{"id":3383,"date":"2026-08-13T05:20:28","date_gmt":"2026-08-13T05:20:28","guid":{"rendered":"https:\/\/zecurit.com\/help\/endpoint-management\/device-access-control\/creating-a-linux-policy\/"},"modified":"2026-08-13T07:48:34","modified_gmt":"2026-08-13T07:48:34","slug":"creating-a-linux-policy","status":"publish","type":"docs","link":"https:\/\/zecurit.com\/help\/endpoint-management\/device-access-control\/creating-a-linux-policy\/","title":{"rendered":"Creating a Linux Policy"},"content":{"rendered":"\n<p>A <strong>Device Access Control<\/strong> policy controls access to USB and peripheral devices. For each device type, you can set the action to <strong>Allow, Block, or Not Configured<\/strong>. The selected settings are applied to all enrolled endpoints assigned to the profile.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What is a Device Access Control Policy?<\/strong><\/h2>\n\n\n\n<p>A <strong>Device Access Control<\/strong> policy controls which USB and peripheral devices can be used on managed endpoints. Each device type, such as <strong>USB Storage Devices<\/strong> or <strong>Bluetooth Adapters<\/strong>, can be set to <strong>Allow, Block, or Not Configured<\/strong>. This lets you apply stricter controls to high-risk devices while allowing everyday peripherals, such as mice and keyboards.<\/p>\n\n\n\n<p>The same device type can have different settings in different profiles. For example, one profile can <strong>Block USB Storage Devices<\/strong> for most users, while another profile can <strong>Allow<\/strong> them for a specific IT support group.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Create Policy<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"744\" height=\"1024\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Linux-policy-744x1024.webp\" alt=\"\" class=\"wp-image-3425\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Linux-policy-744x1024.webp 744w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Linux-policy-218x300.webp 218w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Linux-policy-768x1057.webp 768w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Linux-policy-1116x1536.webp 1116w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Linux-policy-1487x2048.webp 1487w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Linux-policy-scaled.webp 1859w\" sizes=\"(max-width: 744px) 100vw, 744px\" \/><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log in to the <strong>Zecurit portal<\/strong>.<\/li>\n\n\n\n<li>Go to <strong>Endpoint Manager \u2192 Manage \u2192 Profiles<\/strong>.<\/li>\n\n\n\n<li>Click <strong>Create Profile<\/strong>, then select <strong>Linux<\/strong> as the platform.<\/li>\n\n\n\n<li>Select <strong>Device Access Control<\/strong> from the configuration list.<\/li>\n\n\n\n<li>Set an action, such as <strong>Allow, Block, or Not Configured<\/strong>, for each device type under <strong>High Risk Devices, Network &amp; Communication,<\/strong> and <strong>Standard Peripherals<\/strong>.<\/li>\n\n\n\n<li>Click <strong>Publish<\/strong> to activate the profile immediately, or <strong>Save as Draft<\/strong> to complete it later.<\/li>\n<\/ol>\n\n\n\n<p>At least one device type must be set to <strong>Allow<\/strong> or <strong>Block<\/strong> for the profile to take effect. Device types set to <strong>Not Configured<\/strong> are not enforced by the profile.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Policy Details<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Field<\/strong><\/th><th><strong>Required<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Profile Name<\/td><td>Yes<\/td><td>A descriptive name for the profile (e.g., &#8220;Standard Linux Endpoint Security&#8221;). Shown in Inventory to identify which profile is applied to a device.<\/td><\/tr><tr><td>Platform<\/td><td>Yes<\/td><td>Must be set to Linux. Device categories and available actions are the same across platforms, but a profile only applies to endpoints matching its selected platform.<\/td><\/tr><tr><td>Device Type Actions<\/td><td>Yes<\/td><td>The Allow \/ Block \/ Not Configured setting chosen for each device type listed under the profile&#8217;s categories.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>A single profile can set Block on some device types and Allow on others. There is no requirement to apply the same action across an entire category.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Device Categories and Actions<\/h2>\n\n\n\n<p>Each device type uses one of three actions:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Action<\/strong><\/th><th><strong>Effect<\/strong><\/th><th><strong>Best For<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Allow<\/td><td>The device is permitted and functions normally.<\/td><td>Everyday peripherals required for business use, such as mice, keyboards, and printers.<\/td><\/tr><tr><td>Block<\/td><td>The device is denied; the endpoint prevents it from mounting or being used.<\/td><td>High-risk device types where there is no legitimate business need, such as USB storage or optical media.<\/td><\/tr><tr><td>Not Configured<\/td><td>No rule is applied by this profile; the device follows local settings or another assigned profile.<\/td><td>Device types intentionally left to a different, more specific profile or to local policy.