> For the complete documentation index, see [llms.txt](https://sirogy.gitbook.io/trellix-epolicy-orchestrator-on-prem-5.1/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sirogy.gitbook.io/trellix-epolicy-orchestrator-on-prem-5.1/policy-management/policies-overview.md).

# Policies Overview

Policies are a collection of rules or settings that make sure a product's features are configured correctly on your managed systems.

ePO policy management features or functions include:

<details>

<summary>Policy Catalog</summary>

Provides a central location for the creation and management of default and custom policies

</details>

<details>

<summary>Policy Assignments</summary>

The policy settings are defined in the policy object, which is done in the Policy Catalog. The assignments then determine where in the tree that particular object is assigned. For example, if you want a particular setting applied to a machine, you would first create a policy object with the desired setting in the policy catalog, and then assign it to the relevant machine.

</details>

<details>

<summary>Policy Assignment Rules</summary>

Reduce the overhead of managing numerous policies for individual users or systems that meet specific criteria while maintaining more generic policies across your System Tree

</details>

<details>

<summary>Policy History</summary>

Lets you view and compare policy history entries or revert to a previous version of a policy

</details>

<details>

<summary>Policy Comparison</summary>

Lets you compare like policies (all settings, matches, differences). Many of the values and variables are specific to each product. Optionally, you can open a printer-friendly view of the comparison.

</details>

#### **Permission Sets**

To view, or to view and edit policies, you must have the appropriate permissions. Administrators always have permission to view and change policy settings, but other ePO users may need permissions through their respective permission set.

As you add new extensions to the ePO server by installing new point-products, you have new permission sets that control the access to the policies for those products. By default, the extensions install with no permissions for users other than the Administrator.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/TB50mXYQGp4uo4La_Nau4oNW2hUjendHq.png" alt="Menu &#x26;gt; User Management &#x26;gt; Permission Sets"><figcaption><p><em><strong>Menu</strong></em> > <em><strong>User Management</strong></em> > <em><strong>Permission Sets</strong></em></p></figcaption></figure>

***

#### **Assignment and Inheritance**

It is likely that most systems within any environment will require an identical or very similar configuration. A small minority of systems may require radically different settings from the majority.&#x20;

* The purpose of policy objects and inheritance is to allow the described scenario (or any given scenario) to be implemented with the minimal effort possible.
* Policy assignment is the allocation of a specific named policy object at a specific node within the ePO System Tree to achieve this.
* Policy inheritance is the concept of a higher-level policy assignment being applied to a lower-level node.

Creating and configuring a policy object assigned at the System Tree level gives all systems identical settings. For any systems that do not require these settings, create, configure, and assign a different policy object with the new values. Inheritance will ensure that these new values are enforced from the chosen level down, until another policy is assigned.

ePO provides two policy objects (one is named Trellix Default and the other is My Default) for each product or product configuration category.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/BR62Scs_v6XUYgZk_fo1vmv-x7if13wlW.png" alt=""><figcaption></figcaption></figure>

#### **User Interface**

To access the Policy Catalog entries, click **Menu** > **Policy** > **Policy Catalog** or select **Policy Catalog** from the top Menu bar in the ePO console.&#x20;

The Policy Catalog has been divided into three sections:

* Products
* Policy Category
* Policy Details

***Click the information (i) icon in each section in the figure below to see additional details.***

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/pL_wZG7fBeiattYs_ug9XMgngI52h0l21.png" alt="Policy Catalog UI.png"><figcaption></figcaption></figure>

1. ![](https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FZnaBLZEyb4AmMU5wNVic%2Fimage.png?alt=media\&token=1dae819a-1397-4b2e-bd1f-ce7132fa6222)
2. ![](https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FyMehGc4uKBKyqIcc5vKU%2Fimage.png?alt=media\&token=7a0a65fd-398e-43a6-8047-f24afb67f245)
3. ![](https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FaEz72iobCNhIqL9gRukQ%2Fimage.png?alt=media\&token=e4755441-db67-461d-8667-9fe6a68182f6)

