What is our primary use case?
We use it for endpoint security. We were searching if it could replace our old EDR solution.
We use it for everything now. We no longer have another security solution except from the Microsoft 365 package.
Fortinet FortiEDR handles our main endpoint security.
How has it helped my organization?
We have FortiEDR installed on all our systems. This protects them from any threats.
This solution has improved our endpoint security posture. Before this, we didn't have any EDR solution, just standard endpoint security.
Now, with FortiEDR's behavior analysis and comprehensive threat detection, we definitely have better protection.
What is most valuable?
We chose FortiEDR because we were looking for a robust EDR solution. One thing that appealed to us was the potential integration with our FortiGate firewalls.
We hoped to mitigate threats and stop the traffic by having the firewall and EDR work together, but this wasn't straightforward out-of-the-box. It needs specific configuration which hasn't been done yet. That was a bit unexpected.
What needs improvement?
I would like to improve the integration process because a big selling point was the ease of integration within the Fortinet ecosystem. I would expect more built-in collaboration to allow for easier threat mitigation across Fortinet systems.
The strength of FortiEDR lies in its overall ability to protect us from new threats. We have encountered issues with it as well.
We've had a lot of false positives; things incorrectly flagged that require manual configuration to allow. Even worse, after we allow a legitimate program, it sometimes gets flagged again after an update. This has caused a lot of extra work for my team. I would like to see improved heuristics so the system better understands what's legitimate and doesn't keep blocking it after minor updates.
Buyer's Guide
Fortinet FortiEDR
January 2025
Learn what your peers think about Fortinet FortiEDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,997 professionals have used our research since 2012.
For how long have I used the solution?
I have been using it for a year. We use the latest version in my company.
What do I think about the stability of the solution?
I would rate the stability a six out of ten.
We've had some erroneous warnings that didn't make sense. It gives me the impression of a product that still has some issues to resolve.
Additionally, there are three main areas of concern:
- The product itself seems to have some unresolved issues.
- The integration with the rest of the Fortinet ecosystem could be better. It feels standalone rather than part of an integrated solution.
- The high level of maintenance required due to the heuristics, or lack thereof. We keep seeing the same warnings and blockages even after updates. We need to constantly be on top of it, allowing traffic repeatedly.
So, all those factors impact the overall stability. There's room for improvement, especially considering it's a newer version.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten.
It's installed on everyone's devices, so it's protecting users during working hours. Think of it as active for five days a week. We use it to its maximum capacity.
We have around 500 end users.
How are customer service and support?
We work through our supplier for support. We've shared our findings and issues, and there was some initial back-and-forth to find the root cause. There wasn't a clear, immediate answer or solution. They opened tickets with Fortinet, so it feels like the whole process is still evolving.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We had traditional endpoint security, but this is our first EDR solution.
How was the initial setup?
We didn't have any major problems during the installation while in monitoring mode. Issues arose, causing a lot of overhead, when we enabled the prevention mode and started seeing those false positives.
If we're looking strictly at the setup, there weren't any problems. I'd rate my experience with it an eight out of ten, with ten being easy and one being difficult to set up.
The implementation itself was fine, but we experienced a lot of frustration due to the overhead of those false positives. We had to dedicate someone to constantly monitor and allow legitimate traffic. This created a negative experience with FortiEDR.
What about the implementation team?
The deployment involved installing it on all our endpoint user devices. One person handled the deployment.
We use it on the cloud. Since it's a managed service, the provider handles the systems where it's installed. We install the client on our users' devices.
We have one person dedicated to maintaining, but I'd like to have less overhead. There's too much time spent handling these findings. We'll be working with the service provider to try to reduce that.
What's my experience with pricing, setup cost, and licensing?
We license it per employee, so as long as the employee count remains the same, the licensing won't change. We have it installed on every device.
We got a good deal on licensing, so it is in the competitive range.
I would rate the pricing a seven out of ten, with ten being expensive, and one being cheap.
The pricing is fixed. However, we had larger configuration costs associated with the implementation.
Which other solutions did I evaluate?
We considered CrowdStrike and Microsoft Defender. Cost was a factor, and we were interested in the potential integration with FortiGate firewalls. However, that integration didn't work out as smoothly as expected.
What other advice do I have?
Definitely have a small testing environment and not just monitor mode. Include a limited network so you can see how it reacts in full prevention mode to assess the potential impact of false positives.
Also, if you are interested in integration with FortiGate firewalls, carefully investigate how that collaboration will be achieved.
Overall, I would rate the solution a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.