Applying a policy to a device group

After creating a device group, you must apply a policy or a policy group to enforce policy rules to protect devices in the group. A group must have a security policy applied to it. All devices within the device group receive the policy.
If you apply a Host Integrity policy to a device group, you are required to enter a one-time PIN that is sent to your email address. A PIN is also required if a Host Integrity policy is part of a policy group that is applied to a device or device group.
The default policy is automatically applied to the default group so that devices are protected immediately after you deploy the client on a device.
When you apply a policy to a multi-platform device group, only applicable policies are targeted to the devices as per their platform.
  1. To apply a policy to a device group (from the Policies page)
  2. Go to
  3. On the
    tab, select a policy, and select
  4. In the
    Group Hierarchy
    pane, select the device group(s) that should use the policy.
    A device group can be associated with only one policy at a time of the same policy type. If you select a device group that is associated with another policy of the same policy type, you receive a message prompt to override the device group conflict. Selecting
    removes the existing policy and applies the current policy to the device group.
  5. Select
To apply a policy to a device group (from the Devices page)
  1. Go to
  2. On the
    Device Groups
    tab, select a group.
  3. Select
    Apply Policy
  4. Select one or more policies, and select
More information