Blogs Page Banner
Ask Our Experts
Project Solutions & Tech.
Request Quotes: Live Chat | +852-63593631

Entra ID + Intune Firewall SSO: What Actually Consumes a FortiClient EMS License?

author
David Lorame
Reviewed by David Lorame
CCIE/HCIE Senior Engineer
author https://network-switch.com/pages/david-lorame

I am a Senior Network Solutions Architect at Network-Switch.com, holding dual CCIE#22989 and HCIE#33849 certifications. With over two decades of hands-on experience deeply rooted in data centers and enterprise environments, my focus is singular: building fast, secure, and infinitely scalable IT infrastructure.

Published: September 18, 2026 | Last Technically Reviewed: September 18, 2026

Enterprise editorial cover showing Entra ID, Intune, FortiClient EMS and FortiGate as separate layers to explain what actually consumes a FortiClient EMS license.

Quick Conclusion

FortiClient EMS licensing should not be sized from the number of users simultaneously online, the total number of Microsoft Entra accounts, or the number of devices enrolled in Intune. In FortiClient EMS 7.4.7, an EMS instance uses either per-endpoint licensing or per-user licensing, and Fortinet states that both license types cannot be used on the same EMS instance. Under the current per-user model, one licensed user can register up to three devices; a fourth registered device causes that user to consume a second license. Entra authentication, Intune management, FortiGate SAML authentication and FortiClient EMS management therefore need to be counted as separate identity and licensing layers.

A recent public r/fortinet discussion, “Authenticating InTune clients,” raised exactly this problem. The administrator was moving users away from traditional Active Directory domain-joined endpoints toward Microsoft Intune and Entra ID. Their FortiGate environment had historically relied on a domain-controller SSO agent, and the question was how to preserve a relatively seamless user-aware firewall experience once those endpoints stopped authenticating against the local domain controller.

Read the original Reddit discussion — Authenticating InTune clients

The same discussion then moved beyond authentication. One commenter suggested FortiClient EMS/Cloud as a relatively seamless endpoint-identity approach and referred to three complimentary licenses associated with qualifying FortiGate support. That community comment is useful because it explains why the licensing question arose, but it should not be treated as the final licensing rule. Current Fortinet documentation shows that the FortiClient Cloud Free Starter Pack and the FortiClient EMS trial are separate entitlements.

View the EMS / complimentary-license discussion on Reddit

This article therefore uses the community thread to identify the real questions, but uses current Fortinet and Microsoft documentation to establish the licensing rules.

Quick Answer: FortiClient EMS 7.4.7 supports per-endpoint and per-user licensing. The two models cannot be mixed on one EMS instance. Per-user licensing currently allows one user to register up to three devices; a fourth device makes that user consume a second license. This is not concurrent-user licensing. Before buying licenses, separate directory users, EMS-managed users, registered endpoints, Intune-managed devices and simultaneous firewall sessions.

Why Entra ID Changes the Identity Flow-but Not the Need for Firewall Identity

A traditional deployment might have looked like this:


Windows Active Directory
        
Domain Login
        
FSSO / User Mapping
        
FortiGate Policy


When endpoints move toward:


Microsoft Entra ID
        +
Intune-managed / Entra-joined endpoints


the old identity source may no longer exist in the same form.

That does not mean FortiGate suddenly loses the ability to authenticate users.

FortiOS 7.6.7 supports SAML authentication with Microsoft Entra ID as an identity provider. Fortinet lists practical FortiGate SAML use cases including firewall-policy authentication, Agentless VPN, IPsec VPN, ZTNA, explicit proxy and administrator access.

This creates the first important boundary:

Using Entra ID for FortiGate authentication does not automatically mean that FortiClient EMS is required.

FortiGate can perform supported SAML authentication directly against an IdP such as Microsoft Entra ID.

EMS becomes relevant when the requirement moves beyond authentication into endpoint-management functions such as:

  • FortiClient provisioning and policy;
  • endpoint telemetry;
  • endpoint security posture;
  • ZTNA tags;
  • centrally managed endpoint configuration;
  • compliance and endpoint-awareness workflows.

Fortinet's current FortiClient documentation explicitly separates these architectures. FortiClient can operate with EMS alone, or EMS can integrate with FortiGate so endpoint telemetry contributes awareness, compliance and enforcement to the Security Fabric.

