This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Application Control Policy - Do I Allow or clone?

My Baseline Application Policy policy has various categories blocked.  Works well. Now I want some IT team members to have access to a few apps that are blocked by the Baselines Application Policy. So, do I either

a) clone the Baseline policy, unselect the apps I want to allow, assign policy to IT Team member and place above the Baseline policy

b) create an Allow policy including only the apps I want to allow,. assign policy to the IT Team members and  place it above the Baseline policy

My worry about method (a) is that if I want to allow different apps for different people, it's going to get very messy with various cloned baseline policies with different lists of blocked applications. Method (b) would be simpler to manage but the Detection Option settings suggest I'll get alerted every time they access an Allowed application. 



This thread was automatically locked due to age.
Parents
  • Hello Simeon Lewis,

    by default all applications are allowed. As only one policy wins (i.e. policies are not merged) you can't use an allow for this group what would otherwise be blocked policy, you have to use method a). Please note it's a Base policy - the policy in effect if no other policy applies -  not Baseline.

    Christian

Reply
  • Hello Simeon Lewis,

    by default all applications are allowed. As only one policy wins (i.e. policies are not merged) you can't use an allow for this group what would otherwise be blocked policy, you have to use method a). Please note it's a Base policy - the policy in effect if no other policy applies -  not Baseline.

    Christian

Children
No Data