We use this product to deploy to all the clients we have to monitor any kind of suspicious activities occurring on the end points besides antivirus. This will kind of automate their response basically with the EDR. I'm a security analyst and we are customers of Fortinet.
Security Analyst at a tech services company with 11-50 employees
Automation saves us time; forensic detailing and memory exfiltration are great for separate analysis
Pros and Cons
- "Ability to get forensics details and also memory exfiltration."
- "Detections could be improved."
What is our primary use case?
How has it helped my organization?
Since we've had this solution we've been able to monitor different hosts of services and different devices effectively. We can also automate to save a lot of time instead of doing things manually.
What is most valuable?
The most valuable features would be the ability to get forensics details and also memory exfiltration so we can analyze them separately after an incident.
What needs improvement?
Detections could definitely be improved. It's still detecting some things that it shouldn't be like Microsoft Intune and 365 devices as well.
I'd like to see an improvement in the reporting. There are currently no reporting capabilities so I would definitely want to see that.
Buyer's Guide
Fortinet FortiEDR
January 2025
Learn what your peers think about Fortinet FortiEDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,997 professionals have used our research since 2012.
For how long have I used the solution?
I've been using this solution for 18 months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We haven't had issues with scalability and we have over 5,000 endpoints. In the security team we have four people who use the solution daily. The others use it in case of emergency.
How was the initial setup?
The initial setup was very straightforward.
What other advice do I have?
This is definitely a good product and will make your life easier.
I would rate this solution a seven out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technical Officer at Provision Technologies LLP
Has an easy setup and good firewall response
Pros and Cons
- "The ease of deployment and configuration is valuable. It's very easy compared to other vendors like Sophos. Sophos' configuration is complex. Fortinet is a lot easier to understand. You don't need a lot of admin knowledge to do the configuration."
- "The security should be strong for the cloud. Some applications are on-prem and some are on the cloud. Fortinet should also have strong security for the cloud. There should be more security for the cloud."
What is most valuable?
The ease of deployment and configuration is valuable. It's very easy compared to other vendors like Sophos. Sophos' configuration is complex. Fortinet is a lot easier to understand. You don't need a lot of admin knowledge to do the configuration.
The security is also very good and the firewall response is good.
What needs improvement?
Clients want to be in a hybrid mix and match mode. The security needs to be relevant in that way as well. It has to be online, on the cloud and on-premises. This is the customer's mindset. They don't want to go for user applications on the cloud. They think it will fail and the data will be inaccessible. They don't want to go to the cloud platform. The security should be strong for the cloud. Some applications are on-prem and some are on the cloud. Fortinet should also have strong security for the cloud. There should be more security for the cloud.
For how long have I used the solution?
I have been using FortiEDR for the last year.
What do I think about the stability of the solution?
It runs constantly, 24/7. It is quite stable. We haven't had any stability issues.
What do I think about the scalability of the solution?
It is scalable. It is good for both small and large companies. Security has to be strong, it should be at the same standard. It's suitable for all business sizes.
How are customer service and technical support?
We haven't needed to contact support for EDR.
How was the initial setup?
The deployment can be done in one week. We have configured it within a week. It takes generally three people to set it up. I supervise the team.
What's my experience with pricing, setup cost, and licensing?
There are no additional costs.
What other advice do I have?
As of now, it's very good. We don't have a lot of challenges. The EDR concept is new to the market. It doesn't have a lot of competition. As of now, we don't have a lot of user input. If it's on the market for a few more years, I'm sure people will have more feedback.
We do our own documentation and share the whitepapers with our clients. I don't find Fortinet to be a difficult tool. The reporting is good and designed in a way that even a newcomer can use it easily. As of now those clients who have migrated from other security vendors don't have a lot of challenges. The clients appreciate the technology and report that they have tangible benefits.
