App Conditional Policy
The app conditional policy is a feature that allows for detailed management of access rights and isolation security policies for the created app. Access to the app can be controlled based on conditions such as members, location, and time, and various security policies can be applied.
Table of Contents
Basic
Policy Settings
- Add Policy
- Policy Basic Information- Policy Name, Members, Target App
- Setting Conditions- Location, Time
- Execution Policy- Access policy, access via Remote Browser, additional authentication
- Isolation Security Policy- Keyboard, File, Clipboard, Session, Context Menu, etc.
- Policy Settings
Management
Basic Screen Configuration
The conditional policy screen is composed as follows.
- Conditional Policy Tab: A tab where you can apply conditional policies to apps created in the home.
- Priority: Display policy priorities (the smaller the number, the higher the priority)
- Add Policy: Create a new policy using the [Add Policy] button in the top left corner.
- Search: Policy name, members, target app, usage status, and various other conditions can be searched.
- Policy Application Status Inquiry: Policy list top button bar's [Policy Application Status Inquiry] button to check the application history by policy and the non-applied policies.
Policy Search
You can search for policies based on various criteria, including not only the policy name but also members, target apps, conditions, enforcement policies, and usage status.
Types of Search Filters
| Filter | Search Method | Explanation |
|---|---|---|
| Policy Name | Included Search | Search for policy names containing keywords |
| Members | Include search + dropdown selection | User (Name·Email), Group, Department Search, Assignment/Exception Classification Selection, Multiple Selection Available |
| Target | Dropdown Selection | Search by app name or app representative URL, multiple selections allowed |
| Usage | Dropdown Selection | Use / Not Use Selection |
| condition | Include search + dropdown selection | Search by location (IP), time, and device conditions, multiple selections possible |
| Execution Policy | Dropdown Selection | Access Allow/Deny, Isolation Security Policy (Allow All/Restricted Use), Select Additional Authentication Methods, Multiple Selections Possible |
Member Search Details
- When you enter a name or email in the search box, results will be displayed in real-time in a dropdown.
- Allocation / ExceptionYou can distinguish between cases where a tab is selected and assigned to a policy and cases that are exception handled.
- All membersis fixed at the bottom of the dropdown and is included in the search results only when selected directly.
Detailed Condition Search
- Location :
위치 제한 없음or enter a registered location name to search. The results are위치명 | IP 범위It will be displayed in the format. - time :
시간 제한 없음You can search by entering the registered time name. The results are시간명 | 시간 범위It will be displayed in the format. - Device :
모든 디바이스,Desktop,Tablet,MobileSelect an option.
Execution Policy Search Details
- Access Policy: Allow access / Block access selection
- Isolation Security Policy: Allow all / Select restricted use
- Additional authentication methods: Not used / Email verification / OTP verification / Passkey (WebAuthn) verification selection (applies only to access permission policies)
Search Condition Combination Rules
- Between filters (AND condition): If you set multiple different filters, only the policies that satisfy all conditions simultaneously will be displayed.
- Filter within (OR condition): If you select multiple items within the same filter, any policy that matches at least one will be displayed.
- The conditions set are displayed in the form of tags, and the tags'
×You can remove individual conditions with the button.
⚠️ Priority changes are not possible when search filters are applied. To change the priority, please clear all search filters.
Policy Application Status Inquiry
Clicking the [Policy Application Status Inquiry] button at the top of the policy list opens a modal where you can view the application history of conditional policies and the policies not applied by period.
Modal Configuration
- Modal Title: Policy Application Status Inquiry
| area | content |
|---|---|
| Query Period | [Start Date] ~ [End Date] Calendar Selection |
| tab | Applied Policies / Unapplied Policies |
| Download | Download Excel of the search results using the button in the upper right [↓] |
Applied Policies Tab
to users during the specified period**Policies Actually Applied (Heating)**Displays the list.
Table Column Configuration
| column | Explanation |
|---|---|
| Priority | Current priority number of the policy |
| Policy Name | Policy Name (Click to move to the edit details screen) |
| Explanation | Policy Description |
| Policy Usage Status | Currently in use / Not in use status |
| Application Count ↑↓ | Number of times the policy was applied during the inquiry period (comma separated in thousands, sortable) |
| Recent application date ↑↓ | The most recent date the policy was applied within the inquiry period (sortable) |
💡 The "Application Count" and "Most Recent Application Date" columns can be sorted in ascending/descending order. When sorting the application count in ascending order, you can quickly identify policies with low usage frequency at the top.
