Next Topic

Previous Topic

Book Contents

Policy Management Overview

The Policy Management (KPM) module manages agent settings by policy.

  • Once policies are assigned to machines, machine groups or organizations, policies are propagated automatically, without further user intervention.
  • Each policy comprises sub-categories of agent settings called policy objects.
  • Policies can be assigned by machine ID, machine group, or organization. A view definition must be used to filter the machines affected by the policy.
  • Changing a machine's association with a machine group, organization, or view, causes the appropriate policies to be automatically re-deployed.
  • Multiple policies can be assigned to each machine. If policies conflict, policy assignment rules determine the policies that are obeyed or ignored.
  • A compliance cycle checks that each machine is in compliance with applied policies. VSA users can check the status of each machine to ensure it is in compliance with applied policies.
  • A policy can be overridden. A KPM policy override condition exists if agent settings for a machine have been set manually, outside of the KPM module. For example, making changes to the agent menu of a machine using the Agent Menu page in the Agent module sets up an override condition for that agent machine. KPM policies will be ignored from then on. Policy overrides can also be cleared.
  • Policies can be imported and exported using System > Import Center.

Additional Terms

  • Applying a policy means the changes made to its policy objects are marked for deployment. Deployment means the applied changes are propagated to target machines, based on the deployment interval set using the Settings page. Because deployment may take a while, the target machine might not be in compliance between the time the policy is applied and the policy is deployed.
  • Pending changes are changes to policies or policy objects that have been saved, but not yet applied.

Configuration

  1. Set general settings for the entire Policy Management module using the Settings page.
  2. Define agent setting policies using the Policies page.
  3. Apply policies to:
    • Organizations and machine groups using the Organizations / Machine Groups page.
    • Individual machines using the Machines page. You can also clear KPM policy overrides using this page, enabling applied policies to take effect.

    Note: Policies will begin propagating after the policies are applied.

  4. Monitor policy compliance using the Policy Matrix page and Dashboard page.
  5. Monitor Policy Management activity using the Logs page.

Note: See KPM System Requirements.

Functions

Description

Dashboard

Provides a dashboard view of Policy Management activities.

Logs

Displays a log of Policy Management module activity.

Policy Matrix

Displays the policy status of all machines your scope authorizes you to see. A policy status icon displays in the left most column for every machine on this page.

Policies

Defines agent settings by policy, including

  • Agent Menu
  • Agent Procedure
  • Alerts
  • Check-in
  • Credential
  • Distribute File - This policy object is not available in a SaaS-based VSA.
  • Logging
  • Machine Profile
  • Monitor Sets
  • Patch Settings
  • Protection
  • Remote Control
  • Working Directory

Settings

Schedules the interval for automatic deployment of all policies to all assigned machines.

Organizations / Machine Groups

Assigns policies to organizations and machine groups.

Machines

Assigns policies to individual machines.