Support for Layering/Inheriting Policy Settings across Orgs/Sites
later
Allen Bolderoff
We should be able to give a site or agent a Policy, that policy should be able to just inherit another policy, using whole policy chain before it and over riding all prior policies - this allows us to do a BLOCK ALL (or strict default policy), and on a selective basis, allow more freedom - so in our example, we would want "WHITELIST ONLY" for the whole site, and then 3 in mission critical sites available for one policy + the whitelist only, then the second policy will be mission critical + whitelist, but would allow us to say trusted user, can access a few more less required sites
James McDermott
Another way to solve this to avoid policy inheritance (which can get messy too) is to allow override policies per user/site/group.
So a new menu option beside universal lists called Overrides and in there you can create an override rule to permit/block an app or domain and apply it to a user/site/group. This would then take preference over larger policies.
Example: User A is approved to use App X but App X is blocked for the org as considered risky if generally used but User A requires to use it with a customer. So we can apply an override to that user or a group the user is in.
Minetta Gould
James McDermott: Thanks for the suggestion! The way our policies currently work gets you half way there: a Policy Allow List trumps the Universal Block List, so in your example you can achieve that now by assigning the user/group a policy that allows the domain otherwise blocked universally.
Same is not true for the Universal Allow List, however—a Policy Block will not win out in the hierarchy.
James McDermott
Minetta Gould Thanks for the reply! I suppose the situation I was trying to avoid were scenarios such as where user A is allowed to use app X, group B is allowed to use app Y and user C is allowed to use app Z. That would mean 3 additional policies - imagine a scenario where there are 10 or 20 policies to cover these situations, so that will likely introduce configuration drift as the policies become harder to manage.
My suggestion above would allow us keeping a baseline policy and any overriding changes would be kept separate and easily audited/updated. The alternate solution would be to have parent/child policies with inheritance by default.
Appreciate the engagement here too by they way - looking at the whole feature request sections, there's not too many vendors that are this receptive, so thank you!
Minetta Gould
James McDermott: It's my pleasure! And totally see the vision of your suggestion—policy management can get hairy real quick, so a space to customize, sort, and visualize for what you need would be a game changer.
Minetta Gould
Merged in a post:
Apply Multiple Filtering Policy by Priority
J
Jonathan Cuevas
Ability to apply multiple Filtering Policies and enforce by Priority. This way we can create different Policies depending on different requirements. Assign overlapping Policies. Instead of creating different Policies for each Collection of Users.
Minetta Gould
Merged in a post:
Allow a user to have multiple policies assigned
J
Jeremy Grossman
Would be nice to be able to have a single user be assigned multiple policies. This is to prevent having to place an allow for everyone when only one person needs it. To help minimize the risk of over allowing a site for risk and or business need.
J
Jared Roy
Universal block and allow lists have made this less needed for single domain entries; that said, a change of categories is a huge pain if we change a standard. A Parent/Child configuration would be amazing.
Most my platforms allow this, and its super handy.
A global policy for all org as a baseline, then a sub policy for the organization at the org level, then policies branching off that for different branches within the org. Then I can override at each level as needed.
Nickolas Newnham
Yes, please! This would be an amazing feature to have. Overlapping or inheritance would be so helpful.
Deon Marshall
Requested AGES ago, with no movement.
Lennart Friberg
This exact feature just got requested from our client. They have this feature with ZScaler and now moving to DNSFilter, but missing their restricted policies with cross allow rules between policies.
Joe Howard
As an alternative, perhaps allow for policy settings to inherit. So a specific override can be applied to a user or group, but also inherit from the global level. This would remove the need to edit every policy if a common change is required across all policies - we could just edit the top level global and know it's updating through all other policies
Jerry Ketterling
I want the same thing. Id be even happy with SIMPLE program logic that most computer languages support. The Concept of GLOBAL should automatically be visible and ASSIGNED to all lower leaf nodes unless the lower leaf node overrides and or redefines it.
Jerry Ketterling
I agree .. Things at the GLOBAL level should inherit downward automatically until over-ridden by specialization at the Organization or Site level. Speaking of which- the ORGANIZATION should also have its own "pseudo global level" that applies to all their SITES until it is overridden by a specific SITE policy or block page. GLOBAL BLOCK pages should also inherit downward. It would be helpful if the concept of GLOBAL was more akin to PROGRAMING languages. Variable declared GLOBAL are in force at every lower layer and automatically inherited until they are declared as STATIC or overridden at a lower layer. I think this would solve a lot of requests if we let the PROGRAMERS use programatic logic to defined DNSFilter inheritance and application within the MSP platform.
Load More
→