So the design question should not begin with:

"Do we have Entra ID?"

It should begin with:

"What does the firewall actually need to know, and what endpoint functions do we want EMS to manage?"

Authentication and endpoint management overlap, but they are not the same workflow.

Entra ID, Intune, FortiClient EMS and FortiGate Do Different Jobs

Architecture diagram showing Entra ID for identity, Intune for device management, FortiClient EMS for user or endpoint registration, and FortiGate for authentication and access enforcement.

The simplest way to understand the architecture is to separate the objects:


Microsoft Entra ID
        
         Identity / users / groups
        
FortiClient EMS   Microsoft Intune
                           Endpoint management
                           Enrollment / MDM context
        
         FortiClient management
         Identity / telemetry / posture
        
FortiClient Endpoint
        
        
FortiGate
 Authentication
 Security policy
 VPN / ZTNA
 Network enforcement


Each product answers a different question.

Layer Main Question
Microsoft Entra ID Who is the user?
SAML authentication Has the user authenticated?
Microsoft Intune Which devices are enrolled or managed through Microsoft endpoint management?
FortiClient EMS Which FortiClient users/endpoints are registered and managed?
FortiClient telemetry Which endpoint and user context is being reported?
Device posture Does the endpoint satisfy the required security state?
FortiGate What access or security policy should be enforced?

FortiClient EMS 7.4.7 supports Microsoft Entra ID as an authentication server. Fortinet also documents importing an entire Entra domain or selected Entra groups into EMS endpoint management.

But this should not be simplified into:

Every Entra account synchronized into EMS immediately consumes one license.

That statement is too broad.

Fortinet's licensing documentation defines consumption around the selected registered endpoint or user model. In per-user environments, Fortinet also lets administrators exclude users from management, which releases the seat they were consuming.

The better model is:


Directory Object
      
Synced Entra Object
      
EMS-Managed User
      
Registered Endpoint
      
Concurrent Firewall Session


The objects are related, but they are not interchangeable licensing units.

There are also endpoint-platform differences. FortiClient EMS 7.4.7 states that Linux does not support EMS Entra ID integration. macOS does not support native Entra integration either; Fortinet documents specific Intune/Jamf and Company Portal requirements for that scenario.

That matters because even the phrase:

"We use Entra ID with EMS."

does not describe identical behavior across every operating system.

The phrase “three free licenses” came directly from the public discussion that triggered this article. A commenter recommended FortiClient EMS/Cloud and referred to three licenses associated with qualifying FortiGate support.

See the original Reddit comment context

That shorthand turns out to cover more than one possible Fortinet entitlement, which is why it should not be copied directly into a procurement calculation.

What Actually Consumes a FortiClient EMS License?

Side-by-side infographic comparing per-endpoint licensing with per-user licensing, showing that one user can register up to three devices under one user license and a fourth device changes the count.

This is the core procurement question.

FortiClient EMS 7.4.7 supports two licensing bases:

Per-Endpoint Licensing

The relevant object is the endpoint.

If a deployment uses a per-endpoint license and 100 applicable endpoints are registered and managed by EMS, the count is driven by those endpoints.

It is not driven by how many users happen to be online at the same time.

Per-User Licensing

The relevant object is the managed user.

Current EMS 7.4.7 documentation states that one per-user license allows that user to register three devices.

If that same user registers a fourth device, the user consumes two licenses. Fortinet also states that per-endpoint and per-user licensing cannot be used together on one EMS instance.

Per-Endpoint vs Per-User

Question Per-Endpoint Per-User
Primary counting unit Registered endpoint Registered/managed user
One employee with 2 devices 2 endpoints 1 user license under current allowance
One employee with 3 devices 3 endpoints 1 user license
One employee with 4 devices 4 endpoints 2 user licenses
Concurrent sessions matter? No No
Mix both models on same EMS instance? No No

The purchasing rule is therefore:

Do not size EMS from concurrent firewall sessions.

Size it from the actual EMS licensing model.

A Version Boundary That Matters

This rule is version-sensitive.

Fortinet's older 7.0.6 documentation described user-based licensing as a FortiClient Cloud-only feature and explicitly stated that on-premise EMS did not support it.

