Policies decide how aggressively the EDR agent protects each machine and what it's allowed to do. Group your fleet and apply consistent settings instead of configuring devices one by one.
Policy groups
Organize devices into groups and give each a policy:
| Group | Typical posture |
|---|---|
| Servers | Maximum prevention; strict device control; no user override. |
| Workstations | Balanced prevention; USB restricted; standard user rights. |
| Executives / high-risk | Strictest prevention and monitoring. |
| Kiosks / shared | Locked down; removable media blocked. |
Devices inherit their group's policy automatically as they enroll. Policy state then sits beside cross-vendor endpoint protection status — agent health, AV/EDR state, and endpoint risk — so a machine that drifts off its group is visible without opening it.
What a policy controls
- Prevention level — how aggressively to block versus detect-and-alert.
- Device control — allow, read-only, or block USB and removable media.
- Firewall posture — required host-firewall state.
- Disk encryption — check (and report) BitLocker/FileVault status.
- Allow/deny lists — exceptions for known-good apps or hashes.
- Tamper protection — prevent users or malware from disabling the agent.
Roll out changes safely
Test on a pilot group
Apply the change to a small pilot group first and watch for false positives in the Network Portal.
Stage the rollout
Promote to broader groups in waves rather than the whole fleet at once.
Monitor and tune
Add allow-list exceptions for legitimate business apps the new level flags, then continue the rollout.
Tip
Keep tamper protection on everywhere. A common attacker move after landing on a device is to try to disable the security agent — tamper protection stops that and turns the attempt itself into a detection.
