Cloud-delivered web and firewall controls
ZTNA and FortiGate integration options
CASB and data-protection capabilities
Standard, Advanced and Comprehensive
What FortiSASE is and when to consider it
FortiSASE is a cloud-delivered security service edge solution that extends Fortinet security controls to users and locations that are no longer protected by a traditional office perimeter. It is mainly used to provide secure internet access, secure SaaS access and controlled access to private applications for remote and distributed users. Organisations already using FortiGate Secure SD-WAN may also evaluate it as part of a wider single-vendor SASE design. Before proceeding, a buyer should confirm user count, device count, subscription tier, identity source, private-application connectivity, required security locations, endpoint support, traffic volumes and any branch on-ramp or thin-edge design. Licensing, PoP choice and add-ons can change the bill of materials, so the exact requirement should be validated before ordering.
What it does
FortiSASE places cloud-delivered security controls between users and the applications or services they are trying to reach. Depending on the licensed tier and deployment, it can apply secure web gateway inspection, firewall controls, zero-trust network access, cloud application controls, data loss prevention, endpoint protection functions, reporting and digital experience monitoring. The service supports agent-based users through FortiClient and selected agentless use cases. Fortinet also provides options for branch on-ramp and thin-edge connectivity, helping organisations extend security policy beyond individual laptops to selected sites and devices.
Who it suits
FortiSASE is relevant to businesses with hybrid employees, distributed branches, growing SaaS usage, private applications hosted in data centres or clouds, or a need to standardise security policies for users working inside and outside the corporate network. It can be especially relevant where an organisation already uses FortiGate, Fortinet Secure SD-WAN or Fortinet security operations tools and wants to reduce the number of separate access and security products. It is not automatically the right choice for every environment; buyers should compare identity architecture, endpoint mix, application paths, compliance needs, licensing costs and operational ownership before committing.
Business challenges FortiSASE can help address
Users outside the office
Remote staff often reach web, SaaS and private applications from networks that the organisation does not control. FortiSASE is intended to extend policy enforcement and inspection closer to the user rather than depending only on a central office firewall.
Too many separate security tools
Many companies accumulate VPN, web filtering, endpoint, SaaS control and branch-security products from different vendors. A consolidated SASE design can reduce policy fragmentation, although migration planning is still required and existing tools may need to run in parallel during transition.
Inconsistent private access
Traditional VPN access can give users broad network reach. FortiSASE supports application-oriented zero-trust access patterns so organisations can design access around identity, device context and approved applications. The exact policy outcome depends on configuration and identity integration.
Limited SaaS visibility
Business teams may adopt cloud applications without central review. CASB capabilities can help security teams identify and control SaaS usage, while data-protection features can add policy around sensitive information. API coverage and controls should be checked for the applications that matter to the buyer.
Core capabilities in the current FortiSASE platform
Applies web, DNS, malware and encrypted-traffic security controls to internet access according to configured policies.
Delivers cloud-based firewall inspection for user traffic, reducing dependence on a physical perimeter for roaming workers.
Supports explicit application access based on identity and device context rather than giving remote users broad network-level access by default.
Provides inline and API-oriented controls for SaaS visibility, sanctioned application use and selected data-protection requirements.
Helps operations teams investigate user-to-application performance. Availability depends on subscription tier and endpoint method.
Supports selected FortiAP, FortiExtender, FortiBranchSASE and branch on-ramp scenarios so some remote sites can be protected without relying only on endpoint agents.
FortiSASE fit matrix
| Requirement | Suitable when | Confirm before ordering |
|---|---|---|
| Hybrid workforce security | Users need policy enforcement from office, home and mobile locations | User count, device count, agent support and identity source |
| Secure private application access | The business wants application-specific access instead of broad VPN reach | FortiGate hub, SD-WAN bundle, application publishing and authentication design |
| SaaS governance | Security teams need stronger visibility and policy for cloud applications | Which SaaS platforms require inline or API-based control |
| Branch on-ramp | Sites need to send traffic to FortiSASE without installing agents on every local device | CPE support, tunnel design, bandwidth, redundancy and location licensing |
| Operational consolidation | The organisation wants fewer separate consoles and policy stacks | Current tool overlap, migration sequencing, SOC workflows and reporting requirements |
Verified product and subscription information
FortiSASE is a subscription service rather than a fixed hardware appliance, so buyers should evaluate the service tier, user band, term, deployment method and required add-ons as part of the specification. The following information reflects current Fortinet documentation reviewed for the platform. Exact commercial terms should still be confirmed in the quotation because vendor bundles and ordering rules can change.