The current 7.4.7 EMS Administration Guide now states that FortiClient EMS supports both per-endpoint and per-user licensing, and the earlier Cloud-only restriction is no longer present on the current licensing page.

What we should not claim is:

Fortinet officially removed the restriction in version X.

The exact transition release has not been established from the documentation used here.

What can be established is:

7.0.6 documented a Cloud-only limitation; 7.4.7 currently documents both models for FortiClient EMS.

That is why procurement should always be checked against the exact EMS release and commercial SKU being quoted.

"Three Free Licenses" Actually Describes Two Different Things

This is another area where community shorthand can cause purchasing errors.

FortiClient EMS 7.4.7 has a free trial license. Fortinet states that the trial can manage three Windows/macOS/Linux/iOS/Android endpoints and three Chromebooks, but also explicitly says that the trial should not be used for production and does not provide Fortinet technical support.

Separately, FortiClient Cloud has a three-seat Free Starter Pack. Current Fortinet documentation says eligible devices with qualifying FortiCare Premium or Elite contracts registered in FortiCloud can receive three complimentary FortiClient Cloud seats per device, subject to stated exclusions. Fortinet also says this complimentary offer can be changed or discontinued.

Those are not the same entitlement.

So instead of writing:

Fortinet gives you three free EMS production licenses.

write:

Identify whether you are looking at the EMS trial entitlement or the FortiClient Cloud complimentary-seat program before counting any "free" seats in a production design.

One User, Multiple Devices: How the License Count Changes

The current per-user model becomes easier to understand with actual device ownership.

User Registered Devices EMS 7.4.7 Per-User Effect
Alice 1 1 user license
Bob 2 1 user license
Carol 3 1 user license
Dave 4 2 user licenses

This table reflects current FortiClient EMS 7.4.7 behavior and should be rechecked when the deployment is quoted or renewed.

Now consider a company with:

50 employees

Each employee receives:

  • one laptop;
  • one corporate phone.

That creates 100 devices.

Under per-endpoint licensing, if all 100 devices are registered and managed by EMS, the planning basis is 100 managed endpoints.

Under per-user licensing, 50 users with two registered devices each fit within 50 current user-license units because each user remains below the current three-device allowance.

That means:

100 devices does not automatically mean 100 EMS licenses.

But the opposite shortcut is equally dangerous:

50 employees does not automatically mean 50 EMS licenses.

Consider a more realistic inventory:

  • 50 laptops;
  • 35 phones;
  • 10 tablets;
  • 10 shared workstations.

There are 105 devices, but that number alone is insufficient for a per-user quote.

Before sizing, ask:


Which endpoints actually need FortiClient?
        
Which EMS capabilities are required?
        
Per-user or per-endpoint?
        
How many devices belong to each user?
        
Does anyone exceed three registered devices?
        
How are shared endpoints registered?
        
Which retired users/devices remain in EMS?
        
Final licensing scope


This is the difference between inventory counting and license-object counting.

It also explains why Entra directory size is not enough.

If an organization has 300 Entra accounts but only a defined subset will register FortiClient and be managed in EMS, simply quoting 300 seats from the directory count may be the wrong procurement model.

Conversely, a small user population with many registered devices can exceed the expected per-user quantity.

The user-to-device relationship matters.

Shared PCs, Replacements and Departed Employees Change the Count

Licensing is not only a Day-1 spreadsheet exercise.

It is also an operational lifecycle.

Shared PCs

Shared workstations are one of the most important edge cases for per-user licensing.

Fortinet's 7.4.7 licensing documentation warns that when per-user licensing is used without user verification, and an endpoint connects through the EMS address or an invitation code, EMS can treat the locally logged-in user identity as the identity consuming a user license.

That means:

one physical shared PC should not automatically be modeled as one user license.

Before purchase, verify:

  • whether EMS user verification is enabled;
  • how users authenticate to EMS;
  • what identity appears when multiple employees use the same workstation;
  • whether the shared endpoint design actually fits the per-user model.

Fortinet's User Management feature supports Local, LDAP and SAML verification, and the current documentation explicitly says that User Management requires per-user licensing. Microsoft Entra ID can be used as the SAML identity provider.

