×
×
×
×

Device Control Policy Deployment

Deploy device control rules to computer groups so peripheral-device restrictions and monitoring take effect on matching endpoints.

Prerequisites
Create the device control rule before starting its deployment.

Targeting

Associate a policy with a computer group

Choose the computer group that should receive the device control policy.

Open policy deployment

  1. Navigate to Policies → Deploy Policy → Associate Policy.
    Associate Policy page for Device Control policy deployment
    Open the policy-association workflow.
  2. Select the computer group to associate with the policy.
    Computer group selection for a Device Control policy
    Select the computer group that should receive the policy.
Note
Within the selected computer group, the policy applies only to computers whose operating-system platform matches the policy.

If you need to define a target first, review how to create custom computer groups.

Deployment

Select and deploy the policy

Move the required policy into the selected set, then choose when deployment begins.

Choose the policy

Move the policy you want to associate from Available Policies to Selected Policies.

Choose the deployment method

  • Select Deploy to apply the policy during the next refresh cycle.
  • Select Deploy immediately to begin policy deployment immediately.

Exceptions

Exclude user groups

Remove selected user groups from a policy that is associated with a computer group.

Select the excluded groups

  1. Select the computer group and the required policy, then select the exclude user group button.
    Exclude user group action for an associated Device Control policy
    Open user-group exclusions for the selected policy.
  2. Select the user group or groups to exclude from the policy.
    User group selection for Device Control policy exclusion
    Select the user groups that the policy should exclude.

Related