McAfee EPOCDE-AA-BA Product Guide - Page 165

Policy application, permissions. Assignment locking prevents other users

Page 165 highlights

Using policies to manage products and systems Policy application 15 Exporting and importing policies If you have multiple servers, you can export and import policies between them via XML files. In such an environment, you only need to create a policy once. You can export and import individual policies, or all policies for a given product. This feature can also be used to back up policies if you need to reinstall the server. Policy sharing Policy sharing is another way to transfer policies between servers. Sharing policies allows you to manage policies on one server, and use them on many additional servers all through the McAfee ePO console. For more information, see Sharing policies among McAfee ePO servers. Policy application Policies are applied to any system by one of two methods, inheritance or assignment. Inheritance Inheritance determines whether the policy settings and client tasks for a group or system are taken from its parent. By default, inheritance is enabled throughout the System Tree. When you break this inheritance by assigning a new policy anywhere in the System Tree, all child groups and systems that are set to inherit the policy from this assignment point do so. Assignment You can assign any policy in the Policy Catalog to any group or system, provided you have the appropriate permissions. Assignment allows you to define policy settings once for a specific need, then apply the policy to multiple locations. When you assign a new policy to a particular group of the System Tree, all child groups and systems that are set to inherit the policy from this assignment point do so. Assignment locking You can lock the assignment of a policy on any group or system, provided you have the appropriate permissions. Assignment locking prevents other users: • With appropriate permissions at the same level of the System Tree from inadvertently replacing a policy. • With lesser permissions (or the same permissions but at a lower level of the System Tree) from replacing the policy. Assignment locking is inherited with the policy settings. Assignment locking is valuable when you want to assign a certain policy at the top of the System Tree and ensure that no other users replace it anywhere in the System Tree. Assignment locking only locks the assignment of the policy, but does not prevent the policy owner from making changes to its settings. Therefore, if you intend to lock a policy assignment, make sure that you are the owner of the policy. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 165

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Exporting and importing policies
If you have multiple servers, you can export and import policies between them via XML files. In such
an environment, you only need to create a policy once.
You can export and import individual policies, or all policies for a given product.
This feature can also be used to back up policies if you need to reinstall the server.
Policy sharing
Policy sharing is another way to transfer policies between servers. Sharing policies allows you to
manage policies on one server, and use them on many additional servers all through the McAfee ePO
console. For more information, see
Sharing policies among McAfee ePO servers
.
Policy application
Policies are applied to any system by one of two methods,
inheritance
or
assignment
.
Inheritance
Inheritance determines whether the policy settings and client tasks for a group or system are taken
from its parent. By default, inheritance is enabled throughout the System Tree.
When you break this inheritance by assigning a new policy anywhere in the System Tree, all child
groups and systems that are set to inherit the policy from this assignment point do so.
Assignment
You can assign any policy in the Policy Catalog to any group or system, provided you have the
appropriate permissions. Assignment allows you to define policy settings once for a specific need, then
apply the policy to multiple locations.
When you assign a new policy to a particular group of the System Tree, all child groups and systems
that are set to inherit the policy from this assignment point do so.
Assignment locking
You can lock the assignment of a policy on any group or system, provided you have the appropriate
permissions. Assignment locking prevents other users:
With appropriate permissions at the same level of the System Tree from inadvertently replacing a
policy.
With lesser permissions (or the same permissions but at a lower level of the System Tree) from
replacing the policy.
Assignment locking is inherited with the policy settings.
Assignment locking is valuable when you want to assign a certain policy at the top of the System Tree
and ensure that no other users replace it anywhere in the System Tree.
Assignment locking only locks the assignment of the policy, but does not prevent the policy owner
from making changes to its settings. Therefore, if you intend to lock a policy assignment, make sure
that you are the owner of the policy.
Using policies to manage products and systems
Policy application
15
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
165