ZTNA Tag Missing: Why Users Can Authenticate But Not Access Applications
An administrator is troubleshooting a ZTNA issue where users are able to authenticate but the application access is still blocked. The ZTNA status on FortiClient shows 'Connected' but the application does not load. What is the MOST likely cause?
Quick Answer
The answer is that the user’s FortiClient lacks the required ZTNA tags. Even when a user successfully authenticates and the FortiClient shows a “Connected” status, ZTNA enforces access based on tags assigned to the client, not merely on authentication. If the necessary tags are missing, the FortiGate will block application access because it cannot match the client to the permitted access policy. On the Fortinet NSE 7 Advanced Security NSE7 exam, this question tests your understanding that ZTNA is a tag-based zero-trust model, where authentication alone is insufficient—tags act as the dynamic access token. A common trap is assuming a successful VPN-like connection guarantees application access, but ZTNA decouples connectivity from authorization. Remember the mnemonic: “Auth gets you in, tags let you through.”
⚠ Common exam trap
Many candidates assume a 'Connected' ZTNA status means full application access is granted, overlooking that ZTNA tags are the critical enforcer of granular access control beyond just tunnel establishment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's FortiClient does not have the required ZTNA tags assigned
When users can authenticate and the ZTNA status shows 'Connected' on FortiClient, but the application still fails to load, the most likely cause is that the client lacks the required ZTNA tags. ZTNA tags are used by the FortiGate to enforce access policies; without the correct tags, the FortiGate will block the application traffic even though the tunnel is established. This scenario indicates a tag assignment or synchronization issue between FortiClient and EMS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user's FortiClient does not have the required ZTNA tags assigned
Why this is correct
ZTNA tags define access permissions. If the user's client lacks the required tags, the FortiGate blocks access even though the client is connected.
- ✗
The ZTNA application is not configured with HTTPS
Why it's wrong here
ZTNA supports both HTTP and HTTPS; this is not a likely cause.
- ✗
The FortiClient EMS server is not reachable from the FortiGate
Why it's wrong here
If EMS is unreachable, FortiClient may not get tags, but the connection would likely fail earlier.
- ✗
The FortiGate is not configured with the correct ZTNA application gateway
Why it's wrong here
This would prevent connection altogether, not just block access after authentication.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator is troubleshooting a ZTNA access issue. Remote users can connect to the FortiGate's ZTNA proxy, but when they try to access the internal application, they receive a 403 Forbidden error. The administrator has verified that the user is authenticated and the ZTNA rule is configured correctly. What is the most likely cause?
medium- A.The FortiGate firewall policy allowing ZTNA traffic is missing
- ✓ B.The user's device does not have the required ZTNA tags from EMS
- C.The application server does not have a valid certificate
- D.The ZTNA proxy is configured with the wrong port for the application
Why B: A 403 Forbidden error in ZTNA typically indicates that the access control rule denied the request. This can happen if the device does not meet the required posture checks (ZTNA tags). Option B is correct because the ZTNA rule likely requires a specific tag that the device does not have, resulting in denial.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.