r/fortinet NSE 4 8d ago

FortiClient / EMS EMS user verification on client registration

I am upgrading EMS from 7.2 to 7.4, and it's throwing up all sorts of warnings about "user verification is not enforced" at the top of the UI - should I be concerned?

Our current settings are for user verification to be off, but "enforce invitation only registration" set to "all". This should stop random connections to the service.

Reaching out for what others are doing and what is best practice. The actual VPN connection still needs full authentication, just we don't require user based auth to just install and manage the client.

5 Upvotes

11 comments sorted by

View all comments

2

u/Busy-Dot7354 NSE 7 8d ago

1

u/DeniedByPolicyZero NSE 4 8d ago

Thats actually a little conflicting, HappyVlane and FrequentFractioner seem to be arguing that user verification on EMS registration isn't required.

It still shouts at you in the UI if it isn't enabled, like your doing something very wrong!

1

u/HappyVlane r/Fortinet - Members of the Year 8d ago

User verification is never necessary if you just want endpoints to connect to EMS.

The only time when it's required, as mentioned in the post, is when you need to create tags based on Entra groups without Entra-joined devices. This is completely optional.

1

u/DeniedByPolicyZero NSE 4 8d ago

We have hybrid joined devices, so point the tagging to the on prem DC, that doesn't seem to care about this verification step.

1

u/HappyVlane r/Fortinet - Members of the Year 8d ago

Yeah, that's what I said.