Zones that are used for device policy assignment
Zones that are used for assigning device policies need to be organized and created in a specific order based on the ranking of the associated policy. This ensures the most desired policy is assigned to devices, especially if devices are members of multiple zones. This is good practice even if the zones you use for policy assignment are designed to not have overlapping devices.
Higher-ranked devices should be assigned a higher-ranked policy, which is considered to have more restrictive settings and should generally be used to protect your more critical endpoints. Likewise, lower-ranked devices would be assigned a lower-ranked policy, which has less restrictive settings for less critical endpoints.
|
Highest-ranked devices (most restrictive device policy) |
|
Servers |
|
Workstations for Executives |
|
Workstations for HQ |
|
Point of Sale Devices in Texas |
|
Contractors |
|
Lowest-ranked devices (least restrictive device policy) |
The order in which you create zones for each rank of devices should be from the lowest rank to the highest rank. In the example above, you might notice some devices could potentially overlap between the zones for "Workstations at HQ" and "Workstations for Executives". It is important to create the zones in the correct order, so that devices in the "Workstations for Executives" zone receives a more restrictive policy.