A rule group is a collection of rules. Although you can directly add rules to any ePO - On-prem-based policy, the rules defined in a policy are specific to that policy. In contrast, a rule group is an independent unit that collates a set of similar or related rules.
After you define a rule group, you can reuse the rules by associating the group with different policies. Also, when you change or update a rule group, the change is automatically introduced into all associated policies.
Application Control provides predefined rule groups to allow commonly used applications to run smoothly. Although you can't edit the predefined rule groups, you can use an existing rule group as a starting point to develop new rule groups. If needed, you can also import or export rule groups.
Rule groups can drastically reduce the effort required to define similar rules across policies. If you have a large setup and you are deploying the software across numerous endpoints, use rule groups to minimize the deployment time and effort.
Rule group ownership
Users can edit and delete only the rule groups that they own. A user who creates a rule group, is automatically set as the owner of the rule group. Only the owner and ePO - On-prem administrator can edit and delete the rule group. Also, the administrator can assign ownership to other users or revoke ownership from the owner. In this case, the ownership is automatically granted to the ePO - On-prem administrator.
Users who don't own a rule group can only view the rule group and its policy assignments, duplicate the rule group, and add the rule group to policies. But, if the owner or the ePO - On-prem administrator updates a rule in the rule group, the change cascades across all associated ePO - On-prem policies.
This scenario suits non-global administrators who want to use a rule group (created by theePO - On-prem administrator) without maintaining it. If this scenario does not suit your requirements, duplicate the rule group that you don't own, then assign the duplicate to policies. This method provides you ownership of the duplicated rule group.
Rule group example
Here is an example of how rule groups are used.
An organization runs Oracle on multiple servers. Each of these servers is used by the HR, Engineering, and Finance departments for different purposes. To reduce rule redundancy, we define an Application Control rule group (named AC-Oracle) with rules to define the relevant updaters for Oracle to function.
After the rule group is defined, we can reuse these rule groups across policies for the different departments. So, when defining the HR Servers policy, add the AC-Oracle rule group to the policy with rule groups for the other applications installed on the HR server. Similarly, add the AC-Oracle rule group to the relevant policies for the Engineering Servers and Finance Servers. After defining the policies, if the rule for a critical file was not created, directly update the rule group to automatically update all policies.