Software Secure Workload
Activity Configure

(Advanced) Change Policy Priorities


 

Scope policy priority order rarely needs to be changed. Since changing policy priorities can affect enforcement results on all workspaces, change with caution.

Access to this feature is limited to users with very high privilege roles, such as Tenant Owner.

Before you begin

Before changing scope priority order:

  • Understand policy sorting logic and how policy priorities on scopes translate to ordering of individual policy intents. See Policy Priorities.

  • Make changes in a secondary workspace until you are confident that your new order will be as expected.

  • Plan your changes, considering the following guidelines:

    When reordering, keep a parent-first ordering (parent scopes above child scopes) to take advantage of the hierarchical structure of your scope tree.

    (If you have overlapping sibling scopes, it may be necessary to reorder sibling scopes and their children. Overlapping sibling scopes are not recommended. Fix these by updating scope queries. See Scope Overlap.)

Procedure

1

To reorder policy priority, from the navigation menu, Defend > Segmentation,click the < icon to expand the Tools pane, click the three-dot icon next to Tools and choose Policy Order:

Navigating to Policy Priorities page
Figure 1: Navigate to Policy Priorities page

Once on the Policy Order page, you can see the list of all scopes and their corresponding primary workspaces according to the current policy priority.

2

There are several ways to reorder the scopes:

  • To reorder the entire list to place parent scopes above child scopes ("pre-order"): Click Reorder Naturally. This is the recommended order and any deviation from this should be done with care.

  • To reorder the list manually:

    • Drag the rows up and down.

    • Click By Number to set a number for each scope to be used for sorting. This can be easier for large lists.

Setting Policy Priorities for Scopes
Figure 2: Set Policy Priorities for Scopes

What to do next

Run Quick Analysis to see the results of your changes.