Manage policies
You can create and manage policies specific to Windows, Apple (macOS/iOS/iPadOS), and Android devices through BigFix WebUI.
Note:
- Master operators and non-master operators that have the WebUI permission to view the MCM application, and permissions to Create, Edit, and Delete Non-Custom Policies can create or manage the following policies:Users who have the Create, Edit, and Delete MDM Custom Policies permission will see an additional option when creating policies to help them create custom policies.
- Only Master Operators can manage DEP policies.
- Non-master operators must have the following permissions to manage MCM and
BigFix Mobile policies and actions:
- Appropriate permissions to create, edit and delete MCM custom and non-custom policies
- The "custom content" and "can create actions" permissions to deploy MCM actions and policies
- Write permissions to specific custom content sites to have them be an option in the site drop down when associating an MDM policy with a custom site.
- Read permissions or be part of a role that has read permissions to the BESUEM site to get accurate device counts of the policies.
The following are the policies that can be configured using BigFix WebUI:
Certain policy types are operating system specific. Each policy type has the applicable operating system logos underneath to notify the users. If you find more than one logo, it represents that the policy can be applied to more than one operating system, specific to those logos.
Policy type | Scope | Available for the OS |
---|---|---|
Passcode policy |
Create passcode policy for low security requirement |
macOS / iOS / iPadOS, , Android |
Create kernel extension whitelist policy to load code dynamically into the macOS Kernel | macOS | |
Full Disk Access | Create policy to encrypt disc space | macOS |
Upload Custom Policy | Create custom policy | macOS / iOS / iPadOS, , Android |
Restrictions Policy | Create restriction policy | macOS / iOS / iPadOS, , Android |
Certificates Policy | Create policy certificates | macOS, |
Disk Encryption Policy | Create policy to apply disc encryption | macOS, |
Appstore App Policy | Create policy to deploy app store apps on MDM endpoints | iOS / iPadOS, Android |
OS Update Policy | Create policy to manage OS updates | iOS / iPadOS, Android |
To create a policy, follow these steps:
- Open the MCM app.
- Click Create Policy.
- On the page where the policies are listed, select the Supported Operating Systems to display only the policy types that are supported for the selected operating systems. From the filtered list, select the policy type that you want to create.