Policy assignment rule priority

Prev Next

Policy assignment rules can be prioritized to simplify how you manage and maintain your policy assignments. When you set priority to a rule, it is enforced before other assignments with a lower priority.

In some cases, the outcome can be that rule settings are overridden. For example, consider a system that is included in two policy assignment rules, rules A and B. Rule A has priority level 1, and allows included systems unrestricted access to Internet content. Rule B has priority level 2, and heavily restricts the same system's access to Internet content. In this scenario, rule A is enforced because it has higher priority. As a result, the system has unrestricted access to Internet content.

Policy assignment rule priority on multi-slot policies

Multi-slot policies allow administrators to send more than 1 policy of a particular policy type to the client system. For example, an administrator can assign more than 1 Firewall rules policy which are merged and enforced on the client system.

Priority of rules is not considered for multi-slot policies. When a single rule containing multi-slot policies of the same product category is applied, all settings of the multi-slot policies are combined. Similarly, if multiple rules containing multi-slot policy settings are applied, all settings from each multi-slot policy are combined. As a result, the applied policy is a combination of the settings of each individual rule.

When multi-slot policies are aggregated, they are aggregated only with multi-slot policies of the same type. Multi-slot policies assigned using policy assignment rules override policies assigned in the System Tree. Also, user-based policies take priority over system-based policies. Consider the following scenario where:

Scenario: Using multi-slot policies to control Internet access

Your System Tree includes a group named "Engineering" that consists of systems tagged with "IsServer" or "IsLaptop." Policy A is assigned to all systems in this group. Assigning policy B to any location in the System Tree above the Engineering group using a policy assignment rule overrides the settings of policy A, and allow systems tagged with "IsLaptop" to access the Internet. Assigning policy C to any group in the System Tree above the Engineering group allows users in the Admin user group to access the Internet from all systems, including those in the Engineering group tagged with "IsServer."

Policy type

Assignment type

Policy name

Policy settings

Generic policy

Policy assigned in the System Tree

A

Prevents Internet access from all systems to which the policy is assigned.

System-based

Policy assignment rule

B

Allows Internet access from systems with the tag "IsLaptop."

System-based

Policy assignment rule

C

Allows unrestricted Internet access to all users in the Admin user group from all systems.

User-based

Policy assignment rule

C

Allows unrestricted Internet access to all users in the Admin user group from all systems.

Excluding Active Directory objects from aggregated policies

Rules that consist of multi-slot policies are applied to assigned systems without regard to priority. Because of this, you might need to prevent policy setting aggregation. You can do this by excluding a user (or other Active Directory objects such as a group or organizational unit) when creating the rule.

For more information on the multi-slot policies that can be used in policy assignment rules, see the product documentation for the managed product you are using.