FortiClient ZTNA in Dubai, UAE
FortiClient ZTNA gives organisations a managed endpoint agent for secure application access, VPN transition, posture-aware policy enforcement and central visibility. It is designed for teams that want to verify the user and device before granting application access and continue evaluating endpoint posture while the session is active.
Share endpoint count, EMS preference, subscription term, FortiGate environment and migration requirements for a quotation aligned to the right FortiClient SKU.
Application-focused ZTNA with device posture
FortiClient EMS or FortiClient Cloud
Endpoint/device subscriptions by pack and term
Cloud vs on-prem EMS cannot be treated as interchangeable SKUs
Direct answer for buyers
FortiClient ZTNA is the secure-access capability delivered through the FortiClient endpoint agent and managed through FortiClient EMS or FortiClient Cloud. Its main purpose is to provide controlled access to applications using user identity, device identity and endpoint posture rather than granting a remote user broad network reach by default. It is most relevant to organisations already using or planning FortiGate-based application gateways, businesses replacing selected VPN use cases, and teams that need the same access policy logic for users working inside or outside the office. Before proceeding, confirm the endpoint quantity, license term, EMS location, client operating systems, FortiGate/FortiOS compatibility, authentication design and whether the required scope is ZTNA/VPN only or includes broader endpoint-protection services.
What FortiClient ZTNA does
The FortiClient agent establishes an encrypted connection to a FortiGate ZTNA application gateway and supplies identity and endpoint context that can be used during access decisions. Fortinet’s current documentation describes continuous, near-real-time posture checks and adaptive access control, which allows policies to reflect changes in device state instead of relying on a one-time login decision. This makes ZTNA useful when the security requirement is application access with context, not merely a tunnel into the corporate network.
The same FortiClient platform can also provide VPN connectivity and other functions depending on the licensed edition. That matters during migration because an organisation can maintain familiar remote-access workflows while moving selected applications to ZTNA. Buyers should separate the features included in the VPN/ZTNA edition from EPP/ATP, managed-service and add-on options so that the bill of materials matches the actual security objective.
Who should consider it
FortiClient ZTNA is a strong fit for enterprises, midsize businesses and distributed organisations that already operate FortiGate or are standardising on Fortinet for secure application access. It can also be relevant to IT teams supporting hybrid workforces, branch users, external contractors, privileged remote users or application teams that want narrower access than a traditional network-level VPN typically provides.
It is not automatically the right choice for every remote-access project. If the organisation has no compatible FortiGate gateway, needs an entirely cloud-delivered secure-access architecture, has endpoints that cannot run the required FortiClient capabilities, or requires endpoint protection features outside the ZTNA/VPN license, the design may need FortiSASE, another FortiClient edition, or additional Fortinet components. FourTeck can help map the requirement before a subscription is selected.
Business problems the platform helps address
Over-broad remote access
ZTNA can be applied to specific applications so a user does not need broad network reach simply to access one business service. The practical value is a smaller access scope, provided applications, policies and identity sources are designed correctly.
Untrusted device state
FortiClient can supply posture information and security tags that FortiGate policies use when deciding whether a device should reach an application. The checks selected by the administrator determine how useful this control becomes.
VPN migration pressure
Organisations can plan a staged move instead of replacing every remote-access workflow at once. Existing VPN usage can be evaluated alongside ZTNA application publishing so change can follow application readiness and user groups.
Fragmented endpoint management
EMS or FortiClient Cloud centralises deployment, policy, endpoint visibility and ZTNA orchestration. This can reduce manual configuration, but the management design still needs sizing, role assignment, upgrade planning and appropriate logging.
Core capabilities buyers usually evaluate
Encrypted, per-session application access with user and device verification through FortiOS ZTNA gateway functions.
Endpoint posture can be re-evaluated and represented through ZTNA tags, enabling policy decisions to react to changing device conditions.
FortiClient EMS or FortiClient Cloud provides central provisioning, policy control, monitoring and orchestration for managed endpoints.
The VPN/ZTNA edition supports both ZTNA and encrypted VPN access, which can be useful during phased migration or for use cases not yet moved to ZTNA.