| Brand | Fortinet |
| Product name | FortiSASE |
| Product type | Cloud-delivered security service edge / SASE platform |
| Primary use | Secure internet, SaaS and private application access for distributed users and selected branches |
| Remote user subscriptions | Standard, Advanced and Comprehensive |
| User bands | 50–499, 500–1,999, 2,000–9,999 and 10,000+ users in the current ordering guide |
| Devices per user | Up to three devices per user in the current remote-user subscription table; additional device registration can affect license consumption |
| Endpoint operating systems | Windows, macOS, Linux, iOS and Android are listed for current remote-user subscriptions |
| Secure internet access | SSL inspection, antivirus, intrusion prevention, web and DNS filtering, botnet filtering; Secure Browser availability depends on tier |
| Secure SaaS access | Inline CASB and DLP are listed across tiers; cloud API CASB and DLP are license dependent |
| Secure private access | FortiGate private access and ZTNA options; FortiGate SPA can require an SD-WAN Service Bundle |
| Digital experience monitoring | Available in supported subscription tiers and agent-based scenarios; confirm current entitlement |
| Management | SASE cloud management and REST API are listed in the current ordering guide |
| FortiManager integration | FortiManager 7.4.4 and later is documented for synchronising selected security profiles, users, groups and firewall objects |
| Security locations | Fortinet Cloud locations for Standard; Advanced and Comprehensive can include Fortinet and Public Cloud locations according to current subscription rules |
| UAE location guidance | Fortinet currently lists Dubai security locations in its live FortiSASE infrastructure; exact tenant location entitlement must be confirmed during licensing and activation |
| Availability | Contact FourTeck for current UAE licensing, quotation and vendor lead-time guidance |
Licensing, location and deployment dependencies
FortiSASE should not be purchased as though every subscription provides the same functionality and location choice. The current Fortinet ordering guide uses Standard, Advanced and Comprehensive remote-user tiers. Some functions, including Secure Browser, agentless ZTNA, digital experience monitoring, assisted onboarding and wider public-cloud location choices, vary by tier. Comprehensive subscriptions below certain user counts can also have different location availability. FortiGate Secure Private Access connectivity may require the relevant SD-WAN service bundle, and branch on-ramp or thin-edge deployments introduce additional subscription and hardware considerations.
The practical lesson for a buyer is to design the requirement before choosing the SKU. Start with the user population, then identify the applications they access, where those applications live, which identities will authenticate, what endpoints are used and whether branch devices need cloud inspection. From there, map the necessary features to the subscription tier, location count, private-access design and add-ons. FourTeck can assist with this bill-of-material review, but the final entitlement should be checked against current Fortinet ordering documentation at the time of quotation.
A practical FortiSASE purchase and rollout journey
Map users and applications
List employees, contractors, endpoint types, internet destinations, SaaS services and private applications. Identify whether users need the same access from office and remote locations.
Review identity and posture
Confirm the identity provider, MFA approach, endpoint management method and device-posture requirements. These choices affect how zero-trust policies can be designed.
Select the subscription tier
Compare Standard, Advanced and Comprehensive against required functions, security locations, onboarding expectations and management integrations.
Design application connectivity
Determine whether private applications connect through FortiGate hubs, Secure SD-WAN, other supported CPEs, branch on-ramp or agentless publishing methods.
Pilot policies
Use a representative user group to test web access, SaaS controls, private applications, certificate handling, identity, device posture, logs and user experience before broad deployment.
Operate and refine
Review access policies, user experience, incident workflow, subscription usage and renewal dates. A SASE platform still requires ongoing policy ownership and operational governance.
Consistent security for internet and SaaS access
One of the strongest reasons to evaluate FortiSASE is the shift away from assuming that a user is protected simply because a company owns a good office firewall. Hybrid users may connect directly to cloud applications from home broadband, mobile networks, hotels or customer sites. When those connections bypass the headquarters edge, traditional perimeter controls may no longer see the traffic. FortiSASE is designed to move relevant inspection and access controls into a cloud-delivered service so policy can follow the user more consistently.
