When Your Vendor Upgrades on Their Schedule, Not Yours

Jul 27, 2026

Reading Time: 4 minutes

 
There is a category of IT problem that most businesses do not think about until it happens. It is not a cyberattack. It is not a hardware failure. It is your cloud-hosted security platform changing underneath you – and an important part of your configuration not surviving the transition.
That is what happened this week with a client environment using Fortinet’s cloud-hosted Endpoint Management Server.

When a cloud-hosted vendor upgrade breaks your security configuration

In a vendor-hosted environment, the vendor manages the platform and controls its upgrade cycle.  that is one of the benefits of cloud software: businesses do not need to maintain the underlying infrastructure or manually deploy every platform updated.

However, it also means that upgrades may happen according to the vendor’s timetable rather than the client’s operational schedule.

Following a platform upgrade, the Active Directory connector used in the client’s environment was no longer compatible with the updated EMS version. The connection between EMS and Active Directory failed, removing an important source of identity information from the security environment.

The firewalls did not stop working. Traffic continued to flow. But the integration that helped the environment associate users with devices was no longer functioning as intended.

Our monitoring surfaced the connector failure, and the team began investigating before it developed into a wider client issue. We identified the version incompatibility, installed the correct connector version and restored the integration.

The environment returned to normal, but the incident highlighted an important point: cloud-hosted security platforms still require active oversight.

The cloud hosting assumption managed security teams must challenge

When a business moves to a cloud-hosted security platform, the immediate benefit is obvious. No on-premises infrastructure to maintain. Automatic availability. Vendor-managed uptime. These are real advantages, and they are why cloud-hosted security management has become the default for many organisations.

What is less obvious is that “vendor-managed” cuts both ways. When the vendor manages the platform, the vendor also controls when it changes. The upgrade schedule is theirs. The feature rollout timeline is theirs. And when they update a component that your configuration depends on — an AD connector, an API integration, an authentication method — you are relying on the upgrade being backwards-compatible with everything you have built on top of it.

Sometimes it is. Sometimes, as this week demonstrated, it is not.

Vendor-Managed Does Not Mean Risk-Free

Cloud-hosted security management offers real advantages.  There is less infrastructure for the client to maintain. Platform availability is managed by the vendor. Updates, improvements and security fixes can be introduced more efficiently. However, vendor-managed also means vendor-controlled.

The platform can change. APIs can be updated. Authentication methods can evolve. Connectors and other dependent components may need to be upgraded to remain compatible. Most of the time, these transitions happen without disruption. Occasionally, a component that depends on the platform does not move with it.

The risk has not disappeared. It has shifted from maintaining infrastructure to maintaining integration continuity.Fortinet EMS Active Directory connector integration diagram showing identity-based policy enforcement in cloud-hosted security fabric

Why Identity Integrations Matter

The Active Directory connector provides EMS with information about users and devices. That context supports user-aware visibility and policy enforcement across the security environment.

When the connector fails, the impact may not be immediately obvious. The network remains online. Users may continue working. There may be no dramatic outage to alert the business that something has changed. What begins to erode is context.

The security environment may no longer have the same level of visibility into which user is associated with which device. Policies that depend on that identity information may begin operating with incomplete data.

This is what makes integration failures particularly important to monitor. They can weaken the intended security architecture without causing an obvious operational failure.

Integration Monitoring Must Be an Ongoing Discipline

Cloud platforms evolve continuously. The systems and connectors that depend on them must therefore be kept on tested, supported and mutually compatible versions.  That requires more than waiting for something to stop working.

Organisations managing their own security environments should include connector compatibility and integration-health checks in their regular maintenance processes.

Organisations using a managed cybersecurity provider should ask a different question:  Does the provider actively monitor the health of critical integrations, or do they only discover a problem after users begin reporting symptoms?

In this case, the client did not need to identify the failure and raise a support ticket. Our monitoring had already surfaced the issue, and the investigation was underway.  That is what continuous oversight is intended to achieve.

What Proactive Managed Security Looks Like

Managed security is not only about responding quickly once an incident has been reported. It is about maintaining enough visibility to identify when an environment is no longer operating as designed.

The vendor upgraded on their schedule. We responded on ours — which happened to be faster.  Cloud-hosted security does not eliminate the need for active management. It changes what needs to be managed.

The vendor is responsible for operating and evolving the platform. Someone still needs to understand what those changes mean for the integrations, policies and configurations that depend on it.

The real question is not whether the platform will change. It will.  The question is whether someone is watching what those changes do to your environment.

If your organisation relies on cloud-hosted security platforms, speak with our team about how the Trusted Response Centre monitors the integrations and configurations those platforms depend on.

author avatar
Jacques v.d Merwe

Let’s connect