Fit matrix for FortiClient ZTNA
| Requirement | Suitable when | Confirm before ordering |
|---|---|---|
| Application-level remote access | Users should reach selected applications with identity and posture controls. | Application protocols, gateway design, certificates and policy requirements. |
| Hybrid VPN and ZTNA | Some services remain on VPN while other applications migrate to ZTNA. | Which users and applications move first and how routing changes are managed. |
| Central endpoint policy | The organisation wants EMS or FortiClient Cloud to manage endpoints consistently. | On-premises vs cloud EMS, endpoint count, administrative roles and logging needs. |
| Mobile web application access | Supported mobile devices need ZTNA access to web applications. | Current FortiClient/EMS version, MDM integration and platform limitations. |
| Full endpoint protection | Broader security functions are also required. | Whether EPP/ATP or managed FortiClient is the correct edition instead of ZTNA/VPN only. |
Verified product and licensing information
FortiClient ZTNA is sold through subscription choices rather than one universal SKU. Current Fortinet ordering information distinguishes cloud-hosted and on-premises EMS deployments, endpoint pack sizes and multi-year terms. The table below therefore describes the product accurately without treating one pack or term as the default for every buyer.
| Brand | Fortinet |
|---|---|
| Product | FortiClient VPN/ZTNA Agent subscription family |
| Main purpose | Secure application access, VPN connectivity, endpoint posture and central policy management |
| Management options | On-premises FortiClient EMS or FortiClient Cloud, depending on SKU |
| Licensing basis | Endpoint/device subscriptions |
| Published endpoint packs | 25, 500, 2,000 and 10,000 endpoints in current Fortinet ordering guidance |
| Subscription terms | One to five years are available in the current ordering structure; exact SKU must be confirmed |
| FortiGate ZTNA license | Fortinet states that no additional ZTNA-specific license is required on a FortiGate acting as the ZTNA gateway; FortiClient ZTNA licensing is required |
| Gateway support | Fortinet’s current ZTNA ordering guide states FortiGate models running FortiOS 7.0 or later can support the ZTNA gateway feature; confirm current release compatibility before deployment |
| Endpoint platforms | FortiClient support varies across Windows, macOS, Linux, iOS, Android and Chromebook; individual features differ by platform and release |
| MFA | Supported in the ZTNA/VPN capability set, but FortiToken entitlement is not automatically included and must be confirmed separately |
| CASB | Current Fortinet documentation states ZTNA licensing includes FortiCASB API-based entitlement; feature use and onboarding should be checked against the selected SKU and current service terms |
| Availability | Contact FourTeck for current UAE availability, license term and vendor lead-time guidance |
Important licensing and compatibility dependencies
The FortiClient name covers several editions and management options, so the most common purchasing mistake is assuming that every feature is included in every subscription. The VPN/ZTNA edition is designed around secure access, central management and associated controls. EPP/ATP adds endpoint-protection capabilities, while managed FortiClient adds operational services. Some features also require other Fortinet products, such as FortiAnalyzer for particular reporting functions or FortiToken licensing when token-based MFA is chosen.
Cloud and on-premises EMS choices should be decided before ordering. Fortinet’s current ordering guide notes that direct upgrades between on-premises and cloud SKUs are not supported; a move between those management models requires new SKUs to align with the new EMS instance. This is an architectural and commercial decision, not just a hosting preference.
Compatibility must also be checked at the software-release level. FortiClient, EMS, FortiOS, mobile device management and endpoint operating systems evolve independently. A quotation can identify the correct subscription, but the deployment plan should confirm the supported release combination before rollout.
From requirement to working ZTNA: a practical journey
Map users and applications
Identify who needs access, which applications are involved, where they are hosted, which protocols they use, and whether access is required from inside, outside or both.
Choose the EMS model
Decide whether FortiClient EMS is hosted by the organisation or whether FortiClient Cloud is preferred. Include administrative ownership, internet reachability, scale and operational maintenance in the decision.
Define posture and identity
Select authentication sources, MFA approach, certificate handling and the endpoint posture conditions that should influence application access. Avoid creating checks that operations cannot maintain.
Pilot before migration
Test a representative group and one or two applications first. Validate DNS, certificates, application behaviour, user experience, posture changes, logging and fallback procedures before expanding scope.
Roll out and operate
Expand through controlled groups, monitor policy outcomes, maintain compatible client releases and align renewals. Keep VPN only where it remains justified by the application or operational requirement.
Capability focus: identity and device posture together
ZTNA is most useful when the access decision is based on more than a username and password. FortiClient provides endpoint telemetry and can apply posture tags according to administrator-defined rules. FortiGate can then use user identity, device identity and posture information in application-access policy. For example, an organisation may want a managed device to meet a required security condition before a finance or engineering application becomes reachable. The exact posture logic is configurable, so the design should reflect the risk of the application rather than applying one rigid rule to every user.