#### **Policy Approval Management**

As an administrator, you can choose whether policy and task management users need approval to make policy or task changes The Permission Sets allow some policy users not only to create and modify policies, but also to approve or reject policies created by other users. To manage policy creation, you can create permission sets for users who can create and modify specific product policies. For example, you can create permission sets that allow one user to change policies and another user permission to approve or reject those changes.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/15AqY1AvPy7_H5xu_ay2kbv9M94lI66-j.png" alt="Menu &#x26;gt; Configuration &#x26;gt; Server Settings"><figcaption><p><em><strong>Menu</strong></em> > <em><strong>Configuration</strong></em> > <em><strong>Server Settings</strong></em></p></figcaption></figure>

***

To configure the Server Settings to allow users to submit policies for approval:

1. Open **Menu** > **Configuration** > **Server Settings**.
2. Click **Approvals** on the Setting Categories pane.
3. Click **Edit**.
   1. Select **Users need approval for policy changes** if policy users need to seek approval to make changes.
   2. Select **Administrators and Approvers need approval for policy changes** if the administrators and approvers also need to seek approval to make changes.

### **Policy Catalog**

You use the Product menu to view the available policies for a specific product. Policies are further filtered by Policy Category. The categories vary for each product.&#x20;

Example:  Trellix Agent policies are organized by these categories:

* General
* Repository
* Troubleshooting
* Custom Properties
* Product Improvement Program

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/ef3XyxGFtXk_jf_r_QjaURySiD1_FfBIZ.png" alt=""><figcaption></figcaption></figure>

#### **Policy Category**

The figure below highlights some key controls for a selected product's available product categories.&#x20;

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/05hF0dFjLx2eW_eE_e3EobgDInQB_QCkN.png" alt=""><figcaption></figcaption></figure>

1. **Search**: Provides ability to search policy categories based on search string
2. **New policy**: Launches the Create a New Policy dialog box, where you can create a new policy for a selected product and category\
   \-  **Import**: Imports previously exported policies to the selected product\
   \-  **Export**: Downloads or displays the policies of the selected product in .xml format.
3. Policy Categories:\
   Name: Lists the name of existing policies. To open a policy, click the link for its name.\
   Rule Assignments: Shows the number of rule assignments for the policy\
   Assigned To: Shows the number of assignments for the policy. Assigned policies are linked to a corresponding Policy Assignment page.\
   Actions: Provides links to the actions available for a selected policy. Some policies are read-only and can only be duplicated.\
   \-  **View**: Opens a viewable version of the policy details page for the selected product\
   \-  **Edit**: Opens an editable version of the policy details page for the selected product

#### **Policy Details**

The figure below highlights some key controls for the policy details of a selected product category.&#x20;

![Policy Details.png](https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/ayasN9wPnS65dHJ1_nKHmtrkJ8RWLb1ft.png)

1. **Policy Actions**:\
   **Duplicate**: Make a copy of policy to edit\
   **Delete**: Delete policy\
   **Export**: Download policy in .xml format\
   Share: Designate policy to be shared to another ePO server
2. **Policy Information**:\
   **Policy Name**: Shows policy name for selected policy category\
   **Notes**: Allows adding notes to the policy\
   **Owner**: Shows policy owner (click link to manage ownership)
3. **Assignments**:\
   **Affected Systems**: Lists name of existing policies (Click link to open)\
   **Assigned To**: Shows group or system policy is assigned to\
   **Rule Assignments**: Shows number of rule assignments for the policy
4. **History**:\
   **View Full Policy History**: Opens Policy History page directly for selected product and product category

The Policy Catalog includes two types of default polices for managed products: Read-only and editable.&#x20;

* You cannot rename, edit, or delete read-only policies. However, you can duplicate and then customize them, as required.&#x20;
* You can change, rename, duplicate, delete, and export custom policies. This includes custom policies that you create by duplicating an existing policy or by clicking the New Policy button.