For internet access, the current platform includes secure web gateway and firewall-as-a-service capabilities with web and DNS filtering, antivirus, intrusion prevention and encrypted-traffic inspection options. For SaaS, FortiSASE includes inline CASB and data loss prevention functions and supports additional API-based controls depending on licensing. Buyers should not assume that enabling every inspection feature is automatically appropriate. SSL inspection, file controls, browser controls and data policies can affect user experience, privacy handling and application compatibility. A sensible rollout starts with policy objectives, identifies exceptions that are technically justified, tests business-critical sites and documents how the help desk should respond when a legitimate application is blocked.
The value comes from the combination of coverage and operational consistency, not from one isolated feature. If web filtering, SaaS control, endpoint posture and private application access all use coordinated identity and policy, security teams can reduce some of the gaps created by separate products. The final design still depends on the organisation’s identity system, endpoint strategy and application estate.
Zero-trust access to private applications
Many organisations begin a SASE project because they want a more controlled alternative to broad remote-access VPN connectivity. FortiSASE supports zero-trust network access for private applications, allowing administrators to design access around explicit applications, authenticated users and device context. The objective is not simply to replace one tunnel with another. A good ZTNA design changes the trust model so a user receives access to the approved application rather than unnecessary reach into the wider network.
The application path matters. Private resources may live behind FortiGate appliances in a data centre, behind Secure SD-WAN hubs, inside public cloud environments or in other network locations. Fortinet’s current ordering guidance notes licensing requirements for FortiGate Secure Private Access and provides branch on-ramp options for selected designs. Because this part of the deployment touches routing, authentication and application publishing, it should be planned with the network team and application owners rather than treated as an endpoint-only exercise.
Before deployment, document which applications are reachable, the protocol and port requirements, DNS behaviour, user groups, authentication method, device posture, certificate requirements and redundancy expectations. Also identify applications that cannot be easily published through an application-oriented model and may still require another remote-access method. FourTeck can help structure these questions during sizing and quotation so the subscription and connectivity components align with the intended architecture.
Branch, thin-edge and Secure SD-WAN integration
FortiSASE is not limited to laptops running an agent. Fortinet documents branch on-ramp, thin-edge and integration scenarios that extend cloud-delivered security to selected remote locations and devices. This can be useful for small offices, temporary sites, retail points, clinics, classrooms, warehouses or other environments where every device cannot run FortiClient. A branch can establish connectivity to FortiSASE through supported FortiGate or third-party IPsec devices, while selected FortiAP, FortiExtender and FortiBranchSASE platforms can be used in thin-edge designs.
The benefit is architectural flexibility, but the bill of materials becomes more specific. A buyer may need a branch on-ramp subscription, hardware management entitlement, user seats, a particular security location strategy and redundant tunnels. Fortinet’s current ordering guide states that user licenses are still required for thin-edge deployments and documents separate branch on-ramp limits and add-ons. Therefore, a simple user-count quote may not be sufficient for a multi-site project.
Organisations already using Fortinet Secure SD-WAN may have a clearer path to a unified design because FortiSASE and Secure SD-WAN are intended to work together. Even so, route design, hub placement, failure behaviour, application steering, identity and support ownership need to be agreed. A network diagram and site inventory are valuable inputs before requesting final pricing.
Where FortiSASE can fit in a business environment
Professional services and consulting
Consultants, auditors and project teams often work from client offices, home networks and public connectivity. FortiSASE can help maintain consistent internet and private-application controls across those changing locations.
Retail and distributed branches
Retail groups may combine roaming employees with many smaller sites. Branch on-ramp and thin-edge options can be evaluated where local devices require cloud-delivered inspection and central policy coordination.
Education and training
Staff and students may move between campus, home and cloud applications. A SASE design can help apply web and SaaS controls more consistently, provided device ownership and privacy requirements are carefully addressed.
Healthcare and regulated services
Distributed access to sensitive systems makes identity, device posture, logging and data handling important. FortiSASE can form part of the control architecture, but compliance outcomes depend on the organisation’s complete policies and implementation.
Logistics and field operations
Field teams, depots and mobile users often work beyond a fixed corporate edge. Cloud-delivered access security can help standardise policy while keeping private applications available to approved workers.
Enterprises consolidating security tools
Larger organisations may use SASE to reduce overlap between VPN, SWG, CASB and remote-access products. Migration should be phased because policy translation, identity mapping and application dependencies can be substantial.
