Policy Application - McAfee EPOCDE-AA-BA - ePolicy Orchestrator - PC Product Manual

Product guide
Table of Contents

Advertisement

Exporting and importing policies
If you have multiple servers, you can export and import policies between them via XML files. In such
an environment, you only need to create a policy once.
You can export and import individual policies, or all policies for a given product.
This feature can also be used to back up policies if you need to reinstall the server.
Policy sharing
Policy sharing is another way to transfer policies between servers. Sharing policies allows you to
manage policies on one server, and use them on many additional servers all through the McAfee ePO
console. For more information, see Sharing policies among McAfee ePO servers.

Policy application

Policies are applied to any system by one of two methods, inheritance or assignment.
Inheritance
Inheritance determines whether the policy settings and client tasks for a group or system are taken
from its parent. By default, inheritance is enabled throughout the System Tree.
When you break this inheritance by assigning a new policy anywhere in the System Tree, all child
groups and systems that are set to inherit the policy from this assignment point do so.
Assignment
You can assign any policy in the Policy Catalog to any group or system, provided you have the
appropriate permissions. Assignment allows you to define policy settings once for a specific need, then
apply the policy to multiple locations.
When you assign a new policy to a particular group of the System Tree, all child groups and systems
that are set to inherit the policy from this assignment point do so.
Assignment locking
You can lock the assignment of a policy on any group or system, provided you have the appropriate
permissions. Assignment locking prevents other users:
With appropriate permissions at the same level of the System Tree from inadvertently replacing a
policy.
With lesser permissions (or the same permissions but at a lower level of the System Tree) from
replacing the policy.
Assignment locking is inherited with the policy settings.
Assignment locking is valuable when you want to assign a certain policy at the top of the System Tree
and ensure that no other users replace it anywhere in the System Tree.
Assignment locking only locks the assignment of the policy, but does not prevent the policy owner
from making changes to its settings. Therefore, if you intend to lock a policy assignment, make sure
that you are the owner of the policy.
Using policies to manage products and systems
®
®
McAfee
ePolicy Orchestrator
Policy application
4.6.0 Software Product Guide
15
165

Advertisement

Table of Contents
loading

This manual is also suitable for:

Epolicy orchestrator 4.6.0

Table of Contents