When you open an existing policy or create a new policy, the policy settings are organized by tabs, which you click to view and define the settings on that tab. The blue checkmarks indicate enabled policy options.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/kXWHhFvw5zdzKoxW_MfOv5N9_A9MH9J-q.png" alt=""><figcaption></figcaption></figure>

### **Policy Management**

#### **Duplicating a Policy**

When you duplicate a policy, you create an exact copy but with a different name. After duplicating the policy, open and edit it as required.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/uSZxQ25OjquOqPRn_mgZ4ZmzYKk9EwYKH.png" alt=""><figcaption></figcaption></figure>

#### **Adding a Policy**

Like a duplicated policy, a new policy is based on an existing policy and can be created by clicking the **New Policy** button. Again, after creating the policy, open and edit it as required.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/1wr1j85WYCnv2F62_B4VmZoSj6KdFwy41.png" alt=""><figcaption></figcaption></figure>

#### **Editing a Policy**

You can edit policies in two locations: Policy Catalog and System Tree.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/LMyxZSOZjE899AL5_R8dAkyDjkB04G3Pq.png" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Some policies are read-only and cannot be edited. The&#x20;*****Actions*****&#x20;column indicates if the policy you are viewing is read-only.**
{% endhint %}

#### **Changing Policy Ownership**

No one can modify or delete a policy except the policy’s owner or an Administrator. Any user with appropriate permissions can assign any policy in the Policy Catalog page, but only the owner or a global administrator can edit the policy.

All policies, for products and features to which you have permissions, are available from the Policy Catalog page. To prevent any user from editing other users’ policies, each policy is assigned an owner: the user who created it.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/onAvh_kEJ6HdWWIC_vlqnodRhYTm-a14C.png" alt=""><figcaption></figcaption></figure>

Guidelines for policy ownership:

* Only *Owner* and *Administrator* can change ownership
* Only users with appropriate permissions can be assigned ownership
* You can specify multiple non-administrative users as owners of a single policy

#### **Exporting and Importing Policies**

You can use the Export and Import tasks to move policies between servers. To do this, you must export the policy to an XML file, from the Policy Catalog page of the source server, then import it to the Policy Catalog page on the target server.

You can export and import all policies for a product or a single policy.

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/iUy7Ap4X85roAolk_2YbytQxdjkciu_Hl.png" alt="Exporting all Product PoliciesTo export all product policies, select the product under the Products column, select Export in the New Policy drop-down, right click the Download file link and select Save link as...You can then use this file to import to another ePO server.Importing PoliciesTo import policies, select the product under the Products column, select Import in the New Policy drop-down, click the Choose File entry and double-click the policy XML file you want to import."><figcaption></figcaption></figure>

**Exporting all Product Policies**

To export all product policies, select the product under the *Products* column, select **Export** in the *New Policy* drop-down, right click the **Download file** link and select **Save link as...**

You can then use this file to import to another ePO server.

\
**Importing Policies**

To import policies, select the product under the *Products* column, select **Import** in the *New Policy* drop-down, click the **Choose File** entry and double-click the policy XML file you want to import.

***

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/MmC6OawAyWbng9PB_6ldr-zPAL_3pMguH.png" alt="Exporting a Single PolicyTo export a single policy, select the Product under the Products column, select the policy, click Export under the Edit drop-down in Policy Details, right click the Download file link and select Save link as...You can use this file to import to another ePO server or to keep as a backup of the policy."><figcaption></figcaption></figure>

**Exporting a Single Policy**

To export a single policy, select the Product under the *Products* column, select the policy, click **Export** under the Edit drop-down in *Policy Details*, right click the **Download file** link and select **Save link as...**

You can use this file to import to another ePO server or to keep as a backup of the policy.

***

#### **Renaming or Deleting a Policy**

<figure><img src="https://training.trellix.com/content/elearningngx/AhnSgBAy7j7hIT_7H3aY2w/1693969305/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==VHVlIFNlcCAwNSAxNTowMTo0NSBFRFQgMjAyMw==/eot/scormcontent/assets/3DaC3i_KS-2ymW04_lYbVXfGRvpBmHvbP.png" alt=""><figcaption></figcaption></figure>

After selecting (highlighting) the policy (ABC Company above), do one of the following:

**RENAME**:&#x20;

1. Click the policy name field and enter in a new name
2. Click **Save Name**.

**DELETE:**&#x20;

1. Expand the Edit drop-down under Policy Details and select **Delete**.&#x20;
2. Confirm you want to delete the policy entry and click **OK**.

When you delete a policy, all groups and systems inherit the policy of their parent group, where applied.&#x20;

Before deleting a policy, review the groups and systems where it is assigned. If you don’t want the group or system to inherit the policy from the parent group, assign a different policy.