Integration and operational considerations
A FortiSASE project should be evaluated as part of the wider network and security architecture. Identity is a first dependency because access policy is much more useful when users, groups and authentication context are reliable. Review the existing identity provider, MFA requirements, user lifecycle process and any on-premises directory dependencies. Endpoint management is the next major factor. Determine which devices can run FortiClient, which are unmanaged, how certificates will be distributed, how posture data will be collected and whether users require agentless access.
Network teams should map application paths and DNS resolution. Private access may require FortiGate hubs, SD-WAN integration or other service connections. If branches are included, document circuit capacity, existing CPE, IP addressing, routing protocols, tunnel redundancy and whether local breakout is required. Security teams should define inspection policies, data-loss rules, SaaS governance, logging retention and incident-response integration. Help-desk teams should understand the user experience, especially certificate prompts, blocked pages, authentication failures and application exceptions.
Finally, procurement should track subscription ownership, user bands, add-ons, renewal dates and expected growth. A user-count increase, new region or new branch model can affect entitlements. Treating these operational questions as part of the initial design can reduce surprises after purchase.
Questions to resolve before requesting a FortiSASE quotation
FortiSASE licensing is user based. Current subscriptions permit up to three devices per user, so a clear user and endpoint inventory helps prevent incorrect seat calculations.
Standard, Advanced and Comprehensive differ in features, security locations and onboarding. Choose the tier from actual requirements rather than from name alone.
List data centres, cloud networks, FortiGate hubs and other application locations. This determines how secure private access should be connected.
Sites with unmanaged local devices may require additional branch design, hardware support and licensing beyond remote-user seats.
Identity choices affect user authentication, group mapping and zero-trust policy. Confirm this before migration planning.
Document redundancy, alternate access, branch tunnel resilience and application criticality. The design should match operational continuity needs.
Procurement checklist before ordering
✓ Confirm the required FortiSASE subscription tier.
✓ Confirm the licensed user count and expected growth.
✓ Record the number and type of devices per user.
✓ Decide the subscription term and renewal planning approach.
✓ Identify required Security PoP locations and regional constraints.
✓ Confirm whether public-cloud PoP options are required.
✓ List private applications and where they are hosted.
✓ Confirm FortiGate SPA or Secure SD-WAN dependencies.
✓ Identify branch on-ramp, FortiAP or thin-edge requirements.
✓ Review identity provider, MFA and endpoint posture needs.
✓ Define installation, configuration and migration scope.
✓ Confirm logging, reporting and SOC integration expectations.
✓ Check onboarding or professional-service requirements.
✓ Ask FourTeck to validate the current bill of materials before purchase.
How FourTeck can assist with FortiSASE planning
FourTeck can help convert a broad SASE requirement into a quotation request that is easier for technical and procurement teams to validate. The starting point is a requirement review: how many users are in scope, which devices they use, whether access is mainly internet, SaaS, private applications or a combination, and whether the business already operates FortiGate, Secure SD-WAN or other Fortinet platforms. From there, FourTeck can assist with subscription-tier discussion, user-band selection, private-access dependencies, branch or thin-edge requirements, onboarding scope and renewal planning.
Where a deployment includes application migration or replacement of a legacy VPN or proxy service, the scope should be separated into discovery, pilot, production rollout and operational handover. FourTeck can discuss installation and configuration services where required, but the exact deliverables depend on the customer environment and should be written into the quotation. For broader project support, review FourTeck’s network and security services or browse related enterprise security products.
UAE availability and support guidance
FortiSASE is a subscription-based cloud service, so “availability” is different from a normal hardware stock question. A buyer needs the correct subscription SKU, term, user band, feature tier and any add-ons or implementation services. Fortinet currently lists Dubai as part of its FortiSASE security infrastructure, but tenant location entitlement and service selection must still be matched to the purchased subscription and activation choices. Contact FourTeck to confirm current UAE licensing options, quotation validity, vendor lead time and the correct structure for new subscriptions or renewals.
If the project includes FortiGate hubs, Secure SD-WAN, FortiAP, FortiExtender, FortiBranchSASE or other hardware, physical product availability may have a separate lead time from the cloud subscription. Installation and configuration should also be scoped separately when required. FourTeck can coordinate these discussions for organisations in Dubai and the wider UAE after the exact design is confirmed.
