Policies
Policies let you configure Windows settings on managed devices and track whether devices comply with your desired configuration.
Overview
The Policies page has two views:
- Policies tab - Manage your policy profiles
- Device Compliance tab - See which devices are compliant with their assigned policies
Four summary cards at the top show total policies, devices with policies, compliant devices, and non-compliant devices.
Creating a Policy
- Go to Policies in the sidebar.
- Click Create Policy.
- Enter a name (e.g., "Security Baseline", "Windows Update Settings").
- Optionally add a description.
- Click Create Policy.
You'll be taken to the policy detail page to add settings.
Configuring Policy Settings
- Click Add Settings on the policy detail page.
- Browse the settings catalog, organized by category and subcategory.
- Search for specific settings by name.
- Select the settings you want to include.
- Configure the desired value for each setting.
Policy Properties
| Property | Description |
|---|---|
| Name | Descriptive name for the policy |
| Description | Optional notes about the policy's purpose |
| Enabled | Whether the policy is actively enforced |
| Priority | Determines precedence when settings conflict (higher number = higher priority) |
Assigning Policies to Groups
- Open a policy's detail page.
- Under the assignments section, click to assign the policy to a group.
- Select the target device group.
- Optionally tick groups to leave out under Exclude groups. A device in an excluded group is skipped even when it is also in the target group.
- Confirm the assignment.
All devices in the group, except those in an excluded group, will receive the policy settings on their next check-in. To change which groups an assignment leaves out, click Exclusions next to the group assignment; devices that become excluded stop receiving the policy on their next check-in and the agent reverts its settings. The All Devices group cannot be excluded. To remove a policy from a group, click the remove button next to the group assignment.
Monitoring Compliance
Switch to the Device Compliance tab to see per-device compliance status:
| Status | Meaning |
|---|---|
| Compliant | Device meets all assigned policy settings |
| Non-Compliant | Device does not meet one or more settings |
| Superseded | All non-compliant settings are overridden by a higher-priority policy - the device is correctly configured |
| Partial | Device meets some but not all settings (shows ratio, e.g., "3/5") |
| No policies | Device has no policies assigned |
Tips
- Start with a small pilot group to test policy settings before rolling them out broadly.
- Use the priority field to control which settings win when multiple policies target the same device.
- Check the Device Compliance tab regularly to identify devices that have drifted from your desired configuration.