&#x20;If you delete a policy that is applied to the My Organization group, the McAfee Default policy of this category is assigned.

\
**Policy Assignment Management**

Assigning a Policy is the allocation of a specific named policy at a specific node within the ePO System Tree. A policy may be assigned to any node within the ePO System Tree, from the System Tree object itself, to a group or an individual system.&#x20;

> ### Assigning Policy to the Subgroup <a href="#card-title-54" id="card-title-54"></a>
>
> Use this task to assign a policy to a specific group of the System Tree. You can assign policies before or after a product is deployed.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FZenTF7QyamPhmPt1r24d%2Fimage.png?alt=media&amp;token=e23aa231-3971-482d-b941-d3afddbbf36b" alt=""><figcaption><p>From the <strong>System Tree</strong> > <strong>Assigned Policies</strong> tab, in the left pane, select a subgroup.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FA2gukLy09LwX1quVm4Cb%2Fimage.png?alt=media&amp;token=d97fd697-5816-46eb-a186-14829a36be89" alt=""><figcaption><p>At the top of the right pane, select the product from the <strong>Product</strong><br>drop-down list.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2Fplv7fbjGYeO54S4LCSq2%2Fimage.png?alt=media&amp;token=2dc21e37-282f-4ba3-b31e-a68a86bbebf5" alt="" width="563"><figcaption><p>In the right pane, select (highlight) a row and then on the far right, click the <strong>Edit Assignment</strong> link. a Policy Assignment page opens.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FU9roYdRbu8njfGn90mV9%2Fimage.png?alt=media&amp;token=b6252f83-7e00-4a8f-a14f-56ac7683a3fd" alt="" width="563"><figcaption></figcaption></figure>

1. To break inheritance from the parent group, click the radio button by **Break inheritance**.
2. From the **Assigned policy** drop-down list, select the policy you want to assign to this subgroup.&#x20;
3. Choose whether to lock policy inheritance. This prevents any systems, that inherit this policy, from having another one assigned in its place.
4. Click **Save**.

> ### Assigning Policy to a Single System <a href="#card-title-60" id="card-title-60"></a>
>
> Use this task to assign a policy to a single or system. You can assign policies before or after a product is deployed.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FEx9WLOWsSPa5KPqIfuTV%2Fimage.png?alt=media&amp;token=ba7d3a32-8172-4ffd-b228-1201d69b899f" alt=""><figcaption><p>From the <strong>System Tree</strong> > <strong>Assigned Policies</strong> tab, in the left pane, select a subgroup.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FMJcxu9LtWxPs3OUnnGPH%2Fimage.png?alt=media&amp;token=c42d8fd9-5767-4d47-ae4d-b8d833d82964" alt=""><figcaption><p>At the top of the right pane, select the product from the <strong>Product</strong><br>drop-down list.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2Fjw21lE8okGSKJyTEy28p%2Fimage.png?alt=media&amp;token=70a4d5d4-ed41-4767-9c16-0fb24cb169ec" alt=""><figcaption><p>In the right pane, select (highlight) a row and then on the far right, click the <strong>Edit Assignment</strong> link. a Policy Assignment page opens.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FWFjkrgZXDQscfo4nD4ro%2Fimage.png?alt=media&amp;token=2ee33fd9-7b8e-442c-b2ab-a3860677d7f5" alt="" width="563"><figcaption></figcaption></figure>

1. To break inheritance from the parent group, click the radio button by **Break inheritance**.
2. From the **Assigned policy** drop-down list, select the policy you want to assign to this subgroup.&#x20;
3. Choose whether to lock policy inheritance. This prevents any systems, that inherit this policy, from having another one assigned in its place.
4. Click **Save**.

