LogoThreatmatic
Zones

Assign devices to a zone

Control which enrolled devices can reach a zone using tags and device selectors

Assign devices to a zone

Zones use device selectors to determine which enrolled devices can connect. Selectors match devices by tag, so you assign devices to a zone by tagging them — not by naming them individually.

Prerequisites

  • An existing zone (see Create a zone)
  • Enrolled devices with tags applied

Steps

Open the zone

  1. Go to Console → Zones
  2. Click the zone you want to configure

Add device selectors

Under Device Selectors, click Add Selector and enter one or more tags.

A device matches the zone if it has any of the tags in a selector. Add multiple selectors to broaden the match.

Examples:

Selector tagsDevices matched
managedAll devices tagged managed
finance, corpDevices tagged finance or corp
remoteAll remote workforce devices

Keep selectors broad at the zone level and narrow access further with policies. Zones control reachability — policies control what devices can do once they're in.

Save

Click Save. Matched devices will receive the zone's WireGuard routes and DNS configuration on their next sync.

Verify

  1. Go to Console → Devices
  2. Open a device that matches the selector
  3. Confirm the zone appears under Connected Zones

Removing a device from a zone

Remove or change the device's tags so it no longer matches any of the zone's selectors. The route will be withdrawn on the next sync — no restart required.

How is this guide?

Last updated on

On this page