This introduces an operational responsibility: posture checks must be realistic, measurable and maintained. If a condition references software, domain membership or other endpoint state, IT must understand how changes affect users. A pilot should include both compliant and deliberately non-compliant devices to verify expected behaviour. FourTeck can help translate business access requirements into an implementation scope, while the customer’s security policy should define what endpoint conditions are acceptable.
Capability focus: moving from VPN without forcing a big-bang change
Many buyers research ZTNA because traditional remote access has become too broad, difficult to segment or inconsistent with a zero-trust policy. FortiClient is useful in this context because the VPN/ZTNA edition supports both approaches. Fortinet’s current ZTNA guidance describes a staged path where organisations can first use endpoint posture information with existing VPN access and then adopt full ZTNA through the FortiGate application gateway. That allows migration to follow application readiness rather than an arbitrary cutover date.
A phased project should classify applications by protocol, sensitivity, user group, authentication method and dependency. Web applications are often straightforward candidates, but every environment differs. Legacy systems, hard-coded addressing, thick-client applications or unusual protocols may need additional testing. The project should also define what happens when a posture requirement is not met and how users receive support.
This is why licensing and technical design should be discussed together. Buying subscriptions first and discovering architecture constraints later can create unnecessary rework. FourTeck can help customers frame the migration sequence before finalising the required FortiClient pack and term.
Capability focus: central management and lifecycle control
FortiClient EMS is the management layer that turns a collection of endpoint agents into an administrable secure-access deployment. Current Fortinet documentation highlights remote client deployment, policy assignment, ZTNA orchestration, dashboards, software inventory, automatic group assignment, alerts, remote actions and zero-trust tagging rules. FortiClient Cloud provides a Fortinet-hosted EMS option for organisations that do not want to maintain their own EMS server.
The management choice has lifecycle consequences. On-premises EMS places server maintenance, backup, sizing and upgrade responsibility with the organisation. Cloud-hosted management reduces that infrastructure burden but uses different SKUs. Fortinet specifically notes that subscriptions cannot be directly upgraded between on-premises and cloud EMS deployment models. Buyers planning a later hosting change should therefore treat it as a migration project rather than a simple toggle.
Operational planning should also cover endpoint upgrade rings, policy change control, logging retention and renewal dates. For environments adding licenses over time, co-term planning can simplify expiry management. FourTeck can assist with licensing structure and bill-of-material review before procurement.
Where FortiClient ZTNA fits well
Hybrid office and remote staff
Users who move between offices, home and travel locations can be evaluated under consistent application-access logic rather than being treated as trusted simply because they are on a corporate LAN.
Contractors and third parties
Where contractors need only specific applications, ZTNA can narrow the accessible resource set. Identity lifecycle, managed-device policy and offboarding still need clear ownership.
Distributed branch environments
Branch users accessing central applications can benefit from the same user and posture logic as remote users, particularly where the organisation wants a consistent policy model across locations.
Controlled access to sensitive applications
Finance, HR, administration and operational applications can be placed behind stricter access policy. The correct posture, authentication and logging requirements should be agreed with the application owner.
Integration and operational considerations
A successful ZTNA deployment is not created by the endpoint agent alone. The application gateway, identity systems, DNS, certificates, endpoint management, firewall policy and user support process all need to work together. If FortiGate is the ZTNA gateway, confirm the FortiOS release and the application protocol requirements. If MFA is needed, confirm whether existing identity infrastructure is used or whether FortiToken or another supported method is required. FortiToken entitlement is not automatically bundled with FortiClient licensing.
Endpoint platform support should be checked by feature rather than by operating-system name alone. FortiClient is available across major desktop and mobile platforms, but capabilities differ by platform. Fortinet’s current documentation also notes that mobile ZTNA access to web applications requires compatible FortiClient/EMS versions and MDM integration. A mixed Windows, macOS, Linux, iOS and Android estate should therefore be tested against the exact feature set planned for each group.
Logging is another design decision. Decide where access events, endpoint status and security information need to be retained, who reviews them and whether FortiAnalyzer is part of the architecture. This prevents a technically working deployment from becoming difficult to operate after handover.
Questions to resolve before requesting a quote
Fortinet uses endpoint packs, so expected growth can affect the most efficient bill of materials and co-term plan.
Choose on-premises EMS or FortiClient Cloud before ordering because the subscriptions use different SKUs and moving between them is not a direct license upgrade.
List application names, hosting locations, protocols, user groups and dependencies. This gives the implementation plan a realistic starting point.