How to use
- [Policy Application Status Inquiry] Click the button → Open modal
- Setting the query period (start date ~ end date)
- Check the Applied Policies Tab
- Sort by clicking the header of the application count or recent application date column
- You can move to the edit detail screen of the corresponding policy by clicking the policy name.
- Download Excel of the query results by clicking the button [↓] in the upper right corner.
Unapplied Policy Tab
during the set period**Policy that has never been applied (heating)**Displays the list.
Table Column Configuration
| column | Explanation |
|---|---|
| Priority | Current priority number of the policy |
| Policy Name | Policy Name (Click to move to the edit details screen) |
| Explanation | Policy Description |
| Policy Usage Status | Currently in use / Not in use status |
How to use
- [Policy Application Status Inquiry] Click the button → Open modal
- Setting the query period (start date ~ end date)
- Select the Unapplied Policies tab
- Check the list of policies that were not applied even once during the period.
- You can move to the edit detail screen of the corresponding policy by clicking the policy name.
- Download Excel of the query results by clicking the button [↓] in the upper right corner.
💡 By periodically checking for non-applicable policies and organizing unnecessary ones, you can reduce the complexity of policy management and optimize the security environment.
Get Policy
You can import a backup of the conditional policy from a JSON file (single policy) or a ZIP file (multiple policies) to register it.
How to use
- Download: Item checkbox check > Click the [Download Policy] button on the top button bar
- When selecting 1: Download JSON file
- When selecting 2 or more: Download as a ZIP file.
- import: Click the [Get Policy] button to select and register the backed-up JSON file or ZIP file.
Add Policy
Clicking on [Add Policy] will take you to the new conditional policy page, where you can set the following items.
- Policy Basic Information
- condition
- Execution Policy
- Settings
Policy Basic Information
Policy Name
- name(Required): Up to 20 characters can be entered
- Explanation(Optional): Up to 200 characters can be entered.
The conditional policy name is a required field, and you must enter a unique name to identify the policy.
Members
Set users or groups to be assigned or excluded from this conditional policy as members.
Allocation
- All users: Apply policy to all users
- Select User or Group: Search and select a specific user or group
- Search by entering the username or group name in the search box.
- The selected user or group can be confirmed in the box below.
Exclusion
- Specify users or groups to exclude from the policy
- Excluded members are not subject to the policy regardless of assignment status.
- The 'All Users' option cannot be used in the exclusion list.
- If you select members to exclude, you can check the list of excluded members in the box below.
Target App
- Select the app or app group to which this conditional policy will apply.
- Only policies apply to the selected app or group.
- You can select multiple apps, and you can also select by app group.
Setting Conditions
Set conditions such as location and time to be used for policy judgment. Based on the assigned conditions, determine the user's access environment and decide whether to apply the policy.
Location Conditions
You can choose from the following two items for the location (IP) condition.
- All Locations(Default): Apply policy at all locations without specific location conditions
- Exception Selection: To exclude only specific locations among all locations, specify the locations to be excluded through 'Exception Selection'
- Select Registered Location: Select from the locations registered in the conditions section of the Security365 Management Center.
- Click 'Select a Location' to check the list of registered locations.
- [+Register Location] : Click to add a new location condition
- Exception Selection: Use 'Exception Selection' to exclude specific locations from the selected locations.
Time Condition
You can choose from the following two time conditions.
- All Time(default): Always apply policy without specific time limits
- Exception selection: To exclude only specific time zones among all times, specify the time to be excluded through 'exception selection'.
- Select Registered Time: Select from the registered times in the conditions section of the Security365 Management Center.
- Click 'Select a Time' to check the list of registered times.
- [+Register Time] : Click to add a new time condition
- Exception Selection: To exclude a specific time zone from the selected time, use 'Exception Selection'
Condition Management Notes
- The location and time conditions can be registered/deleted/edited in the [Condition Items] menu of the Security365 Management Center.
- Use exception selection to set finely when complex conditions are required.
Execution Policy
Access Policy
This conditional policy sets the access permissions when a member of the target subject wants to connect.