I would rate it a nine out of ten. All of the requirements are addressed nicely and the security is covered. It has everything it needs.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Fortinet FortiEDR
January 2025
Learn what your peers think about Fortinet FortiEDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,997 professionals have used our research since 2012.
Manager Networking Solutions at CCS Computer's Pvt Ltd
A stable solution with a straightforward setup and good technical support
Pros and Cons
- "Fortinet FortiEDR's scalability is quite good, and you can add licenses to the solution."
- "The solution should address emerging threats like SQL injection."
What is our primary use case?
The solution is used by a small organization of around 500 end users to provide online courses to their students.
What is most valuable?
Fortinet FortiEDR's scalability is quite good, and you can add licenses to the solution.
What needs improvement?
Fortinet FortiEDR should include some of the new features and better pricing. The solution should address emerging threats like SQL injection. It would be good if the solution detects ransomware files.
For how long have I used the solution?
We have implemented Fortinet FortiEDR for our clients, and they have been using it for the last two to three years.
What do I think about the stability of the solution?
Fortinet FortiEDR is a stable solution. Our client has been running it successfully for the last three years.
How are customer service and support?
The solution's technical support is good and fast.
How was the initial setup?
The solution's initial setup is very straightforward.
What about the implementation team?
The solution was deployed within a week.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiEDR has a yearly subscription. The solution's pricing should be improved because other players in the market are coming up with competitive prices.
What other advice do I have?
Two to three people are required to deploy Fortinet FortiEDR.
Overall, I rate Fortinet FortiEDR an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Security, infrastructure and networking engineer at Abetelnet Solutions
A stable solution that delivers real-time, automated endpoint protection with orchestrated incident response across any protected device
Pros and Cons
- "Additionally, when it comes to EDR, there are more tools available to assist with client work."
- "We've encountered challenges during API deployment, occasionally resulting in unstable environments."
What is our primary use case?
It is mostly used according to client’s need.
What is most valuable?
I believe that easy deployment is primarily used to facilitate client learning. Additionally, when it comes to EDR, there are more tools available to assist with client work.
What needs improvement?
We've encountered challenges during API deployment, occasionally resulting in unstable environments. Deployment can be a bit tricky at times. In terms of pricing, EDR tends to be more costly than FortiClient. In some cases, we opt for FortiClient because clients may not have the resources or time to invest in EDR.
For how long have I used the solution?
I have experience with Fortinet FortiEDR.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
The customer service is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is pretty easy and I would rate it an eight out of ten.
What's my experience with pricing, setup cost, and licensing?
It is expensive and I would rate it an eight out of ten.
What other advice do I have?
I would overall rate it an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cyber Security Analyst at a retailer with 1,001-5,000 employees
Is stable and scalable but limited in the number of details it provides
Pros and Cons
- "It is stable and scalable."
- "The amount of usage, the number of details we get, or the number of options that can be tweaked is limited in comparison to that with other EDR solutions"
What is most valuable?
It is stable and scalable.
What needs improvement?
Comparatively, it works fine, but the amount of usage, the number of details we get, or the number of options that can be tweaked is limited in comparison to that with other EDR solutions. The ability to make certain changes or investigate is also limited.
Also, the investigation and the details, which I would get when I'm looking into it, and the ways I could configure or white list or black list a few things are also limited. It is not up to an extent where it can give me granular options to do that.
For how long have I used the solution?
I've been using it for about a year.
What do I think about the stability of the solution?
The stability is pretty good.
What do I think about the scalability of the solution?
It is scalable.
What other advice do I have?
For some organizations, FortiEDR is good enough, but for others, it's not. It depends on the organization's infrastructure.
I would rate Fortinet FortiEDR at six on a scale from one to ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Team Lead at Comtrade Group
Collects valuable endpoint data with good analytics and helpful scalability
Pros and Cons
- "The data collected from the endpoint where the EDR is installed is highly valuable for me."
- "The data collected from the endpoint where the EDR is installed is highly valuable for me."