Define the device-health signals that genuinely matter to the organisation and how exceptions will be handled.
If advanced endpoint protection is also required, compare the EPP/ATP edition rather than assuming every endpoint-security feature is included.
Decide whether the requirement is supply only, configuration guidance, migration planning, pilot support, full deployment or ongoing operational assistance.
How FourTeck can assist with sizing and licensing
A useful FortiClient ZTNA quotation starts with the environment rather than a part number. FourTeck can review endpoint quantity, user groups, EMS preference, subscription term, FortiGate platform, application scope and expected implementation services. From there, the commercial requirement can be mapped to the appropriate FortiClient pack and term without assuming that a generic 25-endpoint example suits every organisation.
For customers evaluating a VPN-to-ZTNA transition, FourTeck can also help frame a phased approach: identify pilot applications, determine which users remain on VPN during transition, define the required posture and identity prerequisites, and include installation or configuration scope in the quotation where needed. This is especially valuable when the environment combines different endpoint operating systems or multiple FortiGate sites.
You can also explore FourTeck security products and deployment and support services when the requirement extends beyond licensing.
Information that speeds up a quotation
Send the endpoint count, required term, EMS model, FortiGate model/FortiOS release, endpoint operating systems, applications to publish, MFA preference and target deployment date.
If the design is still open, request a consultation first rather than locking in a license. Discuss your requirement with FourTeck.
UAE availability and support guidance
FortiClient ZTNA availability in the UAE depends on the required license family, deployment model, endpoint pack, subscription term and current vendor processing. A cloud-hosted EMS subscription and an on-premises EMS subscription are different commercial choices, so availability should be checked against the exact SKU rather than the general product name. FourTeck can coordinate a UAE quotation after the endpoint count and management model are confirmed.
If deployment help is required, include that scope before purchase so the quotation can separate subscription supply from configuration, migration or support work. License fulfilment, project scheduling and engineering availability can vary. Contact FourTeck to confirm current UAE availability, the suitable FortiClient term and the expected process for your specific requirement.
Dubai, Abu Dhabi, Sharjah and Ajman coverage
Businesses in Dubai, Abu Dhabi, Sharjah and Ajman can contact FourTeck for FortiClient ZTNA licensing guidance, requirement review, quotation coordination and project-planning assistance. The engagement can begin with a remote review of endpoint quantity, FortiGate environment, identity services and applications that need controlled access. Where installation or configuration work is requested, the exact scope, site requirements and scheduling should be agreed separately. This combined UAE coverage approach is intended to make procurement and deployment planning easier without implying that every license pack, engineer visit or project date is immediately available. Share the business location, endpoint count, required term and planned deployment model so FourTeck can respond with appropriate next-step guidance.
GCC Availability
Organisations planning FortiClient ZTNA across the GCC can use FourTeck for requirement review, license selection, quotation coordination and deployment planning. A regional project may involve the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman, but the commercial and technical requirement should still be defined per deployment. FortiClient subscriptions vary by endpoint count, term and EMS model, while identity integration, application publishing and support scope may differ between offices. FourTeck can help consolidate those inputs and prepare a clearer bill of materials or phased project request. Product availability, electronic license processing, vendor lead times, service visits and project schedules can vary by country and requirement. Buyers should provide the destination country, endpoint quantity, preferred term, EMS hosting choice, FortiGate environment and expected rollout timing before relying on a quotation. For regional technology enquiries, FourTeck’s Kuwait presence can also be relevant to GCC coordination.
Africa Availability
FourTeck can also assist organisations evaluating FortiClient ZTNA for projects in Africa, including deployments spanning East Africa and other regional operations. The starting point should be the exact subscription requirement and technical architecture rather than an assumption about local inventory. Endpoint quantity, license term, cloud or on-premises EMS, FortiGate gateway design, user identity, endpoint operating systems and implementation scope all influence the correct order. Fulfilment may also depend on the destination country, vendor lead time, license region, project conditions and any local deployment requirements. Buyers should share the destination country, exact requirement, quantity, preferred rollout schedule and support expectations so FourTeck can advise on a suitable procurement route. For projects in East Africa, buyers can review FourTeck Kenya, FourTeck Uganda and FourTeck Africa for relevant regional contact paths.
Related options and complementary services
FortiClient EPP/ATP
Consider this edition when the requirement combines ZTNA with broader endpoint-protection capabilities. Confirm the exact feature set and subscription before choosing it as an alternative.
