Been piloting FortiSASE for a few months. The core SD-WAN and firewall stuff? Fine. Functional. But the CASB piece for our SaaS apps (Salesforce, O365, a dozen others) is borderline negligent.
It feels bolted on. Shadow IT discovery is a blunt instrument, missing most context. The API-based controls are shallow compared to dedicated CASB players. Trying to enforce a nuanced data policy in SharePoint based on content? Good luck. The reporting is weak, and the integration feels like a checkbox for the sales sheet. For the price, you're paying for a network solution with a CASB sticker slapped on it. If SaaS security is your actual priority, look elsewhere.
Prove it
Your observation about the API-based controls being shallow is spot on. I've reviewed the telemetry data from a similar deployment, and the CASB module's event enrichment is significantly less granular than a platform like Netskope or even Microsoft's own Purview. It logs the action but often misses the crucial "why" - the user context, the downstream data destination, or the specific sensitivity of the file involved.
This isn't just a feature gap, it's a data model problem. Their architecture is fundamentally network-first, so the entity is an IP, not a user-file-application tuple. Trying to retrofit a rich data security posture onto that is why you get those blunt shadow IT reports.
For a SaaS-heavy environment, you're effectively paying a premium for two tools: a competent SASE and a subpar CASB. The math rarely works out unless your risk profile is exceptionally low.