Dubai, Abu Dhabi, Sharjah and Ajman project coordination
Organisations operating across Dubai, Abu Dhabi, Sharjah and Ajman often have a mix of headquarters users, branch employees, roaming staff and cloud-hosted applications. FortiSASE can be evaluated as a shared policy and access platform across those user groups rather than designing separate remote-access controls for each office. FourTeck can help customers collect requirements across locations, compare user counts, identify branch on-ramp needs, check private-application connectivity and prepare a consolidated quotation request. Service scope, onsite activity, configuration responsibility and project timing should be confirmed in writing because each deployment has different dependencies. For broader Fortinet planning, buyers can also review FourTeck’s Fortinet firewall and security guidance.
GCC Availability
FourTeck can assist organisations evaluating FortiSASE for projects across the GCC, including requirements that involve the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman. Regional planning should begin with the destination country, user count, FortiSASE subscription tier, term, required security locations, private-application design and any branch connectivity. Licensing and service-location choices can vary, and physical components such as FortiGate, FortiAP or FortiExtender may follow different fulfilment timelines from the cloud subscription. Installation visits, configuration work and migration support also depend on the project scope and local conditions. For multi-country deployments, it is useful to agree one architecture and naming standard while still validating country-specific constraints. FourTeck can help coordinate requirement review, quotation structure, license selection, deployment planning and renewal discussion. Buyers should share the target countries, expected user population, preferred rollout window and any support expectations so current options can be confirmed before ordering. Customers with a Kuwait requirement can also review FourTeck’s Kuwait technology support site.
Africa Availability
FortiSASE can also be evaluated for organisations with users or projects in Africa, but regional procurement should be planned carefully. FourTeck can assist businesses reviewing user licenses, subscription tiers, accessories, FortiGate integration, branch connectivity, configuration scope, support expectations and renewals for distributed African operations. Availability and fulfilment may depend on the destination, license region, user count, product model, power or regulatory requirements for any physical edge devices, shipping arrangements and vendor lead times. A cloud subscription may be activated differently from hardware that is needed at a branch or data centre. Organisations with operations in East Africa, West Africa, Southern Africa or Central Africa should provide the destination country, exact requirement, quantity, expected deployment schedule and whether remote or onsite assistance is needed. FourTeck can then discuss an appropriate procurement path without assuming local inventory or a fixed project date. For regional enquiries, see the FourTeck Africa technology portal.
Related Fortinet options and services to consider
Fortinet Secure SD-WAN
Relevant when branch networking and application steering need to converge with FortiSASE. Exact FortiGate hardware and service bundles should be sized separately.
FortiGate NGFW
Can serve branch, data-centre and private-access roles in a wider SASE design. The correct model depends on throughput, interfaces, inspection and high-availability needs.
FortiClient
Used as the endpoint agent for supported FortiSASE scenarios and can provide security, posture and access capabilities according to the subscription.
FortiManager and FortiAnalyzer
May be relevant where teams want coordinated management, policy synchronisation, logging or analytics across a broader Fortinet environment. Licensing should be confirmed separately.
FortiAP / FortiBranchSASE
Suitable to review for thin-edge locations that need cloud-managed connectivity and security without a traditional full firewall at every site.
Deployment and migration services
Useful where the project includes legacy VPN replacement, proxy migration, identity integration, policy conversion or staged rollout. Scope should be defined before quotation.
Why businesses contact FourTeck for FortiSASE projects
A FortiSASE purchase can involve more than selecting a cloud subscription. Businesses often need help understanding whether the project is primarily secure internet access, private application access, SaaS governance, branch protection or a complete SASE architecture. That distinction changes the questions that should be asked and the SKUs that may be required. FourTeck can support requirement clarification, user-band selection, subscription-tier comparison, bill-of-material review, FortiGate and SD-WAN dependency checks, branch connectivity discussion, installation planning, configuration scope and renewal guidance.
This practical procurement approach is useful for IT teams that already understand the desired technical outcome but need help translating it into a commercial request, and for procurement teams that need to understand why two FortiSASE quotations may contain different subscriptions or add-ons. FourTeck does not need to treat every project as identical. A 60-user remote workforce, a 600-user enterprise with multiple cloud applications and a multi-country branch rollout can require very different designs. For UAE enquiries, use the FourTeck business contact page to share the requirement.
