11.3 Assigning Policies to the Management Zone

You can assign security policies to the Management Zone. When determining the effective policies to be enforced on a device, the Zone policies are evaluated after all other assigned policies. For more information about how an effective policy is determined, see Section 5.0, Effective Policies.

Consider the following situations:

You can assign Zone policies at three levels. This enables you to assign different Zone policies to different devices within your Management Zone.

In ZENworks Control Center:

  1. To assign a Zone policy to the Management Zone, click the Configuration tab, click Endpoint Security Management (in the Management Zone Settings panel), then click Zone Policy Settings.

    or

    To assign a Zone policy to a device folder, click the Devices tab, locate the folder in the Devices list, then click Details > Settings > Endpoint Security Management > Zone Policy Settings.

    or

    To assign a Zone policy to a device, click the Devices tab, click the device in the Devices list, then click Settings > Endpoint Security Management > Zone Policy Settings.

  2. If you are assigning a Zone policy to a device folder or device, click Override settings to activate the panel.

  3. In the list, click Add, browse for and select the policy you want to add as a default policy, then click OK to add it to the list.

  4. After you finish adding default policies, click Apply to save the settings.

    By default, Management Zone settings are cached on the ZENworks Server and the cache is updated every 10 minutes. Because of this, if a change is made to a zone setting, devices don’t receive the changes until the next cache update, which might be as long as 10 minutes.

    For ZENworks Endpoint Security Management, the following are stored as zone settings:

    • Zone security policies

    • Location and network environment settings

    • Effective policy report settings

    • Data encryption keys

    If you change any of these settings and you want to apply them immediately to a device, you must use the zac command line utility on the device to bypass the ZENworks Server cache and retrieve the new settings. To do so, run the following command on the device:

    zac ref general bypasscache