Policy assignment rules

Prev Next

Policy assignments rules reduce the overhead of managing numerous policies and help maintain more generic policies across your System Tree.

This level of granularity in policy assignments limits the instances of broken inheritance in the System Tree. Policy assignments can be based on user-specific or system-specific criteria:

  • User-based policies — Policies that include at least one user-specific criteria. For example, you can create a policy assignment rule that is enforced for all users in your engineering group. You can then create another policy assignment rule for members of your IT department. This rule allows the members of the IT department to log on to any computer in the engineering network with the access rights to troubleshoot problems on a specific system in that network. User-based policies can also include system-based criteria.

  • System-based policies — Policies that include only system-based criteria. For example, you can create a policy assignment rule that is enforced for all servers on your network based on the tags you have applied, or all systems in a specific location in your System Tree. System-based policies cannot include user-based criteria.