What you are evaluating
FortiNDR on-premises and FortiNDR Cloud have different architectures and capabilities. Compare the quoted deployment, retention and analysis functions directly; FortiGate, FortiEDR, FortiSOAR and other response products are not implied entitlements.
A useful evaluation context
Teams comparing NDR deployment models or extending a Fortinet-oriented response workflow.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Network analysis and detection provide observations for investigation.
- On-premises sensor and management options support local collection designs.
- Integrations with separate Security Fabric products enable response handoffs.
Where it fits in the work
- Choose the documented collection and management architecture for the pilot.
- Investigate a benign lab anomaly using the available network context.
- Trace a proposed response through the integration’s permissions and the enforcement product’s audit record.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Tabletop an NDR alert that results in a proposed firewall block. Show the approval, API handoff and rule-removal procedure without sending a disruptive command to a production device.
Evidence to look for
Produce a responsibility map and expected audit trail. Identify how the team would detect an integration failure or an over-broad rule.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which features and retention terms belong to the selected Cloud or on-premises offering?
- Which response path remains usable if the management link is interrupted?
- What separate license and privileges does each integration require?