Frequently Asked Questions
What does an Access Control Policy actually control?
A policy holds one or more device type rules, each pairing a Device Type with an
Access Level. Device types available in the dropdown include Printers, Bluetooth
Adapters, Biometric Devices, Imaging Devices, Modems, Keyboards, Mouses, Smart
Card Readers, Tape Drives, Wireless Network Adapters, Floppy Disks, Infrared
Devices, and Removable Storage. Each policy also has a Name and an optional
Description.
What are the available Access Levels?
Four options: Allow, Block, Allow Trusted Devices, and No Change. No Change is
the default on a newly added rule, so a rule left at that setting is saved but
enforces nothing. Selecting Allow Trusted Devices reveals a Trusted Devices
field for choosing which registered devices remain permitted.
Can one policy cover more than one device type?
Yes. The Add Rule button adds another Device Type Rule to the same policy, so a
single policy can block one device class, allow another, and leave a third
unchanged.
How is a trusted device identified?
A Trusted Device entry has a Name, Device Type, and optional Description, then an
Add Device By setting of IDs and Serial Number, with fields for Vendor ID,
Product ID, and Serial Number. Serial Number is optional, so an entry can cover
one specific unit or every device sharing that vendor and product pair.
How does Temporary Access differ from a Trusted Device?
Temporary Access is a time-limited exception for one endpoint rather than a
persistent hardware exemption. It takes a Name, Endpoint, and a Duration Type of
either Fixed Duration (a Duration Value and Duration Unit such as Hours) or Time
Window (an explicit start and end time), plus one or more Allowed Devices with a
Device Type and an Allowed For setting such as All Instances. Entries show a
status of Pending or Expired and can be revoked, edited, or deleted from the list.
How do I push an Access Control Policy to specific machines?
From Deployments, create a new deployment, set the Scope to Specific Endpoints
and choose the target endpoint(s), set the Deployment Type to Apply Policy, then
select the Device Access Control Policy, a Deployment Policy, and who to notify
before publishing. Save As Draft is available if the scope still needs review.
How do I confirm a deployment succeeded?
The Deployments list shows each entry's Type (Apply or Remove), Stage (such as
Initiated or Completed), and Progress (such as 1/1). Opening a deployment's Tasks
view shows the Status per targeted endpoint, moving from Ready to Deploy to
Success, and each task has an Output view with a timestamped execution log
confirming the policy was applied.