{"id":3319,"date":"2026-08-07T10:07:03","date_gmt":"2026-08-07T10:07:03","guid":{"rendered":"https:\/\/zecurit.com\/help\/endpoint-management\/application-control\/deploying-the-policy\/"},"modified":"2026-08-17T05:42:32","modified_gmt":"2026-08-17T05:42:32","slug":"deploying-the-policy","status":"publish","type":"docs","link":"https:\/\/zecurit.com\/help\/endpoint-management\/application-control\/deploying-the-policy\/","title":{"rendered":"Creating a Deployment Policy in Application Control"},"content":{"rendered":"\n<p>A deployment policy is what actually enforces an application group on real devices. It ties one or more application groups to an enforcement action, defines what end users see when something is blocked, and scopes the policy to specific device groups, with the option to exclude individual exceptions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is a Deployment Policy?<\/h2>\n\n\n\n<p>While an application group defines what to look for, a deployment policy defines how and where it&#8217;s enforced. The same application group can be attached to multiple policies. For example, one policy could silently audit a group across the whole organization, while a second, stricter policy actively blocks the same group on a smaller, high-risk device population.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Create Deployment Policy<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"832\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-13-1024x832.png\" alt=\"\" class=\"wp-image-3433\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-13-1024x832.png 1024w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-13-300x244.png 300w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-13-768x624.png 768w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-13-1536x1248.png 1536w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-13-2048x1664.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>To create a deployment policy:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log in to the <strong>Zecurit portal<\/strong>.<\/li>\n\n\n\n<li>Go to <strong>Endpoint Manager \u2192 Application Control<\/strong>.<\/li>\n\n\n\n<li>Select the <strong>Deployment<\/strong> tab.<\/li>\n\n\n\n<li>Click <strong>Create Deployment Policy<\/strong>.<\/li>\n\n\n\n<li>Select the required <strong>Platform<\/strong>, such as <strong>Windows, Linux, or macOS<\/strong>.<\/li>\n\n\n\n<li>Click <strong>New Deployment Policy<\/strong>.<\/li>\n\n\n\n<li>Configure the <strong>Policy Details, Enforcement, and Target Scope<\/strong> sections as required.<\/li>\n\n\n\n<li>Click <strong>Publish<\/strong> to activate the policy immediately, or select <strong>Save as Draft<\/strong> to complete it later..<\/li>\n<\/ol>\n\n\n\n<p>Note: At least one application group must exist before a policy can be created. See Creating an Application Group.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Policy Details<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Field<\/strong><\/th><th><strong>Required<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Policy Name<\/td><td>Yes<\/td><td>A descriptive name for the policy (e.g., &#8220;Application control policy&#8221;). Shown in the Violations log to identify which policy triggered an action.<\/td><\/tr><tr><td>Application Groups<\/td><td>Yes<\/td><td>One or more application groups to enforce, attached via Add Application Group. A policy can enforce multiple groups at once.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Note: A single policy can combine groups with different access types (Block List and Allow List) if your enforcement strategy requires layered rules, though most organizations keep one access type per policy for clarity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Enforcement Actions<\/h2>\n\n\n\n<p>The Enforcement Action determines what happens when a matched application is detected. Choose exactly one per policy:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Action<\/strong><\/th><th><strong>User Sees a Message?<\/strong><\/th><th><strong>Application Runs?<\/strong><\/th><th><strong>Best For<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Block &amp; Notify<\/td><td>Yes<\/td><td>No<\/td><td>Standard enforcement where users should understand why access was denied<\/td><\/tr><tr><td>Block Execution<\/td><td>No<\/td><td>No<\/td><td>Silent, hard enforcement with no user interaction; appropriate for high risk applications<\/td><\/tr><tr><td>Notify Only<\/td><td>Yes (warning)<\/td><td>Yes<\/td><td>Testing a new policy before fully enforcing it, or discouraging use without hard blocking<\/td><\/tr><tr><td>Audit Only<\/td><td>No<\/td><td>Yes<\/td><td>Silent logging to understand application usage before deciding on an enforcement action<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>A typical rollout pattern is to start a new policy on Audit Only, review the resulting Violations data, move to Notify Only if user awareness is needed, and finally switch to Block &amp; Notify or Block Execution once confident the rule is accurate.<\/p>\n\n\n\n<p><strong>Figure 1: Example End-User Block Notification<\/strong><\/p>\n\n\n\n<p>This is what an end user sees when Block &amp; Notify or Notify Only is configured  the Title, Reason, and Contact fields from the Policy Details render directly in the alert dialog on the device.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"562\" height=\"537\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-11.png\" alt=\"\" class=\"wp-image-3430\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-11.png 562w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-11-300x287.png 300w\" sizes=\"(max-width: 562px) 100vw, 562px\" \/><\/figure>\n\n\n\n<p>End-user &#8220;Application blocked by IT Admin&#8221; dialog, showing the Reason text and IT support contact configured in the policy&#8217;s block message.<\/p>\n\n\n\n<p><strong> Figure 2: Application Details View for a Blocked Application<\/strong><\/p>\n\n\n\n<p>When an application is matched and blocked, administrators can drill into the specific detection from the Violations log to see the vendor, product name, verification status, file path, and file hash  useful for confirming that the correct binary triggered the policy.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"562\" height=\"550\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-12.png\" alt=\"\" class=\"wp-image-3431\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-12.png 562w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-12-300x294.png 300w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/image-12-70x70.png 70w\" sizes=\"(max-width: 562px) 100vw, 562px\" \/><\/figure>\n\n\n\n<p>Application Details panel showing a blocked instance of Google Chrome (chrome.exe), including vendor, verification status, file path, and file hash.