Skip to main content

File Access Control- Policies

File Access Control governs who can read, write, or change specific files, folders, and registry keys on your endpoints. A policy is a list of access actions, each granting or revoking permissions on one target.

Edition & permission

Device Control is EndpointOps edition. You need View File Access Control permission.

How to get here

  1. In the left sidebar, click Device Control.
  2. Click the File Access Control card.

Navigate to: Device Control → File Access Control → Policies

URL path: /device-control/file-access-control-settings/policies

The Policies screen

The File Access Control policies listThe File Access Control policies list
ColumnWhat it shows
NameThe policy name.
DescriptionWhat it's for.
Configuration LevelComputer or User.
Actions CountHow many access actions the policy carries.
Created TimeWhen it was created.

Create adds a policy; rows have Edit and Delete.

How do I create a policy?

Click Create. The form opens in a drawer.

The Create File Access Control policy formThe Create File Access Control policy form
FieldRequiredNotes
NameYesThe policy name.
Configuration LevelYesComputer or User.
DescriptionNoWhat it's for.
ActionsYesOne or more access actions- click Add Access Control Action.
Apply On Startup / User LoginNoWhen the policy takes effect (label follows the level).

Each action targets a File, Folder, or Registry key:

  • File / Folder- the Path, the User/Group it applies to, an Action (Append / Overwrite / Revoke), an Inheritance scope, and a permissions table (Allow/Deny Read, Write, Execute, Modify, Full Control).
  • Registry- the Hive Key (HKLM, HKCU, etc.) and Key path, the User/Group, the Action, a registry Inheritance scope, and a permissions table (Allow/Deny Read, Full Control).

Save to add the policy, then deploy it.