Access Permission
- Access Denied: Completely block app access under the given conditions
- Access Allowed: Allows app access and enables the setting of additional authentication methods.
Access via Remote Browser(Can be set only when access is allowed)
Set whether to use a remote browser when accessing the app. This option is only available in app conditional policies.
- ON: Access the app through an isolated browser. The behavior control items of the isolation security policy are also applied.
- OFF: Access the app through the user's PC's regular browser without going through an isolated browser. This is used when operating as a non-isolated app.
| division | ON (Isolated Access) | OFF (General Browser Access) |
|---|---|---|
| Access Path | Isolated Browser Proxy | General browser of the user's PC |
| Access Control (Members·Conditions·Additional Authentication) | Application | Application |
| Isolation Security Policy (File·Clipboard·Keyboard·Context Menu·Input Sensitive Information Inspection) | Application | Not applied |
Even when set to unisolated (OFF), member assignment/exceptions, location/time/device conditions, and additional authentication methods operate the same way. It is recommended to configure business systems that require file export/data copy control to ON, while those that only require access permission management to OFF.
Additional authentication methods(Can be set only when access is allowed)
- Not in use: Accessing the target without additional authentication
- Email Verification: An authentication code input window appears and the authentication proceeds.
- Time limit: 5 minutes
- If you did not receive the verification code in time, click 'Resend Verification Code'
- OTP authentication: Initial registration QR code and recovery key instructions
- Enter the authentication code after registration to proceed with authentication.
- Passkey (WebAuthn) Authentication: A method of additional authentication that verifies the user using passkeys registered on the user's device, such as fingerprints, PINs, and security keys. It provides a higher level of security than email and OTP authentication, allowing for quick access using only biometric authentication without the need to enter an authentication code.
Passkey (WebAuthn) Authentication Workflow
- Display additional authentication modal: When accessing the target app, at the top of the screenAdditional AuthenticationA modal will be displayed. A message stating "For secure access, verification is required using a passkey (fingerprint, PIN, security key, etc.)" will be provided along with the [Authenticate] button. The passkey has a higher security requirement level than other two-factor authentication methods, so the authentication window must be opened as a popup. This modal is a step to bypass the browser's popup blocker by opening the popup with the user's **click (gesture)**.
- Biometric Authentication Process: Clicking [Authenticate] will open the authentication window (popup) and display the message "Authenticate with security key or biometric program." You will proceed with identity verification using the registered passkey on the device through fingerprint, PIN, or security key on the OS authentication screen such as Windows Security.
- Access Allowed: If authentication is successful, the authentication window will close and access to the originally requested app will be allowed.
- Display a notification popup saying "Authentication has failed." when authentication fails.
- Unable to access the target
Other Matters — Passkey authentication requires that the passkey (passwordless) credential for the user identity is pre-registered to function. If the authentication window does not open or if authentication continues to fail, please request SOFTCAMP to check the registration status of the passkey (passwordless) credential.
Isolation Security Policy
Set policies to control user behavior within the app. All behavior control items can select whether to allow or block.
Keyboard Input
- Allow/Deny Settings
- When blocked: "Input via keyboard is prohibited by policy." notification is displayed at the center bottom.
Site Navigation
- Allow/Deny Settings
- Allowed: Free movement to all sites
- Block: Can only navigate to the representative URL and associated URLs.
- When accessing a blocked site: Redirect to the "This action is prohibited by policy." guidance page.
File Security
File Upload
- Allow/Deny Settings
- Additional settings when allowed:
- Extension Limitations: Control the file extensions that can be uploaded (belowExtension Restrictions — Block / Allow MethodReference)
- Select Repository: My PC File Folder / SHIELDGate File Folder
File Download
- Allow/Deny Settings
- When blocked: "This action is prohibited by policy. Downloading is not allowed according to the policy." Move to the guidance page, return to the previous screen with the close button.
- Additional settings when allowed:
- Extension Limitations: Control downloadable file extensions (belowExtension Restrictions — Block / Allow MethodReference)
- Select Repository: My PC File Folder / SHIELDGate File Folder (SHIELDrive storage can be specified when selected)
- Precautions When Using SHIELDrive Storage
- The member must be assigned to SHIELDrive storage to be available.
- Unable to download files if there is no storage allocation
Extension Restrictions — Block / Allow Method
Select the extension control method for file upload and download.격리 보안 정책 > 파일 보안 > 파일 업로드 / 파일 다운로드ofExtension LimitationsSet in.