What buyers are trying to understand before choosing FortiSASE
Most FortiSASE research starts with a simple question: is this mainly a remote-access replacement, a web-security service, or a complete SASE platform? The practical answer is that FortiSASE is the cloud-delivered security service edge component in Fortinet’s unified SASE approach, and it can cover several access patterns at the same time. A company may use it to protect general internet browsing, inspect SaaS access, publish private applications through zero-trust controls and connect selected branch traffic to cloud security. The right design depends on which of those problems the organisation actually needs to solve.
Is FortiSASE the same as a traditional VPN?
No. A traditional VPN usually creates network connectivity between a user device and a corporate environment. FortiSASE can support secure private access, but it also adds web security, firewall controls, SaaS policy, data-protection functions and other cloud-delivered services. A buyer replacing VPN should therefore map each private application and decide whether application-level ZTNA is suitable, rather than assuming the existing network tunnel design should simply be copied into the new platform.
Which FortiSASE tier should a company buy?
The correct tier is driven by feature and location requirements. Current Fortinet ordering information lists Standard, Advanced and Comprehensive subscriptions. Core secure internet, SaaS and private-access functions appear across the tiers, while capabilities such as Secure Browser, agentless ZTNA, digital experience monitoring, assisted onboarding and location choices vary. The safest approach is to create a requirement checklist first, then map each requirement to the current ordering guide before choosing the subscription.
How is FortiSASE priced?
FortiSASE is licensed through user-based subscriptions with different user bands, tiers and terms. Public online prices can be useful for rough market context, but they are not a reliable UAE selling price because the final cost depends on user count, tier, subscription duration, add-ons, region and any deployment services. Buyers should ask for a quotation using the exact user band and architecture. A branch on-ramp, additional security locations, dedicated IP requirements or FortiGate private-access components can change the final commercial structure.
Does every user need FortiClient?
Not necessarily. FortiSASE supports agent-based access and selected agentless methods, and Fortinet also documents branch and thin-edge designs for locations where endpoint agents are impractical. However, agentless access does not mean every capability is identical. Device posture, digital experience monitoring and certain endpoint controls may depend on the agent. Organisations with contractor devices, Chromebooks, shared terminals or unmanaged systems should test those specific use cases before deciding on the subscription and rollout method.
Another common buyer question is whether an existing Fortinet environment makes adoption easier. Organisations already running FortiGate and Secure SD-WAN can benefit from native integration options, but that does not remove the need for design work. Private application traffic must still be routed correctly, hubs must be licensed where required, security locations need to be selected, and the user identity design must be coherent. Existing policy objects and operations workflows should be reviewed rather than assumed to transfer automatically.
Security location choice is also important, particularly for businesses with users concentrated in the UAE or distributed across several countries. Fortinet operates a global FortiSASE infrastructure and currently lists Dubai locations. The subscription tier influences which location types are available, and some user bands can have location limitations. Buyers should therefore confirm where users will enter the service, where important applications are hosted and whether public-cloud or additional location options are required. Latency-sensitive applications deserve pilot testing from the real user networks that will be used in production.
For security teams, the operational question is often more important than the feature list: who will own policy, exceptions, logs and incident response after deployment? FortiSASE can reduce the need to manage separate VPN, SWG and SaaS-security tools, but centralisation only helps if roles are clearly assigned. Define who approves web exceptions, who manages identity groups, who troubleshoots private-application access, how alerts reach the SOC and how subscription consumption is monitored. Include those operational decisions in the project plan, not only in the technical design.
A useful quotation request therefore contains more than “FortiSASE for 100 users.” It should state the user count, device types, subscription term, expected security tier, primary user locations, private application locations, FortiGate or SD-WAN environment, identity provider, SaaS applications of concern, branch or thin-edge requirement, onboarding needs and desired rollout period. With that information, FourTeck can help the buyer compare the bill of materials against the intended outcome rather than quoting an arbitrary license line.
Decision questions that shape a FortiSASE design
Should we start with secure web access or private application access?
Start with the problem that creates the clearest measurable gap. If remote users are bypassing corporate web controls, secure internet access may be the simplest first phase. If legacy VPN gives users broader access than necessary, ZTNA for selected private applications may be the stronger starting point. Many organisations eventually use both, but a phased project is easier to test and support. The subscription should still be selected with the longer-term architecture in mind so the first phase does not create an avoidable licensing change later.
How many devices can one licensed user register?
