Policies

Policies let you configure Windows settings on managed devices and track whether devices comply with your desired configuration.

Overview

The Policies page has two views:

  • Policies tab - Manage your policy profiles
  • Device Compliance tab - See which devices are compliant with their assigned policies

Four summary cards at the top show total policies, devices with policies, compliant devices, and non-compliant devices.

Creating a Policy

  1. Go to Policies in the sidebar.
  2. Click Create Policy.
  3. Enter a name (e.g., "Security Baseline", "Windows Update Settings").
  4. Optionally add a description.
  5. Click Create Policy.

You'll be taken to the policy detail page to add settings.

Configuring Policy Settings

  1. Click Add Settings on the policy detail page.
  2. Browse the settings catalog, organized by category and subcategory.
  3. Search for specific settings by name.
  4. Select the settings you want to include.
  5. Configure the desired value for each setting.

Policy Properties

PropertyDescription
NameDescriptive name for the policy
DescriptionOptional notes about the policy's purpose
EnabledWhether the policy is actively enforced
PriorityDetermines precedence when settings conflict (higher number = higher priority)

Assigning Policies to Groups

  1. Open a policy's detail page.
  2. Under the assignments section, click to assign the policy to a group.
  3. Select the target device group.
  4. Optionally tick groups to leave out under Exclude groups. A device in an excluded group is skipped even when it is also in the target group.
  5. Confirm the assignment.

All devices in the group, except those in an excluded group, will receive the policy settings on their next check-in. To change which groups an assignment leaves out, click Exclusions next to the group assignment; devices that become excluded stop receiving the policy on their next check-in and the agent reverts its settings. The All Devices group cannot be excluded. To remove a policy from a group, click the remove button next to the group assignment.

Monitoring Compliance

Switch to the Device Compliance tab to see per-device compliance status:

StatusMeaning
CompliantDevice meets all assigned policy settings
Non-CompliantDevice does not meet one or more settings
SupersededAll non-compliant settings are overridden by a higher-priority policy - the device is correctly configured
PartialDevice meets some but not all settings (shows ratio, e.g., "3/5")
No policiesDevice has no policies assigned

Tips

  • Start with a small pilot group to test policy settings before rolling them out broadly.
  • Use the priority field to control which settings win when multiple policies target the same device.
  • Check the Device Compliance tab regularly to identify devices that have drifted from your desired configuration.