Skip to main content
Question

Deploying FortiClient (VPN only)

  • September 9, 2025
  • 7 replies
  • 830 views

Forum|alt.badge.img+3

Hello everyone 

We are trying to deploy FortiClient VPN only from this link https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/76cde386-1f8c-11ef-8c42-fa163e15d75b/FortiClient_7.4_Jamf_Deployment_Guide.pdf

the Application installed perfectly but we have issue with configuration of the app
1- To grant FortiTray permissions to load and grant network access.
2- To grant full disk access to load the following FortiClient processes

I have made the same as what they mentioned in the pdf but the user get popup to allow them.

what I want is:
1- These configuration only install if they install FortiClient.
2- Not popup any thing to the user when install FortiClient to allow for permission
3- If someone can please shared with me the configuration.

7 replies

agungsujiwo
Forum|alt.badge.img+10
  • Valued Contributor
  • September 9, 2025

Hello everyone 

We are trying to deploy FortiClient VPN only from this link https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/76cde386-1f8c-11ef-8c42-fa163e15d75b/FortiClient_7.4_Jamf_Deployment_Guide.pdf

the Application installed perfectly but we have issue with configuration of the app
1- To grant FortiTray permissions to load and grant network access.
2- To grant full disk access to load the following FortiClient processes

I have made the same as what they mentioned in the pdf but the user get popup to allow them.

what I want is:
1- These configuration only install if they install FortiClient.
2- Not popup any thing to the user when install FortiClient to allow for permission
3- If someone can please shared with me the configuration.

Hi ​@ShZaidan ,

It seems you may have missed this part: FortiClient_Configuration_Profile.JAMF.mobileconfig. To prevent pop-up messages, the configuration profile FortiClient_Configuration_Profile.JAMF.mobileconfig must be edited according to the steps provided and deployed to the scoped Mac users before installing the app. Important: If the configuration profile fails to install or has not completed installation, do not install the app. Doing so will result in persistent pop-up messages.


scottb
Forum|alt.badge.img+18
  • Valued Contributor
  • January 28, 2026

Hello everyone 

We are trying to deploy FortiClient VPN only from this link https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/76cde386-1f8c-11ef-8c42-fa163e15d75b/FortiClient_7.4_Jamf_Deployment_Guide.pdf

the Application installed perfectly but we have issue with configuration of the app
1- To grant FortiTray permissions to load and grant network access.
2- To grant full disk access to load the following FortiClient processes

I have made the same as what they mentioned in the pdf but the user get popup to allow them.

what I want is:
1- These configuration only install if they install FortiClient.
2- Not popup any thing to the user when install FortiClient to allow for permission
3- If someone can please shared with me the configuration.

Hi ​@ShZaidan ,

It seems you may have missed this part: FortiClient_Configuration_Profile.JAMF.mobileconfig. To prevent pop-up messages, the configuration profile FortiClient_Configuration_Profile.JAMF.mobileconfig must be edited according to the steps provided and deployed to the scoped Mac users before installing the app. Important: If the configuration profile fails to install or has not completed installation, do not install the app. Doing so will result in persistent pop-up messages.

Hi ​@ShZaidan - I have tried in vein to get this profile to deploy in Jamf.

I got it from the admin and uploaded it to Jamf Pro.
Scoped my test Mac and it fails 100% of the time.

Any ideas on how to remedy this.  Tried a few times repeating and no luck.

Thank you 

Scott


Jordy-Thery
Forum|alt.badge.img+17
  • Valued Contributor
  • January 29, 2026

That guide is specifically for EMS as far as I can see. 

Take a look here for an offline installer + config: https://github.com/pro4tlzz/ITSupportTools/blob/main/jamf/forticlient/install-configure/installing-forticlient-vpn-with-configuration-settings.md

As for the configuration profile (no pop-ups) there’s a couple downloads on the MacAdmins Slack. Take a look here: https://macadmins.slack.com/archives/C01UJR7LQBS/p1654805958972759?thread_ts=1654153797.524029&channel=C01UJR7LQBS&message_ts=1654805958.972759


scottb
Forum|alt.badge.img+18
  • Valued Contributor
  • January 29, 2026

Thank you ​@Jordy-Thery - this is a lesson in severe frustration.

I have to face a group deploying this and try to explain why I can’t seem to figure it all out.

This is absolutely the worst product I’ve ever had to build/support on the Macs/Jamf.

I will take a look at “mpermann’s” suggestions there…

Thus far, any profile I upload won’t install.
Looks like I have to build one from scratch as I have no signing cert at the moment…

Again, thanks!


Jordy-Thery
Forum|alt.badge.img+17
  • Valued Contributor
  • January 30, 2026

Thank you ​@Jordy-Thery - this is a lesson in severe frustration.

I have to face a group deploying this and try to explain why I can’t seem to figure it all out.

This is absolutely the worst product I’ve ever had to build/support on the Macs/Jamf.

I will take a look at “mpermann’s” suggestions there…

Thus far, any profile I upload won’t install.
Looks like I have to build one from scratch as I have no signing cert at the moment…

Again, thanks!

Yup. Forticlient is no fun at all. 🙈


dstranathan
Forum|alt.badge.img+19
  • Valued Contributor
  • August 31, 2026

I’m late to the party here. New Fortinet customer.  As of August 2026 (macOS 26 Tahoe 26.6.2) one trick I recently learned from another post for suppressing the macOS "FortiTray Would Like to Add VPN Configurations”. Setup the VPN MDM profile payload like this:

Connection Type: Custom SSL
Server: localhost
VPN Identifier: com.fortinet.forticlient.macos.vpn
Bundle Identifier: com.fortinet.forticlient.macos.vpn.nwextension (NOT com.fortinet.forticlient.macos.vpn)
Requirement: Identifier "com.fortinet.forticlient.macos.vpn.nwextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = AH4XFXJ7DK
Idle Timer: Do not disconnect

The profile MUST be deployed BEFORE FortiClient is isntalled.

This suppresses macOS VPN prompts for me. 👍🏻
 


Thanks @Gchaisty91


avagrace
Forum|alt.badge.img+1
  • New Contributor
  • September 2, 2026

The key with FortiClient on macOS is deployment timing: the configuration profile containing the PPPC (Full Disk Access) and System Extension / Content Filter payloads must be installed and verified on the Mac before the application package runs. If the app lands first, macOS immediately prompts the user before the profile can whitelist it.

Also, if an uploaded custom profile fails to push, check if your MDM is complaining about unsigned payloads or missing Team IDs. Signing the .mobileconfig locally or recreating the PPPC settings directly using Jamf's native profile builder usually bypasses the install failures