Assign a policy to devices
Scope a policy to specific devices, users, or groups using tags and selectors
Assign a policy to devices
Policies in Threatmatic are assigned through tags and selectors — not by naming devices individually. This keeps assignments dynamic: as devices join or leave a tag group, policy coverage updates automatically.
Prerequisites
- An existing policy (see Create your first policy)
- Enrolled devices with tags applied
Steps
Open the policy
- Go to Console → Policies
- Click the policy you want to assign
Set device selectors
Under Device Selectors, click Add Selector and enter one or more device tags.
A device receives the policy if it matches any selector.
Examples:
| Selector tags | Devices covered |
|---|---|
managed | All managed endpoints |
dept=finance | Finance department devices |
role=contractor | Contractor devices only |
env=prod | Production servers |
Set user selectors (optional)
Under User Selectors, add user group tags to further narrow the scope. When both device and user selectors are set, both must match for the policy to apply.
Set weight (priority)
The Weight determines evaluation order when multiple policies apply to the same device. Lower weight = higher priority.
| Weight | Use case |
|---|---|
100 | Critical blocks (highest priority) |
500 | Standard access rules |
900 | Catch-all / default rules |
Save
Click Save. The assignment takes effect on all matched devices within seconds.
Verify
- Go to Console → Devices
- Open a device that matches the selector
- Under Policies, confirm the policy appears as active
Remove an assignment
To stop a policy applying to a device, either:
- Remove the matching tag from the device, or
- Remove the selector from the policy
The policy is withdrawn automatically on the next sync — no restart required.
Next steps
How is this guide?
Last updated on