Security Policies hub
Navigate entitled policy areas, apply organization or device-group scope, and validate endpoint enforcement.
Security Policies hub
Overview → Security Policies is the central policy workspace. Each visible tab identifies What this policy enforces and Applied by so operators can connect a setting to its enforcement component.
Access and entitlement
The page appears when the organization has at least one enabled module. Tabs are entitlement-driven:
- TAO Agent - Windows endpoint hardening (organization-wide).
- GenGuard - keyword blocking, domain allow/block lists, browsing categories, and TAO endpoint GenGuard.
- VisionX - visual-channel risk (phones, cameras, lenses), lock-on-detection, evidence capture, unlock code, and activation.
- Vault / PAM / IPS - password rotation, Personal Vault limits, HostGuard IPS, and publishing the employee File Vault.
- ZeroDevice - USB/BT peripheral learning, approve/reject, and challenge controls.
The TAO Agent tab may appear with several endpoint-related entitlements, not only a separately named TAO entitlement. Vault users have a sidebar limited to Secure Vault. Other role labels indicate intended responsibility; follow your organization’s change-approval policy even when controls are visible.
Organization vs device group
For VisionX, ZeroDevice, GenGuard, and HostGuard IPS, use Apply this policy to at the top of the tab:
| Scope | Effect |
|---|---|
| All devices (organization) | Default policy for the whole tenant |
| A device group | Override for devices in that group (same form controls) |
Create and assign groups under Managed devices. Each device has one primary group. Nested folders inherit parent overrides: organization → parent group → child group. ZeroDevice can still apply a per-station exception on top.
Always organization-wide (no group selector): TAO Agent hardening, PAM rotation interval, and Vault file/share limits.
The Cloud Portal merges the effective policy before TAO downloads it. Agents receive the same policy document shape as before; no TAO reinstall is required for group targeting.
Controlled policy workflow
- Obtain approval and record the current policy state.
- Open Security Policies.
- Select the entitled policy tab.
- Choose All devices (organization) or a device group when the selector is available.
- Read What this policy enforces and Applied by.
- Change only the approved fields. Avoid combining unrelated policy changes.
- Use the panel’s exact save control and wait for its success message.
- Refresh the page and confirm the saved values remain selected.
- Allow the enforcing agent or extension to refresh.
- Validate on a pilot endpoint in that scope and in the related event or device view.
- Review Audit Logs for the policy update when the workflow emits an audit record.
Tab-specific validation
TAO Agent
Use Save endpoint hardening. The success message states that agents refresh on the next heartbeat. Validate the device’s policy version and expected local behavior. See TAO endpoint hardening.
GenGuard
After saving, validate an approved allowed case and an approved blocked case. Use Browser Protection → Live Events to confirm reporting. For a group save, GenGuard-inside-TAO receives the merged override; the browser extension remains organization-scoped. Do not test with production-sensitive data.
VisionX
Validate the selected activation and enforcement behavior on a controlled endpoint in the chosen scope. In Managed devices, review VisionX health and Details, including camera, model, session, activation, and unlock-code readiness.
Vault / PAM / IPS
Organization scope saves IPS, PAM rotation, and Vault file/share rules together. Group scope edits HostGuard IPS only — PAM and Vault file rules stay organization-wide. Validate only on a designated test asset. After publishing Organization File Vault, confirm the employee login at /org-vault/login and that a TCP account cannot use it.
See Organization File Vault for employees.
ZeroDevice
Save learning/enforcing mode and class defaults for the selected scope. Use ZeroDevice → Stations for per-host exceptions when a single endpoint needs different rules.
Troubleshooting
No policy modules enabled
Confirm you are in the correct organization and that the expected subscription modules are enabled. Select Open Deployment Center only after entitlement is confirmed.
An expected tab is missing
Check module entitlement and the user’s role. Missing tabs generally indicate the corresponding module is not enabled; Vault users intentionally do not receive the general sidebar.
The requested tab changes to another tab
If a bookmarked tab is not entitled, the hub selects the first visible tab. Confirm the organization’s modules instead of repeatedly using the old link.
Group selector is empty
Create groups and assign devices under Managed devices, then return to Security Policies.
A change saves but the endpoint does not update
Confirm the endpoint is Online, has a recent heartbeat, runs the expected enforcing component, and reports an updated policy version. Refresh Managed devices and inspect module health. For group saves, confirm the device is a member of that group.
Security notes
- Use peer review for high-impact enforcement, unlock, uninstall, and rotation changes.
- Pilot a group override on a small folder before applying it broadly.
- Never place unlock codes, uninstall codes, credentials, or sensitive evidence in change tickets.
- Treat Applied by as a prerequisite: a saved cloud setting cannot enforce through a missing or unhealthy agent.
