Skip to main content

Security Policies

Security Policies apply Windows GPO-style hardening controls to your endpoints

  • desktop and Explorer restrictions, Internet Explorer settings, network and system controls, taskbar and Start-menu lockdowns, and many more. A policy is a named bundle of those controls, each set to Enable, Disable, or Not Configured.
Edition & permission

Device Control is EndpointOps edition. You need View Security Policies permission.

How to get here

  1. In the left sidebar, click Device Control.
  2. Click the Security Policies card.

Navigate to: Device Control → Security Policies → Policies

URL path: /device-control/security-policy-settings/policies

The Policies screen

The Security Policies listThe Security Policies list
ColumnWhat it shows
NameThe policy name.
DescriptionWhat it's for.
Configuration LevelComputer or User.
Created TimeWhen it was created.

Create adds a policy; rows have Edit and Delete.

How do I create a policy?

Click Create. The form opens in a wide drawer.

The Create Security Policy formThe Create Security Policy form
FieldRequiredNotes
NameYesThe policy name.
DescriptionNoWhat it's for.
Configuration LevelYesComputer or User.
PoliciesNoThe individual controls, grouped into tabs.

The controls are organised into tabbed groups (Desktop, Explorer, Internet Explorer, Network, System, Taskbar / Start Menu, and more). Each control- for example "Hide and disable all items on the desktop" or "Remove My Computer icon on the desktop"- is set to Enable, Disable, or Not Configured.

Save to add the policy, then deploy it.

Tips & troubleshooting

  • Not Configured leaves a setting alone. Only Enable / Disable controls change the endpoint; Not Configured means "don't touch it".