Policy Enforcement Wizard
When you enforce policies for a single workspace from the Enforcement page of the workspace, the policy enforcement wizard lets you:
-
Review policies before they are implemented on the workloads.
This includes policies that are inherited from ancestor scopes.
-
Download policy changes for review.
-
Compare policy versions.
-
Choose which analyzed version of the workspace to enforce.
-
Roll back policies to a previous version.
Steps in the policy enforcement wizard:
-
Select Policy Updates
You can select which version of policies to be enforced on the workloads.
The difference between the currently enforced policies and policies in the selected version is displayed.
Similarly to the Policy Diff , you can filter and review the policy changes and download them as CSV.
-
Impacted Workloads
This step shows the workloads that will be affected by the new firewall rules generated from the selected policy changes. The result comes from searching all the workloads that have enforcement agents within the union of the consumers/providers of the selected policy changes.
The number of potentially impacted workloads cannot exceed the total number of workloads in the scope. However, the actual impacted workloads might be smaller due to other factors such as agent config intents.
Figure 1: List of Impacted Workloads For more details on viewing, filtering, and downloading inventory items, see Manage Inventory for Secure Workload.
-
Impacting Policies
Policies from the ancestor workspaces may impact workloads in the current workspace. Therefore, you should make sure the desired allow policies from ancestor workspaces are enforced.
Figure 2: List of ancestor workspaces and enforced versions -
Review & Accept
This final step summarizes the policy changes to be enforced, the number of potentially impacted workloads, and the catch-all action that will be enforced. When you click Accept and Enforce, the policies in the workspace will be used to calculate the new firewall rules that will be configured on the relevant workloads.
You have the option to provide a name, description, and reason for action for the newly enforced policies for future reference. In case of rollback, you can provide only the reason, as name and description for a past version cannot be changed.
Figure 3: Review the Summary and Enforce Policy Changes