Selecting Extension Control Method
Select one of the two methods from the button at the top of the extension restriction.
- Block Extensions: Only the registered extensions are blocked, and all others are allowed. (Existing method)
- Allowed extensions: Only the registered extensions are allowed, and all others are blocked.
File Extension Registration
- Enter the extension one by one in the input box and**[+]**If added with a button, it will be displayed in the form of a chip.
- Enter only the file extension. For example:
png(.pngeven if you enter likepngwill be registered.) - The input box guidance will be displayed as "Enter the blocked file extensions." / "Enter the allowed file extensions." depending on the method.
- If you enter an already added extension again, a message will be displayed saying "This extension has already been added."
⚠️ File upload and file download**Cannot be set as "Allowed Extensions" at the same time.**If one side is changed to "Allow Extensions," the other side will automatically switch to "Block Extensions."
User Guidance When Blocked
If the file is blocked due to extension restrictions, a message "Attachment Request Failed" will be displayed on the user screen, along with the following information.
- Allowed extensions: (List of extensions registered as allowed in the "Allowed Extensions" method)
- Blocked file: (blocked file name)
Clipboard Access
Controls copy/paste between the isolation browser and the user PC. If clipboard access is allowed, copy and paste can be set in 3 stages respectively.
| Option | value | Action |
|---|---|---|
| Copy in the isolated browser | allowed | Copyable. Can be exported to PC clipboard. |
| Only within the isolated browser | Copyable. Not exportable to PC clipboard. | |
| Block | Copy not allowed | |
| Paste into the isolated browser | allowed | Pasteable. Importable from PC clipboard. |
| Only within the isolated browser | Only content copied from the isolated browser can be pasted. | |
| Block | Cannot paste |
- Each direction is set independently. The ability to copy → paste (internal movement) within the isolated browser is determined by the combination of the two values.
- The existing allow/block settings are each
허용/차단It continues with. The operation of the existing policy does not change. 클립보드 액세스If not allowed, the entire direction setting will be disabled.
Paste 격리 브라우저 내에서만if set to
The PC clipboard content is not transferred to the isolated browser. Even if the user copies from the PC and pastes it,Last copied content in the isolated browserThis is entered, and a guide indicating what has been entered is displayed on the user screen.
Cutting
Cutting is**Copying and pasting are both allowed.**works only in. paste차단If set to __PH_0__, cutting will also be blocked. If cutting occurs when there is no place to paste, only the original will be deleted, resulting in data loss.
Operation by Setting Combination
| copy | Paste | Export | Import | Internal Movement | Cutting |
|---|---|---|---|---|---|
| allowed | allowed | O | O | O | O |
| allowed | Only within the isolated browser | O | X | O | O |
| allowed | Block | O | X | X | X |
| Only within the isolated browser | allowed | X | O | X | O |
| Only within the isolated browser | Only within the isolated browser | X | X | O | O |
| Only within the isolated browser | Block | X | X | X | X |
| Block | allowed | X | O | X | X |
| Block | Only within the isolated browser | X | X | X | X |
| Block | Block | X | X | X | X |
⚠️
복사 = 격리 브라우저 내에서만+붙여넣기 = 허용In the combination, the PC clipboard content takes precedence, so you cannot paste content copied from the isolated browser. If internal copy and paste is needed, you can also paste.격리 브라우저 내에서만Set to.
⚠️
복사 = 격리 브라우저 내에서만+붙여넣기 = 차단The combination is saved, but you cannot paste the copied content anywhere. To prevent copying itself, you need to stop copying.차단Set to.
User Interface Guide
| situation | Guide text |
|---|---|
| Clipboard access not allowed | Clipboard usage is prohibited by policy. |
copy =차단 | Copying is restricted. |
copy =격리 브라우저 내에서만 | The copied content can only be used within the isolated browser. |
copy =격리 브라우저 내에서만+ Paste =차단 | The pasted content is set to be unable to be pasted. |
Paste =차단 | Pasting is restricted. |
Paste =격리 브라우저 내에서만, execute paste | Content copied from the isolation browser has been pasted. |
Paste =격리 브라우저 내에서만, no content to attach | There is no content copied from the isolated browser. |
| Cannot cut | Cutting cannot be used because pasting is restricted. |
Session Maintenance
- Activating session persistence protects the data on the screen through the lock screen when there is no screen activity during idle time.
