Findings and policy rollout
Investigate organization findings, publish policy, and verify device behavior.
Organization findings collect observed issues across devices. Their evidence helps set the scope of a response: one connection, a device group, or the organization.
Investigate the finding
Section titled “Investigate the finding”Open a finding and review its kind, subject, occurrences, affected devices, and evidence. Occurrences count observations; the device count counts distinct devices. Repeated use on one device can therefore increase occurrences without increasing the device count.
Unknown connections and tool calls need review. Threat warnings, policy blocks, and data exposure describe different kinds of observed events and offer different actions.
Prepare a policy change
Section titled “Prepare a policy change”Choose a supported action and review its confirmation. A policy action prepares a draft; check its match conditions, treatment, and scope before publishing.
Use a device group for a limited rollout when appropriate. Groups are assigned to devices directly; adding a person to an organization does not automatically assign that person’s devices to a group.
Publish and verify
Section titled “Publish and verify”- Review the policy draft and its scope in the dashboard.
- Publish the intended version.
- Check the affected devices’ policy state and connectivity.
- Repeat a harmless matching interaction on a test device.
- Inspect the new trace to confirm the matched policy and actual outcome.
Publication makes a policy available for distribution; it does not prove that an offline device received it. Check the device’s last observed state when assessing rollout.
Local actions and organization rules
Section titled “Local actions and organization rules”An enrolled device can still produce local findings and allow local review. Local policy can add restrictions, but a local allow cannot weaken an organization rule. Use device administration to check scope if the outcome differs from your expectation.