### Assigning Policy to a Single System <a href="#card-title-40" id="card-title-40"></a>

Use this task to assign a policy to a single or system. You can assign policies before or after a product is deployed.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FMnBQiHbdxObGyCA1tLJQ%2Fimage.png?alt=media&amp;token=9c184776-7275-4ea2-b1c1-656b896aad3f" alt=""><figcaption><p>From the <strong>System Tree</strong> > <strong>Systems</strong> tab, in the left pane, select the group to which the system belongs.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FKD3emsa0B5iEeRIX7s7m%2Fimage.png?alt=media&amp;token=971c346c-8b48-4266-aabe-72cb8823d5d8" alt=""><figcaption><p>In the right pane, mark the checkbox by the system.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2F5vq6OQ8olqthw7KoOYWQ%2Fimage.png?alt=media&amp;token=4012653a-269d-4d33-a6df-fcd3ab67ec6c" alt="" width="563"><figcaption><p>At the bottom of the page, select <strong>Actions</strong> > <strong>Agent</strong> > <strong>Edit Policies on a Single System</strong>. A Policy Assignment page opens.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FjADDw8Ub3qYg40aPBGkl%2Fimage.png?alt=media&amp;token=06b552a4-84ad-48f1-a327-e89373a19d57" alt="" width="563"><figcaption><p>Select (highlight) the desired policy category, then click <strong>Edit Assignment</strong>. (Do not click the policy name.)</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FqrxhzRuvPn6YQ1bujZCe%2Fimage.png?alt=media&amp;token=74c5ebb3-8908-4f1a-9e2d-f11f17a19782" alt=""><figcaption></figcaption></figure>

If the policy is inherited, select **Break inheritance and assign the policy and settings below**, next to *Inherit from*.

Select the desired policy from the **Assigned policy** drop-down list, then click the **Save** button.

**Note**: From this location, you can also edit the settings of the selected policy or create a new policy.

**Assigning Policy to Multiple Managed Systems**

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FsHU7ueuELIB8Ck8BjrP2%2Fimage.png?alt=media&amp;token=a6acdece-cc9a-4fbd-b935-96b0019e72e1" alt=""><figcaption></figcaption></figure>

1. From the **System Tree** > **Systems** tab, in the left pane, select the group.
2. In the right pane, mark the checkbox by each system.
3. Click **Actions** > **Agent** > **Set Policy & Inheritance**. The Assign Policy page displays.
4. Complete the Assign Policy page and click **Save**.

### Copying and Pasting Assignments <a href="#card-title-47" id="card-title-47"></a>

Use these tasks to copy and paste policy assignments from one group or system to another. This is an easy way to share multiple assignments between groups and systems from different areas of the System Tree.&#x20;

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FSAiRhNhJC0z3b0JTwJbC%2Fimage.png?alt=media&amp;token=fdc616f2-1d35-4356-afc7-803f686b9571" alt="" width="563"><figcaption><p>From the <strong>System Tree</strong> > <strong>Assigned Policies</strong> tab, select the desired group in the System Tree and select the product from the <strong>Product</strong> drop-down list.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FosjqYjxM3oiRJ2TrkvDM%2Fimage.png?alt=media&amp;token=9b6d4ad0-6c5b-4c66-bd54-e37d9d77e424" alt="" width="563"><figcaption><p>Select <strong>Actions</strong> > <strong>Copy Assignments</strong>.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FwrxQqUnjT9bJbr5ZouRk%2Fimage.png?alt=media&amp;token=5fb38690-ff6c-4e91-aa1d-e335c5a0dfbb" alt="" width="563"><figcaption><p>Click in the <strong>Products and Features</strong> box to unselect all the products and click next the desired product, then click <strong>OK</strong>.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FwHc3fYNzTypagwm8TDLC%2Fimage.png?alt=media&amp;token=84c16b1f-75e6-490d-aa65-aa61197a3cf2" alt="" width="563"><figcaption></figcaption></figure>

On the **System Tree** > **Assigned Policies** tab, selected the desired group, then click **Actions** > **Paste Assignments**.

Note: If the group already has policies assigned for some categories, the Override Policy Assignments page displays. If this page appears, select the policy category to paste and click **OK**.

