A Microsoft 365 login from an unmanaged mobile, a shared file sent through an unsanctioned storage service, or an administrator session from overseas can create more exposure than a traditional perimeter event. To secure SaaS apps, Fortinet should be applied as an identity-aware control framework, not simply another security product in an already fragmented stack.
For Australian organisations, the issue is rarely whether SaaS is being used. It is how widely it is used, who can access it, where sensitive information can travel, and whether security teams can see that activity clearly enough to act. The right Fortinet design brings access, inspection, endpoint posture and operational visibility together without making everyday work unnecessarily difficult.
How to secure SaaS apps with Fortinet
SaaS security starts with accepting a practical reality: the application is outside the data centre, but responsibility for user access and data handling remains with the business. Microsoft 365, Google Workspace, Salesforce, ServiceNow, Xero and industry-specific platforms may each have useful native controls. Managing them separately, however, often leaves inconsistent policies, blind spots and a growing administrative burden.
Fortinet helps consolidate those controls through its Security Fabric approach. Rather than relying on one product to solve every SaaS risk, organisations can apply complementary capabilities across identity, endpoint, network, secure access service edge and analytics. This is particularly valuable for businesses with a mix of head office users, branches, remote staff and third-party contractors.
The aim is straightforward: only verified users on acceptable devices should reach approved services, their activity should be governed according to risk, and security teams should be able to investigate exceptions quickly.
Start with the access paths, not the product list
Before selecting licences or enabling policies, map how people actually reach SaaS applications. A user in the office may connect through a FortiGate next-generation firewall. A home-based employee may use FortiClient with secure remote access. A contractor may sign in directly from a browser on a device the organisation does not manage. Each path calls for a different balance of control and convenience.
Classify applications by business importance and the sensitivity of the information they hold. Payroll, finance, customer records, engineering documentation and privileged administration deserve a more restrictive policy than general research or public marketing tools. This avoids the common mistake of applying one broad rule to every cloud service, then creating exceptions until the rule is no longer meaningful.
It also exposes shadow IT. Staff usually adopt unapproved SaaS tools because the approved process is slow or does not meet a real need. Blocking every unknown application can be appropriate in highly regulated environments, but for many organisations a better approach is to identify, assess and either approve a safer alternative or apply measured restrictions. Security policy works best when it reflects how the business operates.
Make identity and device posture the first gate
Passwords alone are not a credible control for valuable SaaS services. Multi-factor authentication, sensible conditional access and least-privilege administration should form the baseline. FortiAuthenticator and FortiToken can support stronger authentication workflows, while Fortinet integrations can help teams apply access decisions consistently across their broader environment.
Device posture matters just as much. A valid user account on an unpatched personal device is not the same risk as the same employee using an encrypted, managed corporate laptop. FortiClient and FortiClient EMS can provide endpoint telemetry and posture signals that support access policy, including operating system status, endpoint protection and device compliance.
Zero trust network access is useful where staff need access to private applications alongside SaaS services, but it should not be treated as a substitute for SaaS governance. ZTNA controls access to defined resources. SaaS security must additionally consider what users do after they are signed in: downloading files, sharing links, creating forwarding rules or granting third-party applications access.
Apply CASB and secure web controls where data moves
A cloud access security broker capability is central to controlling sanctioned and unsanctioned SaaS use. Through FortiSASE and associated cloud security controls, organisations can gain better visibility into cloud application activity and enforce policies around risky behaviour. Depending on the service and deployment model, these controls can help identify shadow SaaS, restrict unsafe uploads, govern file downloads and detect activity that does not align with policy.
Data loss prevention should be designed around the information that genuinely needs protection. Begin with a limited set of high-value patterns, such as tax file numbers, payment card data, customer identifiers or sensitive project documents. Apply monitoring first where operational impact is uncertain, then move to blocking once false positives have been assessed.
This staged approach matters. A policy that blocks every spreadsheet or document upload will quickly frustrate finance, sales and operations teams. Conversely, a monitor-only policy may not satisfy obligations where sensitive data is routinely handled. The correct setting depends on the data type, the destination application, user role and the organisation's risk appetite.
Secure web gateway controls add another useful layer, particularly for unmanaged browsing and web-based threats. They can enforce acceptable-use rules, inspect web traffic where appropriate and reduce exposure to malicious or newly registered sites that may be used in credential theft campaigns. SSL inspection can be highly effective, but it requires careful planning. Some applications, privacy-sensitive categories and certificate-pinned services may need exclusions to prevent disruption.
Secure the branch, remote user and endpoint together
SaaS traffic does not always need to be backhauled to a central office. Sending every cloud connection through a head office firewall can add latency, consume bandwidth and create a poor user experience. For distributed organisations, FortiSASE can provide security controls closer to remote users, while FortiGate appliances remain effective for office and branch protection.
The design should follow the user and application path. A small business with one office may achieve the required outcome with a FortiGate, managed endpoints and strong identity controls. A multi-site organisation with frequent remote work, contractors and direct-to-cloud access will usually benefit from a more distributed SASE model. There is no commercial value in overengineering a simple environment, just as there is no security value in forcing an enterprise requirement into a small-business design.
Endpoint protection remains essential because SaaS sessions are often compromised at the device level. Malware can steal browser sessions, capture credentials or access synchronised cloud files. FortiEDR can help detect and respond to endpoint threats, while FortiClient extends protection and visibility into the user access layer. Combined with patching, disk encryption and managed browser practices, this materially reduces the chance that a valid SaaS account becomes an attacker entry point.
Turn policy into an operating model
Technology only delivers measurable protection when somebody owns the policies, reviews alerts and manages exceptions. Assign clear responsibility for approving SaaS applications, reviewing privileged access, responding to risky sharing events and maintaining offboarding processes. Procurement, IT, security and business owners should all have a defined role.
A practical operating model should include four recurring activities:
- Review newly discovered SaaS applications and decide whether to approve, restrict or replace them.
- Check administrator accounts, third-party integrations and inactive users on a scheduled basis.
- Investigate high-risk events such as unusual sign-ins, mass downloads, external sharing and changes to forwarding rules.
- Test access policies after major application, identity or endpoint changes.
Buy for the architecture you need
Fortinet licensing, appliance sizing and service bundles should be selected against the intended security architecture. The cheapest product configuration can become expensive if it lacks the subscriptions, endpoint coverage or cloud access capacity required to enforce the policy you designed. Equally, buying every available feature before the organisation has processes to operate it is poor value.
A certified Fortinet specialist can help validate user numbers, branch connectivity, remote access demand, application priorities and support requirements before purchase. FortiSecure Store provides that practitioner-led guidance alongside genuine Fortinet hardware, subscriptions and optional deployment support, helping Australian buyers avoid incompatible or incomplete designs.
Start with the SaaS applications that carry the greatest business consequence, establish identity and device trust, then expand controls with evidence from real usage. That gives your organisation stronger protection without turning cloud adoption into an obstacle to getting work done.

