
Explore classes of malware from viruses and worms to trojans and ransomware, how they spread, and how spam emails, phishing sites, and rootkits enable attacks in enterprise endpoint management.
Explore web filtering in Forticlient EMS, enabling always-on or off fabric filtering, configuring categories and safe search, managing per-category actions, exclusions, and plugin-based https enforcement for endpoints.
Enable and configure the Forticlient EMS application firewall to detect application traffic, block social media by category, use overrides to allow Instagram, and monitor and notify blocked attempts.
Identify and mitigate endpoint vulnerabilities with FortiClient EMS by patching software, running automatic or manual vulnerability scans, and applying FortiGuard vulnerability signatures to reduce risk.
Learn how to push SSL or IPsec VPN configurations from FortiClient EMS to 40 clients, including corporate and personal VPNs, and manage DNS cache and certificate settings.
Explore sandbox detection, using static and dynamic analysis to counter zero-day attacks. Learn deployment options and how the 40 client and sandbox interact, with quarantine and alert remediation.
View software inventory across all endpoints, showing vendor, version, last installed date, and install count; filter by host or user and enable sending installed applications to EMS.
Explore zero trust tags to group devices by criteria such as OS, AD group, IP range, and vulnerabilities, then apply tags to security policies via FortiClient EMS and FortiGate integration.
Establish a FortiGate–EMS connector via SSL to transfer endpoint data, tags, and Active Directory groups from FortiClient EMS to FortiGate, enabling tag-based security policies and compliance checks.
Explore FortiClient EMS administration, including built-in super administrator, restricted and standard roles, endpoint administrator permissions, domain and LDAP integration, login restrictions, and managing users, settings, and logs.
Configure system settings in Forticlient EMS, including server name, ip address, https access via fqdn, port and certificate options, logging, smtp alerts, and endpoint quarantine and web filter features.
Learn FortiClient Enterprise Management Server (FortiClient EMS) which is a security management solution that enables scalable and centralized management of multiple endpoints. FortiClient EMS provides efficient and effective administration of endpoints running FortiClient.
FortiClient offers comprehensive endpoint protection ( malware protection, viruses protection, advanced threat protection,web filtering, application filtering, removable media access control, VPN,..) for your Windows-based and Mac-based desktops, laptops, file servers, and mobile devices. FortiClient can safeguard your systems with advanced security technologies and provide a single management console.
Module 1: Introduction
Introduction Part 1: forticlient EMS and forticlient Security Features
Introduction Part 2: Architecture – Capacity – Services and Ports
Introduction Part 3: Deployment options
Module 2: Installation Preparation and installation
Lab Environment
Installing forticlient Enterprise Management Server EMS
Installing Active Directory
Module 3: Licensing and Integration between EMS and LDAP
Licensing
Integrate EMS with Active Directory
Grant the EMS access to the LDAP users
Module 4: EMS basic configuration
Default Profile and Policy
Installing forticlient on the endpoints dynamically via the EMS
Pushing the configuration dynamically from the EMS to the endpoints
Endpoints – Profiles – policies
Forticlients upgrade via the EMS in one click
Installing Forticlient on Non-Domain joined computers
Uninstalling forticlients from the EMS
EMS Communication Matrix: Required services and ports
Groups and group assignment rules
Module 5: Endpoint Security Features profiles
Malware, Virus , Bot , Spam Email and URL, Trojan, Ransomware, C&C , Vulnerability, Risk and threat
Malware Protection
Web Filtering
Application Filtering
Vulnerability Management
VPN
Sandbox Detection
System Settings
On-fabric & Of-fabric
Module 6: Software Inventory
Software Inventory
Module 6: Zero trust Tags
Zero trust Tags
Module 7: EMS and Fortigate integration
EMS and Fortigate Integration
Module 8: Administration
Administration
Module 9: System Settings
System Settings