Policy prioritization

Prev Next

The Agent Policy Service allows you to prioritize xAgent policies by defining the order of precedence in the Web UI. Access the Policies page and drag a policy in the Policies table to a new position to change the policy priority level. Policies given a higher priority takes precedence over policies assigned a lower priority.

UI_Policy_Priority_No_scap.png

Important

The Agent Default Policy is always set to the lowest priority level.

Policy priority exceptions

Custom policies created using an API custom configuration channel override all other policies for the assigned host set.

Note

Trellix recommends using the Web UI to create custom policies because you cannot change the priority level or host set assignment for a custom policy created using an API custom configuration channel.

When an API custom configuration channel is created for a host set, the xAgent settings are established by that channel, and any xAgent configuration settings are ignored for endpoints included in the host set. To return the host set to the xAgent Default Policy or an assigned custom policy instead of the custom configuration channel settings, you must first delete the custom policy. You can create a new custom policy using the Web UI.

In addition, if a host is included in multiple host sets with different custom configuration channels, channel priority numbers are used to determine which xAgent settings apply to the host. See Understanding Configuration Channel Priorities for more information.