Zones that are used for device policy assignment

Zones that are used for assigning device policies need to be organized and created in a specific order based on the ranking of the associated policy. This ensures the most desired policy is assigned to devices, especially if devices are members of multiple zones. This is good practice even if the zones you use for policy assignment are designed to not have overlapping devices.

Higher-ranked devices should be assigned a higher-ranked policy, which is considered to have more restrictive settings and should generally be used to protect your more critical endpoints. Likewise, lower-ranked devices would be assigned a lower-ranked policy, which has less restrictive settings for less critical endpoints.

For example, your organization may have your endpoints organized and ranked in this way:

Highest-ranked devices (most restrictive device policy)

Servers

Workstations for Executives

Workstations for HQ

Point of Sale Devices in Texas

Contractors

Lowest-ranked devices (least restrictive device policy)

The order in which you create zones for each rank of devices should be from the lowest rank to the highest rank. In the example above, you might notice some devices could potentially overlap between the zones for "Workstations at HQ" and "Workstations for Executives". It is important to create the zones in the correct order, so that devices in the "Workstations for Executives" zone receives a more restrictive policy.