- "In smaller markets like Serbia, Bosnia, Montenegro, and Slovenia, it can be challenging to find customers with 500 endpoints. My suggestion to Fortinet would be to lower this minimum order quantity to one."
- "When I implemented FortiEDR, it identified Cisco AnyConnect VPN as malicious data, which led to the VPN being cut off. Consequently, people could not work remotely from home."
What is our primary use case?
For FortiDR, it serves as an add-on to the firewalls and the SD-WAN solution that I am already using from Fortinet. Basically, it is an additional layer on top of my existing network environment.
Initially, when I started, I bought FortiGate from Fortinet. After that, I implemented tools like webmail. Then, after maybe six months to a year, I decided to switch from my existing EDR to other vendor solutions, like Kaspersky, Trend Micro, or Broadcom, and eventually switched to Fortinet since it's interoperable with the firewall I am already using.
The EDR became the next step in implementing Fortinet solutions for me.
What is most valuable?
The data collected from the endpoint where the EDR is installed is highly valuable for me. The firewall and FortiEDR Analyzer use this data for analytics, collecting it from the endpoint. This data allows for comprehensive analysis and better security measures. The collection and analysis of data are essential features that enhance its functionality significantly within my network.
What needs improvement?
This is a question for the partners who implement and install it. I am not involved in the implementation process, so I cannot suggest improvements. As mentioned, this is a query for my presales team, not me. I am part of the security team lead, focusing mainly on sales.
Regarding the product, Fortinet could consider reducing the minimum order quantity for EDR, currently set at 500 pieces. In smaller markets like Serbia, Bosnia, Montenegro, and Slovenia, it can be challenging to find customers with 500 endpoints. My suggestion to Fortinet would be to lower this minimum order quantity to one.
For how long have I used the solution?
I have been working with it since September 2016. It is approaching nine years now as of September this year, although it may not be successful.
What do I think about the stability of the solution?
I encountered a situation at a radio and television station in Serbia. When I implemented FortiEDR, it identified Cisco AnyConnect VPN as malicious data, which led to the VPN being cut off. Consequently, people could not work remotely from home. If they enabled FortiEDR, it severed the connection since it flagged Cisco AnyConnect as malicious and fraudulent, disrupting the VPN tunnel to the headquarters. After that, I stopped scanning the Cisco AnyConnect and switched to Fortinet VPN.
Everything worked fine afterward. However, if a customer prefers not to switch from another VPN solution, FortiEDR might still see it as an issue and detect it as potentially malicious, causing problems in the working environment.
What do I think about the scalability of the solution?
It is very easy to scale and is highly scalable due to being a Fortinet product. When implemented in a Fortinet environment with an existing firewall, FortiAnalyzer, and FortiManager, it is straightforward to install and scale by adding more EDR for endpoints.
How are customer service and support?
Their performance is decent, though not excellent. Response times can sometimes be slow. When I request technical support, the response time can vary, sometimes taking up to ten to fourteen hours. That's acceptable. However, for setting up some proper solutions for issues at the customer site, it can take about one week. This duration is excessive.
How would you rate customer service and support?
Negative
What's my experience with pricing, setup cost, and licensing?
It's reasonably priced compared to other vendors' similar products.
What other advice do I have?
I would rate the overall solution as nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Last updated: Jan 30, 2025
Flag as inappropriateBuyer's Guide
Download our free Fortinet FortiEDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Endpoint Detection and Response (EDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cisco Secure Endpoint
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Elastic Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
Trend Vision One
Check Point Harmony Endpoint
VMware Carbon Black Endpoint
Buyer's Guide
Download our free Fortinet FortiEDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are pros and cons of CrowdStrike Falcon vs Fortinet FortiEDR?
- What's the difference between Fortinet's FortiEDR and FortiClient?
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?
- What is the best EDR or XDR product for a company with 9000 employees?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Do we need to use both EDR and Antivirus (AV) solutions for better protection of IT assets?
- How does EternalBlue work?