The current Fortinet ordering guide states that each user can use up to three devices. A fourth registered device can consume an additional license. This matters for executives, engineers and field staff who may use a laptop, phone and tablet. During sizing, count named users and then identify users who regularly need more than three registered devices. Also consider shared devices and service accounts separately rather than forcing them into a standard employee model.
Can FortiSASE work with our existing FortiGate environment?
Yes, FortiSASE is designed to integrate with FortiGate and Fortinet Secure SD-WAN in supported architectures. The exact design depends on whether the FortiGate acts as a private-access hub, branch edge or part of a broader SD-WAN topology. Current ordering guidance includes specific SPA service-bundle requirements. Before buying, confirm the FortiGate models, firmware, HA arrangement, hub locations and whether each private application path has redundancy.
What if we have unmanaged devices or contractors?
FortiSASE supports agentless scenarios, but the design must be matched to the required control. A contractor who only needs one browser-based private application may have a different access method from a managed employee who requires full internet inspection, posture checking and digital experience monitoring. Identify unmanaged-device use cases separately, decide what data they may access and confirm which functions are available in the selected tier and access method.
Do we need dedicated public IP addresses?
Some SaaS services, partner systems or allowlists depend on predictable source IP addresses. FortiSASE subscriptions and add-ons provide dedicated egress IP options, but quantities and minimum-user requirements vary. Before ordering, list every external service that uses IP allowlisting, identify which users need that path and confirm the required region. This is more reliable than discovering after rollout that an important partner only accepts traffic from pre-registered addresses.
What should we prepare for a pilot?
Choose users from different locations and job functions, include at least one critical SaaS application and one private application, and test the real identity and endpoint process. Define success measures for login reliability, application reachability, web policy, user experience, logging and help-desk handling. A pilot should expose operational dependencies, not merely prove that a tunnel can connect. Record every exception so production policy remains controlled.
Frequently asked questions about FortiSASE
What is FortiSASE used for?
FortiSASE is used to deliver cloud-based security and access controls for users reaching the internet, SaaS services and private applications. It is commonly considered for hybrid workforce security, zero-trust private access, web protection, SaaS control and integration with Fortinet Secure SD-WAN.
What FortiSASE subscription tiers are available?
Current Fortinet ordering documentation lists Standard, Advanced and Comprehensive remote-user subscriptions. Feature entitlements, onboarding and security-location options differ, so buyers should compare the current ordering guide against their exact requirement before purchase.
How many users are required for FortiSASE?
The current user-band ordering table begins at 50 users for standard remote-user subscriptions, while selected SD-WAN starter-kit options can include smaller seat counts. The right SKU depends on the deployment and should be confirmed at quotation time.
Can FortiSASE replace a remote-access VPN?
It can support secure private application access through ZTNA and related connectivity options, which may replace or reduce traditional VPN use in suitable applications. Some legacy protocols or broad network-access requirements may still need another approach, so application testing is essential.
Does FortiSASE support SaaS security?
Yes. Current FortiSASE capabilities include inline CASB and data-loss-prevention controls, with API-based CASB and DLP options dependent on licensing. The SaaS applications and policy depth required should be confirmed before choosing the tier.
Can FortiSASE integrate with FortiGate and Secure SD-WAN?
Yes. Fortinet documents FortiGate private access, Secure SD-WAN integration and branch on-ramp designs. Specific service bundles, hub licensing and supported device requirements apply, so the existing network should be reviewed before ordering.
Is FortiSASE available for users in Dubai?
Fortinet currently lists Dubai security locations in its FortiSASE infrastructure. Actual tenant location choice depends on subscription and activation rules. Contact FourTeck to confirm current UAE licensing and the location options available for the proposed user band.
Does FortiSASE work without an endpoint agent?
Selected agentless access methods are supported, and Fortinet also offers branch and thin-edge options. Feature coverage can differ from agent-based access, particularly for posture, endpoint security and experience monitoring, so unmanaged-device requirements should be tested explicitly.
What information does FourTeck need for an accurate quote?
Share the user count, device mix, subscription term, required tier, key user locations, private-application locations, identity provider, FortiGate or SD-WAN environment, branch requirements, onboarding scope and expected project timing.
Plan the subscription around your real users and applications
Share your user count, required security tier, private application design, FortiGate or SD-WAN environment and deployment locations. FourTeck can help structure a current UAE quotation and identify the licensing or implementation questions that should be resolved before purchase.