- Idle time setting available when activated (in minutes)
- When idle time elapses, the screen is immediately locked, and you can return to the work page through the 'Refresh' button.
Screen Marking
- Enable/Disable settings available
- When activated: Display a watermark containing information such as username and email on the screen.
- Data Leakage Prevention and Accountability Enhancement
- The screen mark display method can be customized in the 'Business System > Security Screen Settings > Screen Marking/Watermark Settings' menu.
Print Watermark
- Available for use/not in use setting
- When activated: Display a watermark containing information such as username and email on the screen.
- Data Leakage Prevention and Accountability Enhancement
- The watermark display method can be customized in the 'Business System > Security Screen Settings > Screen Marking/Watermark Settings' menu.
Video Conference Mode
- Activate in work systems that require video conferencing
- Activation Limitations: SHIELDGate shortcut function not available (shortcut icon not provided in the upper right corner)
- Settings for Optimizing Video Conference Performance
Context Menu
- Available for use/not in use setting
- When activated: Individually control the context menu items displayed when right-clicking in the RBI browser by target.
- Context Menu Settings > Clicking the link opens the detailed settings slide. The current setting status is summarized text (e.g:
32개 표시 | 2개 숨김) is indicated.
Context Menu Detailed Settings
Individually control the ON/OFF state of menu items to be displayed for each clickable target area.
| area | Explanation |
|---|---|
| Page Background Area | Context menu displayed on right-clicking empty space (Back, Forward, Refresh, Print, View Page Source, Inspect, etc.) |
| Text Selection Area | Menu displayed on right-click after dragging text (Copy, Print, etc.) |
| link | Menu displayed when right-clicking on a link (Open in new tab, Copy link address, etc.) |
| image | Menu displayed when right-clicking on an image (Save image, Copy image, etc.) |
| video | Menu displayed when right-clicking on the video (Play/Pause, Save video, etc.) |
| Audio | Menu displayed when right-clicking on the audio (Play/Pause, Save Audio, etc.) |
| Input Field | Context menu displayed on right-clicking the text input field (Cut, Copy, Paste, etc.) |
- Each item within the area is controlled by an individual ON/OFF toggle,All ON / All OFFYou can toggle all items in the area at once with the button.
- bottomInitializationClicking the button will reset all items to their default values.
- If all items in a specific area are OFF, the context menu will not be displayed when right-clicking in that area.
⚠️ Shortcut Key Integration: If you set the menu item to OFF, the associated keyboard shortcuts will also be blocked. (e.g.: Print item OFF →
Ctrl + PBlock)
⚠️ Top Button Constraints in Browser: Setting the back/forward/refresh menu items to OFF does not block clicks on the navigation buttons at the top of the browser. Shortcut key(
Alt+←,F5Only (etc.) will be blocked.
- Video/Audio: You can control the basic playback-related menu for video and audio, and it is applied based on the standard context menu items of the browser.
- Shortcut keys: The browser's default shortcuts associated with the context menu items are controlled together, while custom shortcuts are excluded.
Data Security — Sensitive Information Input Inspection
Input Prompt Firewall (formerly Custom Overlay) feature checks for sensitive information (such as regular expressions) in the text entered by the user,Before the original text is delivered to the siteControls. This item is displayed according to company settings.
Settings
- Input Sensitive Information Check(ON/OFF): This toggles the inspection for this policy target on or off. It operates as follows depending on the inspection method.
- Self-Inspection (Regular Expression): If you turn the inspection ON,Regular Expression Selection(Select from the list registered in sensitive information management, new addition possible) andLog Optionssets.
- Log storage scope: All cases / Only blocked cases
- User input content included: Whether to include the text entered by the user in the inspection log.
- External Integration: Only the inspection ON/OFF is set, and the regular expression and log details are handled by the external inspection system.
If this item (Data Security > Input Sensitive Information Check) is not visible, you need to enable the input prompt firewall. Please contact SOFTCAMP.
Core Values
- Prevention: Unlike the existing method that detects after transmission, it inspects and blocks before the input is sent externally.
- Original text not leaked: Designed to only transmit results that have passed inspection, ensuring that sensitive information does not leave external services or remote screens.