**Exporting and Importing Policy Assignments**

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2F9RlNZS60tgbYXcFXLzzW%2Fimage.png?alt=media&amp;token=eece1172-4b5a-4268-83ef-2e89bdbfe2aa" alt="" width="563"><figcaption></figcaption></figure>

* **Export All Assignments**: Exports all displayed assignments to an XML file
* **Export Group Policies**: Exports policies assigned to a specific group
* **Export Table**: Displays the Export page, allowing you to choose the way the table is exported
* **Import Assignments**: Imports previously exported policy assignments

#### **Locking Policy Assignment**

Policy enforcement locking prevents other users from changing policy assignment settings: in the group where locking took place and in any subgroups.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FOWSu43XC84w3llGJm96z%2Fimage.png?alt=media&amp;token=07cc510d-5643-4d4c-bbaf-d9c4b5f77d72" alt=""><figcaption></figcaption></figure>

* Can be locked at any group within the System Tree
* Does not prevent a policy from being modified
* Prevents breaking inheritance below the point of assignment

### **Policy Assignment Approval**

With the Policy Assignment Approval feature, if the user or administrator tries to assign the policy on systems or groups, then the administrator or the user with appropriate permissions can verify and approve the changes before it gets assigned and pushed to systems or groups.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FzMLrDhuUCJVP6vPJWtpm%2Fimage.png?alt=media&amp;token=697d824d-a403-4799-95e9-1a25cddc5ef9" alt=""><figcaption></figcaption></figure>

### **Policy Assignment Rules**

Policy assignment rules reduce the overhead of managing numerous policies for individual users or systems that meet specific criteria, while maintaining more generic policies across your System Tree. This level of granularity in policy assignment limits the instances of broken inheritance in the System Tree needed to accommodate the policy settings that specific users or systems require.&#x20;

Policy assignments are based on user-specific or system-specific criteria.

* System-based rules:
  * Assigned to managed systems
  * Assigned priority, which can be changed
  * Cannot include user-based criteria
* User-based rules:
  * Assigned to groups, organizational units, or user names
  * Can include system-based criteria
  * Enforced when users log into the network

### Creating Policy Assignment Rules <a href="#card-title-53" id="card-title-53"></a>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2F3AevLR3P38LAGcTIuE75%2Fimage.png?alt=media&amp;token=c968be3e-8f1e-4ace-818f-c056cb2c05f6" alt="" width="320"><figcaption><p>Complete these steps from the Policy Assignment rules page.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FiTGAdfkTADmeLK4ah785%2Fimage.png?alt=media&amp;token=2c318909-8b5f-4b85-8782-fe5265d54d61" alt=""><figcaption></figcaption></figure>

Click the **New Assignment Rule** button at the top of the page to launch the Policy Assignment Builder. Your first step is to enter rule details (Name and Description), then click **Next**.

**Note**: By default, the priority for new policy assignment rules is assigned sequentially based on the number of existing rules. You can edit the priority of this and any rule by clicking **Edit Priority** on the Policy Assignment Rules page.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FaizmV8SCbAXD2F2FaiJ1%2Fimage.png?alt=media&amp;token=e2d6dade-b487-43a9-94e0-6a9a86f97d99" alt=""><figcaption></figcaption></figure>

From the Assigned Policies page, click **Add Policy** and select the policies to be applied. Click the plus sign (**+**) to add another policy. Click the minus sign (**-**) to remove a policy. Click **Next** to continue.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2F72VExyV6NivxVzuRgIK8%2Fimage.png?alt=media&amp;token=9265237b-f4ee-4291-a545-6370bf6e0c34" alt="" width="563"><figcaption></figcaption></figure>

From the Selection Criteria page, choose the criteria for this assignment (**Comparison** and **Value**).

Apply any additional **Available Properties** from the left pane, then click **Next**.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2Fc9BoXpp1NESdVwnTNogM%2Fimage.png?alt=media&amp;token=6d9f41d0-d23c-4736-bece-8cf201fd78e0" alt=""><figcaption></figcaption></figure>

From the Summary page, review the rule configuration. Click **Back** to make changes to prior screens. When satisfied with the configuration, click the **Save** button in the bottom right corner of the page.

#### **Policy Assignment Rules Priority**

Policy assignment rules can be prioritized to simplify maintenance of policy assignment management. When you set priority to a rule, it is enforced before other assignments that have a lower priority.

By default, the priority for new policy assignment rules is assigned sequentially, based on the number of existing rules.&#x20;

You can edit the priority of this, or any, rule by clicking **Edit Priority** on the Policy Assignment Rules page.

