1.8 Security Policy Summary

The following chart provides a summary of location support (global or location-based), assignment support (device, user, or zone), and multiple-policy support (plural or singular).

 

Global

Location Based

Device Assignment

User Assignment

Zone Assignment

Plural

Singular

Antimalware Enforcement

 

 

 

Antimalware Custom Scan

 

 

 

Antimalware Network Scan

 

 

 

Antimalware Scan Exclusions

 

 

 

Application Control

 

Communication Hardware

 

Firewall

 

Location Assignment

 

 

Microsoft Data Encryption

 

 

 

Security Setting

 

 

Scripting

 

 

Storage Device Control

 

USB Connectivity

 

VPN Enforcement

 

 

Wi-Fi

 

Global: Can be created as a global policy. A global policy is available regardless of the device’s location.

Location Based: Can be created as a location-based policy. A location-based policy is available only when the device’s location matches a location defined in the policy.

Device Assignment: Can be assigned to a device, device folder, or device group.

User Assignment: Can be assigned to a user, user folder, or user group.

Zone Assignment: Can be assigned as a default policy at the Management Zone.

Plural: Supports merging of multiple policies (of the same type) into one effective policy to be enforced on a device. The effective policy is a determined by established ordering and merging rules. For details, see How the Effective Policy is Determined.

Singular: Supports enforcement of only one policy (of a single type) on a device. If multiple policies are assigned, the effective policy is determined by established ordering rules. For details, see How the Effective Policy is Determined.