Assign devices to a zone
Control which enrolled devices can reach a zone using tags and device selectors
Assign devices to a zone
Zones use device selectors to determine which enrolled devices can connect. Selectors match devices by tag, so you assign devices to a zone by tagging them — not by naming them individually.
Prerequisites
- An existing zone (see Create a zone)
- Enrolled devices with tags applied
Steps
Open the zone
- Go to Console → Zones
- Click the zone you want to configure
Add device selectors
Under Device Selectors, click Add Selector and enter one or more tags.
A device matches the zone if it has any of the tags in a selector. Add multiple selectors to broaden the match.
Examples:
| Selector tags | Devices matched |
|---|---|
managed | All devices tagged managed |
finance, corp | Devices tagged finance or corp |
remote | All remote workforce devices |
Keep selectors broad at the zone level and narrow access further with policies. Zones control reachability — policies control what devices can do once they're in.
Save
Click Save. Matched devices will receive the zone's WireGuard routes and DNS configuration on their next sync.
Verify
- Go to Console → Devices
- Open a device that matches the selector
- Confirm the zone appears under Connected Zones
Removing a device from a zone
Remove or change the device's tags so it no longer matches any of the zone's selectors. The route will be withdrawn on the next sync — no restart required.
How is this guide?
Last updated on