FortiSASE
Relevant when the secure-access requirement extends toward cloud-delivered SASE capabilities rather than a FortiGate-centred ZTNA gateway architecture.
FortiGate ZTNA gateway
FortiGate provides the ZTNA application-gateway function. The existing model, FortiOS release, capacity and application design should be confirmed before deployment.
ZTNA implementation support
Use configuration or migration services when the project needs application publishing, posture design, pilot rollout, VPN coexistence planning, documentation or handover.
What buyers are trying to understand before choosing FortiClient ZTNA
One of the most common research questions is whether FortiClient ZTNA is simply another VPN. It is not. The same FortiClient agent can provide VPN connectivity, but ZTNA is designed around controlled access to applications with user and device verification. A traditional VPN generally creates a tunnel into a network segment; a ZTNA design aims to expose only the applications the policy permits. This difference affects architecture, firewall rules, troubleshooting and user experience. Buyers should therefore decide whether they are replacing a specific VPN use case, improving posture checks on an existing VPN, or building full application-level ZTNA.
For centrally managed FortiClient ZTNA deployments, EMS or FortiClient Cloud provides the control plane for endpoint management, policy and ZTNA orchestration. The buyer must choose the management model. A free standalone VPN client should not be mistaken for the managed ZTNA subscription described on this page.
Current Fortinet ordering guidance states that only the FortiClient ZTNA license is required for this use case and no additional ZTNA-specific license is required on a FortiGate acting as the gateway. The FortiGate model, FortiOS release and normal platform entitlements still need verification.
Yes, the VPN/ZTNA edition is designed to support both. This enables practical migration: keep VPN for applications that still require it, introduce ZTNA for suitable applications, and reduce network-level access progressively rather than forcing every application into one cutover window.
Endpoint count, EMS deployment model, subscription term and selected FortiClient edition are the main commercial variables. Installation, configuration or migration services are separate project considerations. A useful quote must therefore state the endpoint pack and exact term rather than advertising one generic product price.
Another frequent question concerns cloud versus on-premises EMS. The difference is not only where a management server runs. FortiClient Cloud is a Fortinet-hosted EMS service, while on-premises EMS is deployed and maintained by the customer. The two options use different subscription SKUs, and Fortinet’s current ordering guide specifically warns that direct subscription upgrades between on-premises and cloud EMS are not supported. If an organisation expects to change the hosting model later, it should consider that migration effort and licensing impact during initial procurement.
Buyers also ask whether mobile users are supported. FortiClient supports major desktop and mobile platforms, but the feature set is not identical on every operating system. Current Fortinet documentation states that ZTNA for web applications on mobile devices is supported with FortiClient/EMS 7.2.2 or later when EMS is integrated with mobile device management. This is a good example of why a high-level statement such as “supports iOS and Android” is not enough for design approval. The exact feature, release and MDM dependency should be checked.
For organisations comparing FortiClient ZTNA with a broader endpoint-security license, the key question is the security objective. If the project is primarily secure application access with VPN coexistence, the VPN/ZTNA edition may be appropriate. If the same endpoint agent must also deliver additional endpoint-protection capabilities, evaluate the EPP/ATP edition. Fortinet’s current documentation states that EPP licensing includes ZTNA entitlements, so buyers should avoid purchasing overlapping capabilities without understanding the subscription structure.
Finally, buyers preparing a quotation should provide enough technical context for the license to match the deployment. The minimum useful information is endpoint count, preferred term, EMS model, FortiGate model and FortiOS release, endpoint operating systems, identity source, MFA requirement and the applications selected for the first phase. Adding whether the customer needs supply only, configuration, migration or a pilot makes the commercial response more useful and reduces the risk of receiving a price for the wrong subscription.
Decision questions that improve the design before purchase
Should we buy cloud-managed or on-premises EMS?
Choose based on who will operate the management platform, infrastructure policy, internet dependency, administrative control and lifecycle responsibility. FortiClient Cloud reduces customer-hosted EMS infrastructure, while on-premises EMS keeps the management server under the organisation’s control. Because the SKUs are different and direct upgrades between the two are not supported, this choice should be made before the order is placed.
How do we know whether an application is a good ZTNA candidate?
Start with applications that have a clear user population, known protocol behaviour, stable identity integration and a business reason for narrower access. Test how the application behaves through the FortiGate ZTNA gateway, including DNS, certificates, authentication, idle sessions and dependent services. Legacy or unusual protocols may need more investigation before migration.
What if our users fail posture checks?
