Managing Assigned Endpoints
To manage policy assignment to endpoints, you need to have have the Endpoint Configuration Management permission.
Assigning a Policy to Endpoints
Assign a policy to one or more endpoints to include the policy’s risk factors in endpoint health calculations. To assign a policy:- Open the Policy details page.
- Select the Endpoints tab.
- Select one or more endpoints in the Available Endpoints list.
- Click Assign.
- Review the confirmation message.
- Click Confirm to apply the change.
- The policy is assigned to the selected endpoints.
- A policy assignment event is recorded in the endpoint’s Policy Changes History.
- Online endpoints collect any additional data required by the policy. Offline endpoints start collecting information as soon as they get online.
- Endpoint health is recalculated after data collection is completed.
- Risk factors defined by the policy become available for evaluation.
Unassigning a Policy from Endpoints
Unassign a policy to exclude its risk factors from future endpoint health calculations.Policies inherited from endpoint groups cannot be unassigned directly from an endpoint. To remove such assignments, unassign the policy from the corresponding endpoint group.
- Open the Policy details page.
- Select the Endpoints tab.
- Select one or more endpoints in the Assigned Endpoints list.
- Click Unassign.
- Review the confirmation message.
- Click Confirm to apply the change.
- The policy is removed from the selected endpoints.
- A policy removal event is recorded in the endpoint’s Policy Changes History.
- Endpoint health is recalculated after the change is applied.
- Risk factors that belong exclusively to the removed policy no longer appear in Endpoint details after health data is updated.

The Endpoints tab on the Policy Details page.
Managing Assigned Endpoint Groups
To manage policy assignment to endpoint groups, you need to have have the Endpoint Configuration Management permission. The change is applied to all endpoints in the group.
Assigning a Policy to Endpoint Groups
Assign a policy to an endpoint group to apply the policy to all endpoints that belong to the group. To assign a policy:- Open the Policy details page.
- Select the Endpoint Groups tab.
- Select one or more endpoint groups in the Available Endpoint Groups list.
- Click Assign.
- Review the confirmation message.
- Click Confirm to apply the change.
- The policy is assigned to the selected endpoint groups.
- The policy is applied to endpoints that belong to those groups.
- Online endpoints collect any additional data required by the policy. Offline endpoints start collecting information as soon as they get online.
- Endpoint health is recalculated after data collection is completed.
Unassigning a Policy from Endpoint Groups
Remove a policy from an endpoint group when the policy should no longer apply to endpoints within that group. To unassign a policy:- Open the Policy details page.
- Select the Endpoint Groups tab.
- Select one or more endpoint groups in the Assigned Endpoint Groups list.
- Click Unassign.
- Review the confirmation message.
- Click Confirm to apply the change.
- The policy is removed from the selected endpoint groups.
- Endpoints within those groups stop using the policy for health calculations.
- Endpoint health is automatically recalculated.
- Risk factors belonging exclusively to the removed policy disappear from Endpoint detailsafter health data is refreshed.
Related
About policies
Explore security and compliance policies, understand how risk factors, controls, and severity ratings contribute to policy health scores.
About health score
Understand how endpoint, policy, and control health scores are calculated from detected risks.
Endpoint details
Health trends and active risk factors on the individual endpoint dashboard.
Endpoint history
The history of endpoint health, policy assignments, and risk factor status changes.