- Bypass Blocking: Perform inspection and judgment at a control point rather than the user local, blocking bypassing inspection by local tampering.
- Judgment · Record: It determines whether the text file is allowed or blocked, and logs the entire process in an audit log.
Policy Settings
You can set the usage and validity period of this conditional policy.
Usage status
- use: Policy is activated and works immediately
- Not in use: The policy is disabled and does not operate.
Expiration Date
- If not set: Operates indefinitely
- Expiration Date Usage: Checking the 'Expiration Date' item activates the calendar.
- Set the period by selecting the start date and end date.
- Policy operates only during the set period.
Policy Application Priority
- If multiple policies conflict, the policy with a higher priority (a smaller number) will be applied.
- You can adjust the priority by dragging and dropping in the policy list.
- If multiple policies are set for the same conditions, the most restrictive policy takes precedence.
- Policy priorities are important for the effective management of policies, so they should be set carefully.
Priority Quick Move
After selecting a policy, you can quickly change the priority using the following method.
- Move to top / Move to bottom: Move immediately to the top or bottom
- Priority Move Dropdown: Select the desired number to move directly to a specific location
⚠️ Priority changes are not possible when search filters are applied. Please proceed after clearing all filters.
Download Policy Status
You can download the list of conditional policies as an Excel (.xlsx) file. This is provided separately from the existing JSON backup feature.
- Full Download: Save all registered policy information as an Excel file
- Download Search Results: Save only the results with the current search filter applied as an Excel file
💡 JSON download is for policy backup and restoration, while Excel download is used for status analysis and reporting purposes.
Management of Default Execution Policy
This is a feature that allows you to pre-set and manage the default values automatically filled in the execution policy and isolation security policy items when registering a new conditional policy. It reduces repetitive manual settings and prevents setting omissions and input errors.
Accessing the Default Value Management Screen
Click the [Execution Policy Default Management] button on the right side of the top button bar of the policy list.
[+ Policy Registration] ... [Execution Policy Default Management]
※ The default values for the app and URL input fields are managed independently. Changing the default in one menu does not affect other menus.
Default Value Setting Range
The items that can be set in the default value management screen are as follows.
| item | Whether to apply default values | Note |
|---|---|---|
| Policy Name / Description | ❌ | Unique input for each policy |
| Members / Target App | ❌ | Unique designation for each policy |
| Condition (Location·Time) | ❌ | Set directly for each policy |
| Execution Policy (Access Policy · Additional Authentication) | ✅ | |
| Isolation Security Policy (Keyboard, File, Clipboard, Session, Context Menu, etc.) | ✅ | |
| Settings (Usage Status · Validity Period) | ❌ |
Save Default Value
In the default value management screen, set the execution policy and isolation security policy items, and then click the [Save] button.
| Action | result |
|---|---|
| [Save] Click | The current settings are saved as the default values for the app conditional policy. Automatically applied when registering a new policy later. |
| [Cancel] Click | Return to the list screen without saving changes |
| Default value not set state (initial) | Display in system initial value (fully allowed, not set) state |
Automatic application upon registering a new policy
[Add Policy] When clicked, the execution policy and isolation security policy items are automatically filled with the default values saved. Enter the policy name, members, target app, and conditions, and register by modifying only the necessary items.
| status | Action |
|---|---|
| When a default value is set | Execution Policy · Isolation Security Policy has been reset to default. |
| If no default value is set | Initialize to system default values (same as existing operation) |
| If manually modified after automatic application | The modified value takes precedence and does not affect the default value. |
※ Automatic application only applies to initial value settings upon new registration. It does not affect existing saved policies.
Apply default values in bulk to the selected policy
After selecting the policies with checkboxes in the list, clicking the [Apply Default Execution Policy] button in the top button bar will overwrite the execution policy and isolation security policy items of the selected policies with the current default values.
How to use
- Select the checkbox for the policy to apply the default value from the list.
- Click the [Apply Default Execution Policy] button in the top button bar.
- Check the default values to be applied in the confirmation dialog (execution policy · isolation security policy summary).
- Clicking the [Apply Default] button will immediately apply the default values to the selected policy.
⚠️ The application of default values is saved immediately. Policy name, description, members, target app, conditions, and settings will not be changed.
⚠️ If no default value is set, the system's initial value will be applied.