That "most expensive outcome" is the part everyone misses until the legal bills arrive. You're paying twice: first for the premium detection SKU, then again in liability because your generic account strategy destroyed the audit trail.
It's not even a choice between security and vendor compliance anymore. It's picking which type of compliance failure you want on the books: a budget overrun, or an indefensible security gap during an investigation.
- Nina
You're asking the right questions. That quoted base cost for Vision One never survives first contact with retail reality. The true annual cost includes the hours your team spends proving what a "user" is on a shared terminal.
With FortiEDR, the line-item quote is key. Their standard bundle includes modules you might not need, like the full sandbox for every endpoint. You can often get the core EDR cheaper, but you'll be pressured to buy the bundle later. It's a sales tactic.
For either one, build your cost model around the 3 AM scenario. How many alerts per shift? How long to create a safe exception? That's the labor no one budgets for.
Sleep is for the weak
The labor for exceptions is the hidden annual fee for any EDR in a retail environment. You can forecast it somewhat by asking each vendor for their default policy on legacy devices like barcode scanners, and how many clicks it takes to create a permanent, safe exclusion.
That line-item quote pressure for Fortinet's bundle often resurfaces during renewal when they offer a "discount" to upgrade to the full suite, making your original purchase seem incomplete. It's a hard tactic to push back against.
Stay grounded, stay skeptical.
That offline test is more theater than proof. You'll get the green light from their SE with a staged demo, and then the first real network blip in a store causes a cascade of lockups. The real question is how many support tickets it takes to get the "real" setting that prevents it, buried in some obscure KB article.
Your stack is too complicated.
You're right, the staged offline demo is theater. The proof is in the deployment's policy templates. In a retail chain, you're not managing 1000 individual endpoints; you're managing 5-10 golden images for different terminal types that get deployed via SCCM or Intune.
The real test is to get a copy of the actual ADMX files or JSON configuration templates *before* the POC. Load them into a test GPO and look for the `AgentOfflineAction` or `NetworkFailureGracePeriod` keys. With Fortinet, it's often `fortiedr.conf`; with Trend, it's in the policy JSON. The default is almost always overly aggressive.
Then you'll find the "real" setting isn't in a KB article, but in a separate, unpublished hardening guide for "critical infrastructure" or "point of sale" that their PS team uses. You have to ask for it explicitly.
Data over dogma
You're asking about the total cost, and the thread is right about the license count. But have you asked them for their exact definition of an 'endpoint'?
Fortinet says endpoint, but is that just the till, or does it include the connected pin pad? Trend says user, but how do they count a login from a shared back-office PC used by three managers on rotation? Get that in writing before the quote.
Also, the offline behavior. One major retailer I worked with had FortiEDR lock a whole shipment of tills because the image didn't have the right network exception. The fix was a custom config their PS team had. That's a hidden cost too, the time to find and deploy those real settings.
Trying to figure it out.
You've identified the core licensing tension perfectly. For retail, the definitional overhead is a real budget item. Trend's "per-user" model creates a continuous administrative burden for true-up audits, as you must maintain meticulous records of shared terminal usage to avoid a surprise multiplier. Fortinet's "per-endpoint" seems simpler, but you must confirm their definition includes every attached device with an OS, like standalone pin pads or inventory scanners, not just the primary till.
The hidden cost for both isn't a module, it's the policy labor. Neither platform's default posture is retail-optimized. You'll spend the first 90 days building exception lists for legacy devices. Ask each vendor for their default detection sensitivity for USB-HID devices and their process for whitelisting a device by hardware ID versus process path. The time-to-safe-exclusion is your team's unlicensed annual fee.
—at
The per-user vs. per-endpoint debate is a distraction. The real cost for a chain your size is in the management fabric.
> typical annual licensing costs
You won't get a "typical" cost, you'll get a "first year with onboarding" cost. The second-year renewal for Trend will hinge on your user-count audit reconciliation, which is a quarterly paperwork exercise you're not staffed for. Fortinet's per-endpoint cost is more predictable, but only if you get the exact module list in writing now, and have a clause locking it for three years. Their "Essentials" bundle often omits the forensic isolation tools you'll need for PCI forensic reviews.
The substantial hidden cost isn't a module, it's the delta between their default aggressive posture and what a retail POS image can tolerate. Both will treat your inventory guns as anomalous network scanners. Budget two weeks of a senior engineer's time just to build and test the golden image exceptions before you push to a single store.
Trust but verify – and audit
Typical annual licensing is a moving target, but you can pin it down. For your scale, list every device with a kernel - that's your true count. The quoted base for Vision One's per-user model will inflate the moment you account for shift workers and shared kiosks. FortiEDR's per-endpoint quote is cleaner, but you must audit the fine print for what an "endpoint" excludes; I've seen them charge separately for virtualized tills.
The substantial hidden cost for both is the professional services you'll need to tune the default policies. Neither ships with a retail-hardened configuration. You'll pay extra for the vendor's PS team to build the exception lists for your legacy pin pads and inventory scanners, or you'll burn a month of your team's time doing it. Ask for their "point of sale" hardening guide upfront - if they don't have one, that's a red flag and a future cost.
Speed up your build
You've zeroed in on the critical operational cost: the licensing definitions. Beyond the paperwork overhead of Trend's per-user model, there's the technical overhead of enforcement. You'll need to integrate your HR system or AD logs for accurate counts, which is another integration to maintain.
For per-endpoint, the hidden cost is in the physical audit. A standalone label printer running an embedded OS might be an "endpoint" you hadn't budgeted for.
The essential feature you'll pay extra for with both is granular policy management. The base licenses won't give you the fine-grained control needed to, say, allow a specific USB vendor ID for a scanner while blocking all others. That's usually an add-on or requires the higher service tier.
—Anita