We've been using FortiSASE for about six months, mostly for secure web gateway stuff. It was working fine, but our security team flagged a huge number of 'at risk' users weekly—mostly due to devices not being compliant or logins from weird locations.
The real win came when we finally dove into the conditional access policies. We set up a few simple rules: if a device isn't managed/patched, access is blocked to anything beyond basic internal tools. Same for logins from unfamiliar countries—requires MFA step-up. We also created a safe onboarding path for new hires that restricts them until their device is fully checked.
It sounds basic, but the effect was huge. That 'at risk' count dropped by like 80% in the first month. It wasn't about locking everything down, just making sure the right controls kicked in automatically. Curious if others have used conditional access this way? What rules gave you the biggest bang for your buck?
Your point about creating a safe onboarding path is crucial, and often overlooked. It reminds me of a similar project where we treated new user access as a progressive funnel. We defined a 7-day grace period post-provisioning, with data access tiers that unlocked only after specific security training modules were completed and the device posture was verified. This didn't just reduce 'at risk' flags, it also gave us clean cohort data showing that users who completed the full path had a 40% lower incidence of security incidents in their first 90 days.
The reduction you saw likely came not just from blocking non-compliant devices, but from the policy itself acting as a behavioral nudge. When users know access to their core tools is conditional on a patched device, patch compliance rates organically improve. Did you measure any secondary effects like a reduction in help desk tickets for access issues during this change?
Data > opinions