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">User-Facing Block Message<\/h2>\n\n\n\n<p>Available only when the Enforcement Action is Block &amp; Notify or Notify Only, since Block Execution and Audit Only never surface a message to the user.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Field<\/strong><\/th><th><strong>Description<\/strong><\/th><th><strong>Example<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Title<\/td><td>Short heading shown in the block dialog<\/td><td>&#8220;Application blocked by IT policy&#8221;<\/td><\/tr><tr><td>Reason<\/td><td>Explanation shown to the user<\/td><td>&#8220;Your access to this application has been blocked by your IT administrator.&#8221;<\/td><\/tr><tr><td>Contact<\/td><td>An email address users can reach out to for help or an exception request<\/td><td>contact@example.com<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Keeping this message clear and including a real contact address reduces help desk confusion and repeat tickets from users who don&#8217;t understand why an application won&#8217;t open.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Target Scope and Exceptions<\/h1>\n\n\n\n<p>Target Scope controls which devices the policy applies to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Choose a target type from the dropdown (e.g., Groups) and select the relevant device groups under Select Groups.<\/li>\n\n\n\n<li>Optionally add an Except rule; choose a type (e.g., Devices) and select specific endpoints to exempt from this policy, even if they belong to a targeted group.<\/li>\n\n\n\n<li>Click the + icon next to a target to add additional target\/exception pairs, allowing multiple scoping rules within a single policy.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Scenario<\/strong><\/th><th><strong>Recommended Scope Setup<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Enforce company wide<\/td><td>Target: Groups \u2192 All Devices; no exceptions needed<\/td><\/tr><tr><td>Enforce on one department only<\/td><td>Target: Groups \u2192 select that department&#8217;s device group<\/td><\/tr><tr><td>Enforce broadly but exempt IT admin machines<\/td><td>Target: Groups \u2192 All Devices; Except: Devices \u2192 select admin machines<\/td><\/tr><tr><td>Pilot on a small test group first<\/td><td>Target: Groups \u2192 select pilot group only<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">Publishing vs. Saving as Draft<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Option<\/strong><\/th><th><strong>Effect<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Publish<\/td><td>Activates the policy immediately; enforcement begins on all in-scope devices<\/td><\/tr><tr><td>Save as draft<\/td><td>Stores the policy configuration without activating it, so it can be reviewed or completed later<\/td><\/tr><tr><td>Cancel<\/td><td>Discards changes and exits without saving<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">Example Deployment Policies<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Policy Name<\/strong><\/th><th><strong>Application Groups<\/strong><\/th><th><strong>Enforcement Action<\/strong><\/th><th><strong>Target Scope<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Block Unauthorized Browsers<\/td><td>Approved Browsers &#8211; Kiosk Devices<\/td><td>Block Execution<\/td><td>Kiosk Devices group<\/td><\/tr><tr><td>Remote Access Tool Audit<\/td><td>Unauthorized Remote Access Tools<\/td><td>Audit Only<\/td><td>All Devices<\/td><\/tr><tr><td>US Branch Prohibited Apps<\/td><td>Prohibited app &#8211; US Branch<\/td><td>Block &amp; Notify<\/td><td>US Branch group, except IT Admins<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">Best Practices<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name policies clearly enough that they&#8217;re identifiable later in the Violations log without opening them.<\/li>\n\n\n\n<li>Roll out new policies with Audit Only first to avoid disrupting legitimate business workflows.<\/li>\n\n\n\n<li>Use Target Scope exceptions rather than creating a separate application group just to carve out a few devices.<\/li>\n\n\n\n<li>Review published policies periodically, since application usage and risk levels change over time.<\/li>\n<\/ul>\n\n\n\n<h1 class=\"wp-block-heading\">Troubleshooting Tips<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Issue<\/strong><\/th><th><strong>Resolution<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Publish button is disabled<\/td><td>Confirm a Policy Name is entered and at least one Application Group is attached<\/td><\/tr><tr><td>Policy enforced on wrong devices<\/td><td>Review Target Scope; confirm the correct Groups\/Devices were selected and exceptions are correctly configured<\/td><\/tr><tr><td>Users report no block message shown<\/td><td>Confirm Enforcement Action is Block &amp; Notify, not Block Execution or Audit Only<\/td><\/tr><tr><td>Draft policy not enforcing<\/td><td>Draft policies are inactive by design; open the policy and click Publish to activate it<\/td><\/tr><\/tbody><\/table><\/figure>\n","protected":false},"featured_media":0,"parent":3309,"menu_order":1,"comment_status":"open","ping_status":"closed","template":"","meta":{"_is_vendor_doc":"0","footnotes":""},"doc_tag":[],"class_list":["post-3319","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/comments?post=3319"}],"version-history":[{"count":14,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3319\/revisions"}],"predecessor-version":[{"id":3442,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3319\/revisions\/3442"}],"up":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3309"}],"next":[{"title":"Monitoring Violations","link":"https:\/\/zecurit.com\/help\/endpoint-management\/application-control\/monitoring-violations\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3322"}],"prev":[{"title":"Creating an Application Group in Zecurit","link":"https:\/\/zecurit.com\/help\/endpoint-management\/application-control\/creating-an-application-group-in-zecurit\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3310"}],"wp:attachment":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/media?parent=3319"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/doc_tag?post=3319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}