In some cases, the outcome can be that some rule settings are overridden; for example, consider a user or system that is included in two policy assignment rules, Rules A and B. Rule A has priority level 1 and allows included users unrestricted access to internet content. Rule B has priority level 2 and heavily restricts the same user's access to internet content. In this scenario, Rule A is enforced because it has higher priority. As a result, the user has unrestricted access to internet content.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2F7o6ZLEbVhIZYxLo1Chkm%2Fimage.png?alt=media&amp;token=34b78999-b0ab-4225-bbe5-057fa687e83b" alt=""><figcaption></figcaption></figure>

#### **Resetting Broken Inheritance**

<figure><img src="https://training.trellix.com/content/elearningngx/3LFlnPIoN1Ptoj2jNrEF-g/1694487374/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==TW9uIFNlcCAxMSAxNDo1NjoxNCBFRFQgMjAyMw==/eot/scormcontent/assets/GmPVJu2Mt1kBIFqq_g4HsbncZ-_5gyzbu.png" alt=""><figcaption></figcaption></figure>

1. From the **System Tree** > **Assigned Policies** tab:

   Locate the **Broken Inheritance** column on the right. This column displays the number of groups and systems where this policy's inheritance is broken.&#x20;

   **Example**: If only one group does not inherit the policy, this is represented by *1 doesn't inherit*, regardless of the number of systems within the group.&#x20;
2. Click the link indicating the number of child groups or systems that have broken inheritance. The Broken Inheritance page displays a list of the names of these groups and systems.&#x20;
3. To reset the inheritance of any of these, mark the checkbox next to the name, then click **Actions** > **Reset Inheritance**.

{% hint style="info" %}
You can also click the **Edit Assignment** link, the **Broken Inheritance** link, then **Actions** > **Reset Inheritance**.
{% endhint %}

### **Policy Enforcement**

Policy enforcement is an inherited property that is independent from policy assignment. It is inherited from the System Tree root (My Organization) unless inheritance is turned off. By default, when assigned, all policies have an Enforcement status of **Enforcing**.

<figure><img src="https://training.trellix.com/content/elearningngx/3LFlnPIoN1Ptoj2jNrEF-g/1694487374/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==TW9uIFNlcCAxMSAxNDo1NjoxNCBFRFQgMjAyMw==/eot/scormcontent/assets/Spn9diIOuT7JBHNU_CUtxs38UGaaGAe_z.png" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**If a policy is not enforced, it will not be implemented by the Trellix Agent. This means that, although the managed system has received the policy assigned to it, that policy will not be applied on the system.**
{% endhint %}

Policies are enforced when:&#x20;

* The agent communicates with the ePO server or the Agent Handler at the configured\
  agent-to-server communications interval (ASCI)
* You send an Agent Wake Up call from the ePO server (updates and enforces policies on the client)
* In addition, if the client end user has access to the Trellix Agent Status Monitor (set by the policy), the user can click the Check New Policies button to initiate communication and enforce policy changes.

When you reconfigure policy settings, the new settings are delivered to and enforced on the managed systems at the next agent-server communication. The frequency of this communication is determined by the Agent-to-server-communication interval (ASCI) settings on the General tab of the Trellix Agent policy pages or the Trellix Agent Wakeup client task schedule (depending on how you implement agent-server communication). By default, this interval is set to occur once every 60 minutes.

Once the policy settings are in effect on the managed system, the agent continues to enforce local policy settings at a regular interval. This enforcement interval is determined by the Policy enforcement interval setting on the General tab of the Trellix Agent policy pages. By default, this interval is set to occur every 60 minutes.&#x20;

<figure><img src="https://training.trellix.com/content/elearningngx/3LFlnPIoN1Ptoj2jNrEF-g/1694487374/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==TW9uIFNlcCAxMSAxNDo1NjoxNCBFRFQgMjAyMw==/eot/scormcontent/assets/yD26rcEQBLYfxYYP_XdZFyIudAEb2DNVG.png" alt=""><figcaption></figcaption></figure>

### **Policy Comparison**

### Introduction <a href="#card-title-59" id="card-title-59"></a>

The Policy Comparison feature lets you compare similar policies. This helps to determine which settings are different and which settings are the same.

Many of the values and variables included in Policy Comparison are specific to each product. For product policies not included in the table, see the documentation for the product that provides the policy that you want to compare.

