# FortiEDR

> Endpoint detection and response integrated with the Fortinet Security Fabric, quote-only pricing.

FortiEDR is an endpoint detection and response platform from Fortinet for Windows, macOS, Linux and mobile endpoints, delivering automated threat remediation with integration into the Fortinet Security Fabric and third-party tools. Pricing is not published; contact Fortinet for per-endpoint pricing. Listing updated 6 September 2026. Checked by MSP Software 6 September 2026.

- Page: https://mspsoftware.net/software/fortiedr
- Vendor: Fortinet, https://mspsoftware.net/vendors/fortinet, website https://www.fortinet.com/products/endpoint-security/fortiedr
- Categories: EDR and XDR (primary)
- Free version: no.
- Deployment: cloud, on-premises and hybrid. Platforms: Windows, macOS, Linux, Android and iOS. HQ: United States. Founded: 2000.
- Support: email, phone, 24/7 and help desk. Training: documentation, webinars and live online.

## From the vendor

FortiEDR is an endpoint detection and response platform from Fortinet for protecting Windows, macOS, Linux and mobile endpoints against evolving threats and attacks. The platform identifies and stops endpoint breaches in real time using automated incident response, behavioral detection and advanced threat intelligence mapped to the MITRE ATT & CK framework. It delivers customizable incident response playbooks with capabilities including ransomware prevention, data exfiltration blocking, and automated remediation through device isolation, password resets, IP blocking and file deletion. The agent is lightweight, supports legacy systems (Windows XP and Server 2003) through current operating systems, and runs across multiple Linux distributions, macOS versions and VDI environments without excessive system resource consumption or performance impact whatsoever. FortiEDR offers attack surface reduction through device and application discovery capabilities and includes a threat hunting console for detailed investigation and forensics work. Rollback features restore endpoints to their pre-attack state, undoing malicious system changes completely. The platform integrates with the Fortinet Security Fabric to share threat intelligence across firewalls, email security, identity and other Fortinet products, and also connects to third-party SIEM platforms, FortiSIEM, and cloud security services including Google Cloud Security Command Center and Amazon GuardDuty. Fortinet offers the FortiGuard Managed Detection and Response service as an add-on with 24-hour human-staffed SOC coverage, managed threat response and dedicated incident response capabilities. Deployment is flexible: cloud-native, on-premises or hybrid configurations through a multi-tenant console. Professional services and support are available for deployment and ongoing operations. The vendor publishes no list price; MSPs should contact Fortinet sales for per-endpoint pricing details and to discuss trial options. Fortinet is based in the United States and was founded in 2000.

## Our take

FortiEDR suits MSPs with existing Fortinet infrastructure who want integration with the Fortinet Security Fabric, or those seeking a standalone EDR with access to managed detection and response services if needed. The platform stands out for comprehensive operating system support including legacy Windows versions, multiple Linux distributions, and macOS. Pricing is quote-only with no published list rate, so compare the per-endpoint cost against published pricing from CrowdStrike Falcon, SentinelOne or Microsoft Defender for Endpoint. Before committing, confirm macOS and Linux support for all your client endpoints, verify integrations with your existing SIEM and cloud services, and discuss trial availability and deployment assistance with Fortinet sales.

## Pricing

FortiEDR does not publish a list price.

## Features

| Feature | Supported | Note |
| --- | --- | --- |
| Behavioural detection | yes | Detects behavioural threats including in-memory attacks and advanced malware |
| Automated remediation | yes | Customizable incident response playbooks with automated actions including isolation, password reset, and file deletion |
| Rollback to pre-attack state | yes | Can rollback malicious changes made during security incidents |
| USB and device control | yes | Discovers and controls rogue devices, IoT devices, and their vulnerabilities |
| Application allow-listing | yes | Application discovery and control capabilities for attack surface reduction |
| Threat hunting console | yes | Threat hunting console with rich telemetry for investigation and forensics |
| Managed MDR add-on | yes | FortiGuard Managed Detection and Response Service available as add-on with 24-hour SOC |
| SIEM and SOAR integration | yes | Integrates with FortiSIEM and third-party SIEM and SOAR platforms |
| macOS support | yes | Full support for macOS El Capitan through Sequoia |
| Linux support | yes | Support for RedHat, CentOS, Ubuntu, Oracle, and Amazon Linux |

