Work with policies
For information about policy types, permissions, targeting, and priority, see How policies work.
- Policies can only target existing tags. If you haven’t created tags, create them before configuring policies. For details, see Manage tag definitions and Manage tags.
- In this release, policies can be created only at the service organization level.
- Only tags created in the same service organization as the policy are available for targeting.
- Access to policy management requires an N-able user account that is linked to N-able SSO.
Create a policy
Use this task to create a patch policy and save it as Ready to deploy. The policy does not affect devices until you deploy it.
Before you begin
Make sure you have:
- Write access to policies.
- Access to the target service organization.
To create a policy:
- Go to Policies.
- Select the service organization where you want to create the policy.
- On the Policies page, select Add policy.
- Select the type of policy you want to create. The configuration wizard contains multiple tabs. Select each tab to review and update the available settings.
- On the Add policy page, enter a Name , and Description, and then select Next.
-
Policy names must be unique within a service organization for each policy type.
- On the Configuration page, configure the policy rules. Select Next.
-
On the Tags page, select the tags to target for the policy.
- Select the required tags under Available and move them to Assigned.
A tag cannot be targeted by more than one policy of the same type.
- Review the policy settings, and then select Confirm to create the policy.
What to do next
Deploy the policy to apply its configuration to tagged devices. For more information, see Deploy a policy.
- The system assigns the lowest priority to new policies by default.
- You can create multiple policies and deploy them later.
- If a tag already targets a policy of the same type, you’ll be prompted to replace it before saving the configuration.
Deploy a policy
Newly created policies start in a Ready to deploy state. A policy does not affect assets until you deploy it.
You must deploy a policy after you:
- Create a new policy
- Update an existing policy
- Target the policy to new tags
- Remove the policy by unassigning tags
- Mark a policy for deletion.
You can deploy multiple policies that are in a Ready to deploy state at the same time.
Automatic redeployment
If targeting changes after a policy is deployed, the system automatically re-deploys it. This ensures that assets always reflect the correct policy state without requiring manual redeployment.
Automatic redeployment occurs when:
- Assets are added to or removed from tags
- Rules for dynamic tags change
Automatic redeployment does not introduce new policy settings. It reapplies the existing deployed configuration to the correct set of assets based on current tags.
To deploy a policy:
- Go to Policies.
- Select the service organization where you want to deploy the policy.
- From the Actions menu, select Deploy policies. The policies in the list are deployed to devices associated with the tags.
Policy deployment may take a few moments. Once deployment completes successfully, the status of all policies changes to Deployed.
Edit a policy
Use this task to update the settings or tag targets of an existing policy. Editing a policy does not change its priority and does not apply changes until the policy is deployed.
Before you begin
Make sure you have:
- Write access to the policy type
- Access to the service organization where the policy is created
To edit a policy:
- Go to Policies.
- On the Policies page, select the service organization.
- Locate the policy you want to change. From the Actions menu, select Edit. In the Settings panel, review each tab and update the settings as needed:
- Details
- Update the Name or Description.
- Configuration
- Update the rules for the policy.
- Tags
- Update tag assignments by moving tags between Available and Assigned.
- Details
- Select Save to apply your changes.
The policy is updated and returned to the Ready to deploy state.
What to do next
Deploy the policy to apply your changes to devices. For more information, see Deploy a policy.
- Editing a policy does not automatically deploy the changes. You must deploy the policy again.
- If you add or change tags, deploy the policy so that the targeted devices receive the updated configuration.
- If you remove tags, the policy no longer targets devices with those tags after deployment.
Prioritize a policy
Policies run in priority order. The Order column shows each policy's priority. You can reorder policies or change the priority of a specific policy.
To change a policy's priority:
- Select the Actions menu for the policy.
- Select Change order.
- Do one of the following:
- Select Move up or Move down to adjust the priority one position at a time.
- Select Set order to assign an order of priority for all policies at once.
Policies at the top of the list have a higher priority than policies lower in the list.
Delete a policy
Delete a policy to remove its configuration from all associated devices. When a policy is deleted, other applicable policies may take effect automatically.
Before you begin
Make sure you have:
- Write access to delete policies.
- Access to the service organization where a policy is to be deleted.
To delete a policy:
- Go to Policies.
- On the Policies page, select the service organization. Locate the policy you want to delete.
- From the Actions menu for the policy, select Delete. When prompted, select the checkbox and select Delete again to confirm deletion.
- If the policy was previously deployed, its status changes to Pending deletion. The policy remains applied to assets until you deploy the deletion.
- If the policy was not deployed, it is removed from the policy grid when you deploy the deletion.
- After marking one or more policies for deletion, select Deploy from the Actions menu to permanently remove the policy and withdraw it from targeted assets.
If the policy was not deployed, it is simply removed from the policy grid.
There is no way to revert a policy from a Marked for delete state to a Deployed or Ready to deploy state. Deleted policies are permanently removed from view but retained in the system for audit and recovery purposes.
View assets targeted by a policy
View the assets that are targeted by a policy to understand which configuration is in effect and why. If multiple policies apply, priority determines the final configuration.
Before you begin
Make sure you have:
- Read access to policies.
- Access to the service organization the policy belongs to.
To view a policy:
- Go to Policies.
- On the Policies page, select the service organization. The list of available policies for the organization are displayed.
- Review the Tags column to see which tags are assigned to each policy.
- Select a policy to see the targeted assets.
- Under the Summary tab, see the list of targeted assets.
