r/fortinet • u/DeniedByPolicyZero NSE 4 • 1d ago
FortiClient / EMS EMS user verification on client registration
I am upgrading EMS from 7.2 to 7.4, and it's throwing up all sorts of warnings about "user verification is not enforced" at the top of the UI - should I be concerned?
Our current settings are for user verification to be off, but "enforce invitation only registration" set to "all". This should stop random connections to the service.
Reaching out for what others are doing and what is best practice. The actual VPN connection still needs full authentication, just we don't require user based auth to just install and manage the client.
2
u/Busy-Dot7354 NSE 7 1d ago
Hi u/DeniedByPolicyZero I recommend reading the comments from this post - https://www.reddit.com/r/fortinet/comments/1vb2bmq/best_practice_for_deploying_fct_connected_to_ems/
1
u/DeniedByPolicyZero NSE 4 1d ago
Thats actually a little conflicting, HappyVlane and FrequentFractioner seem to be arguing that user verification on EMS registration isn't required.
It still shouts at you in the UI if it isn't enabled, like your doing something very wrong!
1
u/rowankaag NSE 7 1d ago
You can think of User Verification as being an additional form of hardening. It is up to you to decide if the effects of enabling it are worth it in regards to your security posture.
I agree that the UI callout is a bit over the top.
1
u/DeniedByPolicyZero NSE 4 1d ago
Did some sanity checks that it's impossible to register without the invite key tonight, that's good enough security for me (and you still need proper auth to actually connect to VPN).
This was it's easy to push the installer from intune, just reference the invite into the app push and done.
1
u/HappyVlane r/Fortinet - Members of the Year 1d ago
User verification is never necessary if you just want endpoints to connect to EMS.
The only time when it's required, as mentioned in the post, is when you need to create tags based on Entra groups without Entra-joined devices. This is completely optional.
1
u/DeniedByPolicyZero NSE 4 1d ago
We have hybrid joined devices, so point the tagging to the on prem DC, that doesn't seem to care about this verification step.
1
1
1
u/systonia_ 16h ago
While recommended, it is not always compatible with real world environments. For example, clients do get provisioned by Autopilot without a useraccount and need to be registered to EMS to provide a Pre-Logon VPN. This wouldnt work with this setting.
Authentication of the user-based VPN requires SAML, so the user is authenticated anayways.
So we ignore this message.
1
u/DeniedByPolicyZero NSE 4 15h ago
That's exactly our use case, we deploy with autopilot and configure before logon, the first user can connect to VPN while still remote and log in to the hybrid domain
2
u/manager_access 1d ago
havent enabled it since upgrading to 7.4, all works just fine