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FcDf0l7zdZLrByY6DwMWM%2Fimage.png?alt=media&amp;token=0c7df60a-a466-4886-9570-802d17179ef9" alt="" width="310"><figcaption><p>Click <strong>Menu</strong> > <strong>Policy</strong> > <strong>Policy Comparison</strong>, then select a product and category from the lists. </p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2F67KU2746adjmWb92NXUW%2Fimage.png?alt=media&amp;token=2a7ae7ad-afd7-4cf3-b5b9-965a56b14078" alt="" width="563"><figcaption><p>Select <strong>Show Only Differences</strong> or <strong>Show All Settings</strong>. These settings populate the policies to compare in the <strong>Policy 1</strong> and <strong>Policy 2</strong> lists. </p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2Fpc2JD2OzmBRpXv3azXFV%2Fimage.png?alt=media&amp;token=65df8a15-c3ee-4a49-8804-2fa8109644b8" alt="" width="563"><figcaption><p>Select the policies to compare in the row from the <strong>Policy 1</strong> and the <strong>Policy 2</strong> column lists. The top two rows of the table display the number of settings that are different and identical.</p></figcaption></figure>

<figure><img src="https://3241386954-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FjmsGhOHPrgQSX87jFLLt%2Fuploads%2FWYFiyrQVnlDLenBSSvt0%2Fimage.png?alt=media&amp;token=3f766190-bec9-4d43-beed-341fb0b4604c" alt="" width="563"><figcaption><p>Click <strong>Print</strong> in the bottom right corner of the screen to open a printer-friendly view of this comparison.</p></figcaption></figure>

### Summary <a href="#card-title-64" id="card-title-64"></a>

<figure><img src="https://training.trellix.com/content/elearningngx/3LFlnPIoN1Ptoj2jNrEF-g/1694487374/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==TW9uIFNlcCAxMSAxNDo1NjoxNCBFRFQgMjAyMw==/eot/scormcontent/assets/lAyGybGvZutGqD5b_Q2pRTWwl-Hyk6_jz.png" alt="" width="563"><figcaption></figcaption></figure>

The **Show All Settings** / **Show Only Differences** options populate the policies to compare in the Policy 1 and Policy 2 lists.&#x20;

The Show Only Differences option, when selected, shows only the policy changes between the two policies being compared, providing a quick look at what’s different between the two policies.

**Policy History**

When you change a policy from the Policy Catalog, a Policy History entry is created where you can describe the change for future reference. Policy History entries display in three places:

* Policy History
* Server Task Log Details
* Audit Log Details

Only polices you create in the Policy Catalog have Policy History entries.

<figure><img src="https://training.trellix.com/content/elearningngx/3LFlnPIoN1Ptoj2jNrEF-g/1694487374/0088YmZiUEJFNUlneVVCNnVIVG9rc3ZsOUtjbnk2Yk5iN1AvYUNTQWlxV0NxUVIvbzFnKzYwdnFDczFXSmY3TEk0Rw==TW9uIFNlcCAxMSAxNDo1NjoxNCBFRFQgMjAyMw==/eot/scormcontent/assets/99RZ7i6eNMxI0oaI_rXaMFVQyid_zUKye.png" alt="" width="563"><figcaption></figcaption></figure>

1. To view the Policy History, select **Menu** > **Policy** > **Policy History**.\
   **Note**: No Policy History entries display for McAfee Default policies. You might need to use the page filter to select a created or duplicated McAfee Default policy.
2. Use the **Product**, **Category**, and **Name** filters to select Policy History entries.
3. To manage a policy or Policy History entry, click **Actions**, then select an action.
   * **Choose Columns:** Opens a dialog box that allows you to select which columns to display.
   * **Compare Policy:** Opens the Policy Comparison page, where you can compare two selected policies. The current version of a policy has the latest date. To compare the current revision of a policy and a previous policy revision, select the latest revision and a previous revision.
   * **Export Table**: Opens the Export page, where you can specify the package and format of Policy History entry files to export, then email the file.
   * **Revert Policy**: Reverts the policy to the selected policy version. You can select only one target policy.

{% hint style="info" %}
Make sure that you leave a comment when you revise a policy. Consistent commenting creates a strong history of your changes.

To record policy revisions, enter a comment in the text field next to **Duplicate** in the footer of the **Policy Catalog** page.
{% endhint %}
