LogoThreatmatic
Policies

Assign a policy to devices

Scope a policy to specific devices, users, or groups using tags and selectors

Assign a policy to devices

Policies in Threatmatic are assigned through tags and selectors — not by naming devices individually. This keeps assignments dynamic: as devices join or leave a tag group, policy coverage updates automatically.

Prerequisites

Steps

Open the policy

  1. Go to Console → Policies
  2. Click the policy you want to assign

Set device selectors

Under Device Selectors, click Add Selector and enter one or more device tags.

A device receives the policy if it matches any selector.

Examples:

Selector tagsDevices covered
managedAll managed endpoints
dept=financeFinance department devices
role=contractorContractor devices only
env=prodProduction servers

Set user selectors (optional)

Under User Selectors, add user group tags to further narrow the scope. When both device and user selectors are set, both must match for the policy to apply.

Set weight (priority)

The Weight determines evaluation order when multiple policies apply to the same device. Lower weight = higher priority.

WeightUse case
100Critical blocks (highest priority)
500Standard access rules
900Catch-all / default rules

Save

Click Save. The assignment takes effect on all matched devices within seconds.

Verify

  1. Go to Console → Devices
  2. Open a device that matches the selector
  3. Under Policies, confirm the policy appears as active

Remove an assignment

To stop a policy applying to a device, either:

  • Remove the matching tag from the device, or
  • Remove the selector from the policy

The policy is withdrawn automatically on the next sync — no restart required.

Next steps

How is this guide?

Last updated on

On this page