A posture rule should have an operational outcome, not merely deny access. Define what the user sees, how IT verifies the failed condition, whether remediation is automatic or manual, and how temporary exceptions are governed. Pilot the rules with both healthy and deliberately non-compliant endpoints before applying them to a large group.
Do we need to replace VPN everywhere?
No. Many organisations keep VPN for use cases that are not yet practical to move and use ZTNA for selected applications. The right objective is to reduce unnecessary network-level access where it makes business and technical sense. A phased approach also gives teams time to validate application behaviour and user support processes.
How should endpoint quantity be calculated?
Count the devices that require the licensed FortiClient capabilities, not just employee headcount. Shared devices, multiple devices per user, servers and future growth can affect the quantity. Fortinet publishes endpoint packs, so a small change in required count can change the most appropriate order combination and renewal plan.
What information should we send FourTeck first?
Provide the endpoint count, preferred contract term, EMS deployment choice, FortiGate details, endpoint operating systems, identity and MFA approach, initial application list and desired support scope. If any of those items are undecided, FourTeck can begin with a consultation rather than forcing an early SKU selection.
Why businesses contact FourTeck for FortiClient projects
The value of a reseller or integrator in a FortiClient project is not a generic claim about product quality; it is the ability to turn a business requirement into a workable bill of materials and implementation scope. FourTeck can help clarify the number of endpoints, determine whether cloud or on-premises EMS is preferred, check whether ZTNA/VPN or EPP/ATP is the more suitable edition, and align the subscription term with procurement expectations.
FourTeck can also help separate licensing questions from deployment questions. A buyer may already know the required subscription but still need assistance with pilot planning, application publishing, identity integration, posture policy, migration sequencing or handover. Defining these activities before purchase makes the quotation easier to compare and reduces ambiguity during implementation.
For broader company information, visit About FourTeck or contact the team through the Dubai technology enquiry page.
Frequently asked questions
Is FortiClient ZTNA the same as the free FortiClient VPN?
No. The managed FortiClient ZTNA offering uses subscription licensing and central management through EMS or FortiClient Cloud. A standalone VPN client should not be treated as an equivalent replacement for the managed ZTNA capability.
Does FortiClient ZTNA require FortiGate?
For the FortiGate-based Universal ZTNA architecture described here, FortiGate provides the ZTNA application-gateway function. Confirm the FortiGate model and FortiOS release as part of the design.
Do I need a separate ZTNA license on FortiGate?
Fortinet’s current ZTNA ordering guide states that the FortiClient ZTNA license is the required ZTNA license and no additional ZTNA-specific license is needed on the FortiGate gateway. Normal platform licensing and compatibility still apply.
Can FortiClient ZTNA and VPN be used at the same time?
Yes. The VPN/ZTNA edition supports both, making it suitable for staged migration where some applications use ZTNA while others remain on VPN.
Is FortiClient ZTNA licensed per user or per device?
Current Fortinet ordering guidance for the managed VPN/ZTNA offering is endpoint/device based. Published pack sizes include 25, 500, 2,000 and 10,000 endpoints. Confirm the exact SKU and term for the planned deployment.
Should we use FortiClient Cloud or on-premises EMS?
Choose according to operational ownership, infrastructure policy and management preference. The two options use different SKUs, and Fortinet states that direct subscription upgrades between on-premises and cloud EMS are not supported.
Does the ZTNA license include endpoint antivirus and advanced protection?
Do not assume it does. FortiClient has multiple editions. If broader endpoint protection is required, compare the EPP/ATP edition and confirm the feature matrix for the current release.
Can mobile devices use FortiClient ZTNA?
Fortinet supports ZTNA use cases on mobile, but feature availability is version and management dependent. Current guidance states web-application ZTNA on iOS and Android requires FortiClient/EMS 7.2.2 or later with EMS integrated to MDM.
What do you need to prepare a UAE quotation?
Provide endpoint count, preferred term, cloud or on-premises EMS, FortiGate details, endpoint platforms, MFA needs, first-phase applications and whether configuration or migration support should be included.
Is FortiClient ZTNA currently available in Dubai?
Contact FourTeck to confirm current UAE availability for the required endpoint pack, deployment model and subscription term. Availability and license processing can vary by SKU and vendor lead time.
Build the quotation around your actual ZTNA plan
Tell FourTeck how many endpoints you need to manage, whether EMS should be cloud-hosted or on-premises, which FortiGate environment is in use, and whether you need licensing only or help with pilot, migration and configuration. The team can then coordinate the correct FortiClient subscription and current UAE availability.