## Integrations

- FortiSIEM, https://www.fortinet.com/products/security-operations/fortisiem
- Fortinet Security Fabric, https://www.fortinet.com/products/security-services/security-fabric
- Google Cloud Security Command Center, https://cloud.google.com/security-command-center
- Amazon GuardDuty, https://aws.amazon.com/guardduty/
- Active Directory, https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started-with-active-directory-domain-services
- FortiClient EMS, https://www.fortinet.com/products/endpoint-security/forticlient-ems

## Alternatives

- Cortex XDR: Cross-domain XDR for endpoint investigation and response with 24/7 managed detection services. https://mspsoftware.net/software/cortex-xdr
- SentinelOne: Autonomous endpoint detection and response with one-click rollback, per-endpoint annual pricing. https://mspsoftware.net/software/sentinelone. Compare: https://mspsoftware.net/compare/fortiedr-vs-sentinelone
- Trend Vision One Endpoint Security: Endpoint protection with EDR, XDR and threat hunting under credit-based licensing. https://mspsoftware.net/software/trend-vision-one
- CrowdStrike Falcon: Cloud-native EDR with behavioral detection, threat hunting and managed response via OverWatch. https://mspsoftware.net/software/crowdstrike-falcon. Compare: https://mspsoftware.net/compare/crowdstrike-falcon-vs-fortiedr

## FAQ

### How much does FortiEDR cost?

FortiEDR does not publish a list price. No MSP price reports have been approved yet.

### Does FortiEDR offer a free trial?

There is no free version.

### What does FortiEDR integrate with?

FortiEDR lists integrations with FortiSIEM, Fortinet Security Fabric, Google Cloud Security Command Center, Amazon GuardDuty, Active Directory and FortiClient EMS.

### Is FortiEDR cloud or on-premises?

FortiEDR can be run in the cloud or on-premises. FortiEDR supports a hybrid deployment.

### Who is FortiEDR for?

MSPs report using FortiEDR at sizes of 51-200 and 200+ technicians.

### What does FortiEDR cost per endpoint?

FortiEDR pricing is not published on Fortinet's website. MSPs must contact Fortinet sales for a quote. Unlike competitors such as CrowdStrike Falcon or SentinelOne that publish per-endpoint pricing, Fortinet's quote-only pricing means costs vary based on deployment size, configuration, support tier and MDR add-on choices.

### Does FortiEDR integrate with my existing RMM or documentation tools?

FortiEDR integrates with the Fortinet Security Fabric, third-party SIEM and SOAR platforms, and cloud security services including Google Cloud and AWS. Fortinet's public documentation does not list explicit integrations with PSA, RMM, or documentation platforms such as NinjaOne, Datto RMM or IT Glue. Contact Fortinet to confirm integration availability with your specific tools.

### Can FortiEDR protect macOS and Linux endpoints?

Yes, FortiEDR provides full protection across Windows, macOS (El Capitan through Sequoia), and Linux (RedHat, CentOS, Ubuntu, Oracle, Amazon Linux), as well as mobile platforms including Android and iOS. The platform also supports legacy systems such as Windows XP and Server 2003.

### Does FortiEDR offer a managed detection and response service?

Yes, Fortinet offers the FortiGuard Managed Detection and Response Service as an add-on to FortiEDR. This includes 24-hour human-staffed SOC coverage, threat investigation, managed threat response and dedicated incident response capabilities for customers requiring extended security support and monitoring services.

### How does FortiEDR respond to threats automatically?

FortiEDR uses customizable incident response playbooks mapped to the MITRE ATT & CK framework to automate threat response. The platform can execute actions including device isolation, IP address blocking, password resets, and file deletion without manual intervention, reducing mean time to response.