The EDR solution provides centralized Policy Management and Exclusion Capabilities that enable administrators to configure, assign, modify, and manage security policies across endpoints, sites, and device groups.
The policy framework provides flexible policy assignment, near real-time policy propagation, predefined exclusions, false-positive handling, and granular exclusion controls at multiple administrative levels.
1. Policy Propagation Across Sites and Device Groups
The EDR Management Console allows administrators to propagate security policies across sites or groups of devices from a centralized location.
Administrators can create or modify a policy and assign it to the required:
- Site
- Device Group
- Multiple Device Groups
- Individual Devices
This provides consistent security configuration across endpoints while reducing the need for manual configuration on individual devices.
2. Dynamic Policy Assignment
The solution supports dynamic policy assignment based on device attributes.
Administrators can configure policies to be automatically assigned to endpoints based on available device characteristics and organizational requirements.
This helps ensure that endpoints receive the appropriate security policy as their attributes or group membership change.
3. Device Group Assignment During Installation
The solution allows newly installed devices to be placed directly into a specific device group during installation.
This ensures that the endpoint receives the appropriate group-level policies and configurations without requiring a separate manual assignment after installation.
The capability simplifies large-scale endpoint deployment and helps maintain consistent security controls from the initial installation.
4. Near Real-Time Policy Updates
Policy modifications are propagated to applicable endpoints in near real time.
When an administrator changes a security policy, the updated configuration is communicated to the relevant endpoints without requiring a lengthy manual synchronization process.
This enables security teams to quickly respond to emerging threats and changing organizational security requirements.
5. Predefined Security Exclusions
The EDR solution provides a predefined list of known or recommended exclusions to simplify policy configuration.
These exclusions can help prevent legitimate applications, trusted files, system components, or other known-safe activities from being unnecessarily flagged by security controls.
The predefined exclusions provide administrators with a starting point for maintaining compatibility while preserving effective security protection.
6. False Positive Exclusion
The solution provides mechanisms to exclude verified false positives from detection or prevention policies.
When a legitimate file, process, application, or activity is incorrectly identified as suspicious, an authorized administrator can create an appropriate exclusion based on the available security controls.
This allows organizations to reduce unnecessary alerts while maintaining protection against genuine threats.
7. Multi-Level Policy Exclusions
Administrators can configure policy exclusions at multiple levels through the centralized Management Console.
The solution supports exclusion management at levels such as:
- Account Level
- Group Level
- Device Level, where applicable
This provides granular control over where an exclusion is applied.
For example, an exclusion required by a specific department or device group can be applied only to that group rather than being applied across the entire organization.
8. Process-Level Exclusions
The EDR solution provides process-level exclusion capabilities.
Administrators can configure exclusions for specific trusted processes when required by operational or application compatibility requirements.
Process-level exclusions can be used to prevent legitimate processes from being unnecessarily affected by applicable security controls while maintaining protection for other processes and activities.
9. Centralized Policy Management
The overall policy framework provides administrators with centralized control over endpoint security configurations:
Create Policy → Assign to Site/Group → Deploy to Endpoint → Monitor → Modify → Propagate Changes
This centralized approach enables administrators to maintain consistent security configurations while providing the flexibility to apply different policies and exclusions according to organizational requirements.
10. Granular and Flexible Policy Control
The combination of site/group policy propagation, dynamic assignment, installation-time group placement, near real-time updates, predefined exclusions, false-positive handling, multi-level exclusions, and process-level exclusions provides a flexible policy management framework.
The solution enables administrators to maintain strong endpoint security while minimizing operational disruption caused by legitimate applications or activities.