Replacing a Laptop

A hardware refresh also affects license accounting.

Do not assume the previous endpoint automatically disappears simply because the employee receives a replacement.

A controlled workflow is:


Old Endpoint
     
Decommission
     
Remove / Deregister as appropriate
     
Register New Endpoint
     
Verify User / Endpoint Association
     
Confirm Current License Count


This matters most when a user is already near the three-device threshold.

A stale laptop plus a new replacement can temporarily make a three-device user appear to have four registered devices.

Employee Departure

User offboarding should include EMS.

Fortinet's Verified Users documentation explicitly provides an Exclude from Management function and says that excluding a user frees the license seat that user was consuming.

Therefore, a leaver process should not end with:

Disable the Entra account.

It should also review:

  • whether the user is still managed in EMS;
  • whether assigned endpoints remain registered;
  • whether those endpoints will be retired or reassigned;
  • whether the EMS seat has actually been released.

This is particularly relevant to annual or multi-year renewal planning.

A licensing database that contains departed users and retired devices can distort the next quote even if the original Day-1 count was correct.

Firewall SSO, Endpoint Compliance, VPN and Admin Login Are Different Workflows

A common architecture diagram might contain all of these terms:

Entra ID
Intune
FortiClient
EMS
FortiGate
SAML
VPN
ZTNA

That does not mean they all consume the same Fortinet license.

Authentication vs Management vs Licensing

Use Case What Is Being Authenticated or Managed? Does It Automatically Imply an EMS Seat?
FortiGate firewall SAML authentication User identity No
FortiGate administrator SAML login Administrator identity No
SAML-authenticated IPsec VPN Remote user/session Not simply because SAML is used
EMS-managed FortiClient User or endpoint registered to EMS Yes, under the selected EMS model
Endpoint posture / telemetry Managed FortiClient endpoint context EMS/FortiClient licensing is relevant
Intune enrollment Microsoft-managed device Separate Microsoft licensing
Entra objects synchronized into EMS Directory objects Do not count synchronization alone as an EMS seat

FortiOS 7.6.7 explicitly supports SAML for firewall authentication, Agentless VPN, IPsec VPN, ZTNA, explicit proxy and administrator authentication, with Microsoft Entra ID listed as a common IdP.

That means the presence of Entra ID in an authentication flow does not automatically imply FortiClient EMS consumption.

FortiClient EMS licensing becomes relevant when users or endpoints are actually registered and managed according to the EMS licensing model.

Microsoft Intune is another separate commercial domain. Microsoft's current documentation states that Intune users or devices require appropriate Microsoft licensing, with user- and device-based licensing rules of its own.

Therefore:

Microsoft Intune license FortiClient EMS license

and:

Entra authentication EMS endpoint management

Integration does not merge the licensing systems.

This is especially important during procurement because a project can legitimately require:

  • Microsoft identity licensing;
  • Intune licensing;
  • FortiClient EMS licensing;
  • FortiGate security subscriptions;

without those products sharing the same counting unit.

How to Size EMS Licensing Before You Buy

Decision-flow infographic showing how to size FortiClient EMS licenses by separating directory users, EMS-managed users, registered endpoints and concurrent sessions, while checking shared PCs and replacement devices.

The safest approach is to start with separate identity and device inventories.

Suppose a project has:

100 employees
180 corporate devices
20 shared PCs
BYOD users
contractors

Do not begin by ordering 100 or 180 EMS licenses.

Begin with the licensing architecture.

A practical sizing process should establish:

  1. which EMS license basis is being quoted-per-user or per-endpoint;
  2. which devices actually need FortiClient management;
  3. which security features require EMS-managed endpoints;
  4. how many registered devices belong to each managed user;
  5. which users may exceed the current three-device allowance;
  6. how shared workstations authenticate and register;
  7. which retired users or endpoints should be removed before sizing;
  8. whether Intune and Entra requirements are being counted separately;
  9. whether direct FortiGate SAML authentication can satisfy some identity requirements without EMS;
  10. which version, deployment type and commercial SKU the reseller quote actually covers.

The key relationship is:


Directory Users
      
EMS-Managed Users
      
Registered Endpoints
      
Concurrent Sessions


If those four numbers have not been separated, the licensing BOM is not ready.