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Device types are grouped into three categories to make large policies easier to review:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Category<\/strong><\/th><th><strong>Includes<\/strong><\/th><\/tr><\/thead><tbody><tr><td>High Risk Devices<\/td><td>USB Storage Devices, CD\/DVD Drives, External Hard Drives, Mobile Devices (MTP\/PTP), Imaging Devices<\/td><\/tr><tr><td>Network &amp; Communication<\/td><td>Wireless Adapters, Bluetooth Adapters, Modems<\/td><\/tr><tr><td>Standard Peripherals<\/td><td>Mice, Keyboards, Printers, Smart Card Readers, Serial Ports<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>A typical rollout pattern is to leave a new device type on Not Configured while confirming which endpoints actually use it, then move to Block once you&#8217;ve confirmed it has no legitimate business use in your environment.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Publishing vs. Saving as Draft<\/strong><\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Option<\/strong><\/th><th><strong>Effect<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Publish<\/td><td>Activates the policy immediately; enforcement begins on all Linux endpoints the profile is assigned to.<\/td><\/tr><tr><td>Save as Draft<\/td><td>Stores the profile configuration without activating it, so it can be reviewed or completed later.<\/td><\/tr><tr><td>Cancel<\/td><td>Discards changes and exits without saving.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Example Policies<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Profile Name<\/strong><\/th><th><strong>Category Focus<\/strong><\/th><th><strong>Action<\/strong><\/th><th><strong>Notes<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Standard Linux Endpoint Security<\/td><td>High Risk Devices<\/td><td>Block<\/td><td>Applied to all Linux workstations and servers.<\/td><\/tr><tr><td>Linux Kiosk Lockdown<\/td><td>High Risk + Network &amp; Communication<\/td><td>Block<\/td><td>Applied to shared\/kiosk Linux device group only.<\/td><\/tr><tr><td>IT Support Exception<\/td><td>High Risk Devices<\/td><td>Allow<\/td><td>Scoped to the Linux IT support device group only.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Best Practices<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name profiles clearly enough that they&#8217;re identifiable later in Inventory without opening them.<\/li>\n\n\n\n<li>Set high-risk device types (USB storage, optical media, external drives) to Block by default.<\/li>\n\n\n\n<li>Keep everyday peripherals  mice, keyboards, printers on Allow.<\/li>\n\n\n\n<li>Use a separate, narrowly scoped profile for exceptions rather than loosening the base policy.<\/li>\n\n\n\n<li>Review published profiles periodically, since device usage and risk levels change over time.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting Tips<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Issue<\/strong><\/th><th><strong>Resolution<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Publish button is disabled<\/td><td>Confirm a Profile Name is entered, Platform is set to Linux, and at least one device type has an action set.<\/td><\/tr><tr><td>Device blocked unexpectedly<\/td><td>Check whether another assigned profile also sets a policy for that device type; Block generally takes precedence over Allow.<\/td><\/tr><tr><td>User reports device still works after Block<\/td><td>Confirm the profile was Published, not left as a draft, and that the device has synced with the endpoint.<\/td><\/tr><tr><td>Draft profile not enforcing<\/td><td>Draft profiles are inactive by design; open the profile and click Publish to activate it.<\/td><\/tr><tr><td>Policy created for Linux not applying to a device<\/td><td>Confirm the target device&#8217;s platform is Linux; a profile only applies to endpoints matching its selected platform.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\"><\/h1>\n\n\n\n<p><\/p>\n","protected":false},"featured_media":0,"parent":3334,"menu_order":1,"comment_status":"open","ping_status":"closed","template":"","meta":{"_is_vendor_doc":"0","footnotes":""},"doc_tag":[],"class_list":["post-3383","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3383","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/comments?post=3383"}],"version-history":[{"count":4,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3383\/revisions"}],"predecessor-version":[{"id":3426,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3383\/revisions\/3426"}],"up":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3334"}],"next":[{"title":"Associate Groups and Devices","link":"https:\/\/zecurit.com\/help\/endpoint-management\/device-access-control\/associate-groups-and-devices\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3360"}],"prev":[{"title":"Creating a Windows Policy","link":"https:\/\/zecurit.com\/help\/endpoint-management\/device-access-control\/creating-a-windows-policy\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3351"}],"wp:attachment":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/media?parent=3383"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/doc_tag?post=3383"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}