For Network-Switch project reviews, this is where a pre-quote inventory is more useful than a simple user count. The same compatibility-first principle used in our engineering and BOM review process applies to licensing: establish the identity flow, device population, management scope and product dependencies before turning them into commercial line items. Network-Switch's current review service publicly covers architecture validation, compatibility review, management requirements and BOM checking before purchase.

The procurement question should therefore be:

"Which identities and endpoints will FortiClient EMS actually register and manage under the licensing model we are buying?"

Not:

"How many people are online?"

And not:

"How many Entra accounts exist?"

That distinction is what prevents a technically valid identity architecture from becoming an incorrectly sized licensing quote.

Frequently asked questions (FAQs)

Does every Entra ID user synchronized into FortiClient EMS consume an EMS license?

Do not assume that from synchronization alone. EMS can integrate with Entra ID and import domains or selected groups, while current EMS licensing is defined around the selected per-user or per-endpoint model. Fortinet also allows managed users to be excluded, which frees their license seat. Count the EMS-managed population rather than treating directory presence alone as the billing unit.

Is FortiClient EMS licensed by concurrent users?

No. FortiClient EMS 7.4.7 documents per-endpoint and per-user licensing. Simultaneous FortiGate sessions are not the EMS counting unit.

Can I use per-user licenses for employees and per-endpoint licenses for shared PCs on one EMS instance?

Not under the current 7.4.7 rule. Fortinet states that both licensing types cannot be used on the same FortiClient EMS instance. If shared-device requirements complicate the model, validate the exact architecture before purchase rather than assuming the two schemes can simply be mixed.

How many devices can one per-user EMS license cover?

Under FortiClient EMS 7.4.7, one per-user license allows a user to register up to three devices. Registering a fourth device causes that user to consume two licenses. This is version-sensitive and should be confirmed again against the current quote and documentation.

Are the three FortiClient Cloud complimentary seats the same as the EMS three-endpoint trial?

No. They are separate entitlements. EMS has a trial that can manage three applicable endpoints plus three Chromebooks and is not intended for production. FortiClient Cloud separately documents a three-seat complimentary Free Starter Pack for devices with qualifying FortiCare contracts.

Do I need FortiClient EMS simply to authenticate Microsoft Entra users on FortiGate?

Not necessarily. FortiGate supports SAML authentication with Microsoft Entra ID for several use cases without making EMS the authentication requirement. EMS becomes relevant when centrally managed FortiClient endpoints, telemetry, posture or related endpoint-management functions are part of the design.

Source and Evidence Boundary

The community source establishes that the problem is real: an administrator moving away from traditional domain-joined endpoints asked how to preserve user-aware FortiGate authentication in an Entra/Intune environment, and FortiClient EMS/Cloud was raised as an option. Reddit replies are not used as formal licensing policy.

The official vendor sources establish licensing behavior: FortiClient EMS 7.4.7 defines per-endpoint versus per-user licensing, the current three-device user allowance, the fourth-device behavior, Entra integration, User Management, trial limits and license-seat release. FortiOS establishes SAML use cases, FortiClient Cloud establishes the separate Free Starter Pack, and Microsoft establishes Intune's independent licensing domain.

The engineering analysis in this article-such as separating Directory Object, Managed User, Endpoint and Concurrent Session-is a decision framework used to prevent different identity objects from being counted as if they were the same commercial unit.

Official Technical Sources

Primary Community Source

Reddit - Authenticating InTune clients

FortiClient EMS 7.4.7

Windows, macOS, and Linux licenses - per-endpoint and per-user licensing

Licensing FortiClient EMS

User Management - verification methods and per-user requirement

Verified Users - excluding users to free seats

Adding an Entra ID server

Free trial license

FortiClient, FortiClient EMS, and FortiGate relationship

Historical Licensing Reference

FortiClient 7.0.6 - User-based licensing and historical Cloud-only restriction

FortiClient Cloud

FortiClient Cloud licensing - three-seat Free Starter Pack

FortiGate / FortiOS

FortiOS 7.6.7 - SAML and Microsoft Entra ID authentication use cases

Microsoft

Microsoft Intune - Assign licenses to users and devices

Make Inquiry Today