Desktop Conditional Policy
Basic Screen Composition
The conditional policy screen is composed as follows:
- Conditional Policy Tab: A tab where you can apply conditional policies to the apps created on the home page.
- Priority: Display policy priorities (the smaller the number, the higher the priority)
- Add Policy: Top left of the**[➕ Add Policy]**Create a new policy with the button
- Search: Policy name, members, usage status, and various other conditions can be searched.
Policy Search
You can search for policies based on various criteria, including not only the policy name but also members, conditions, enforcement policies, and usage.
Types of Search Filters
| Filter | Search Method | Description |
|---|---|---|
| Policy Name | Included Search | Search for policy names containing keywords |
| Members | Include Search + Dropdown Selection | User (Name·Email), Group, Department Search, Assignment/Exception Classification Selection, Multiple Selection Available |
| Usage | Dropdown selection | Use / Not Use Selection |
| condition | Include Search + Dropdown Selection | Search by location (IP), time, device conditions, multiple selections available |
| Execution Policy | Dropdown selection | Access Allow/Deny, Select Additional Authentication Methods (Email·OTP), Multiple Selections Possible |
Member Search Details
- When you enter a name or email in the search box, results will be displayed in real-time in a dropdown.
- Allocation / ExceptionYou can distinguish between cases where a tab is selected and assigned to a policy and where it has been handled as an exception.
모든 구성원is fixed at the bottom of the dropdown and is included in the search results only when selected directly.
Detailed Condition Search
- Location:
위치 제한 없음or enter a registered location name to search. The results are위치명 | IP 범위It will be displayed in the format. - time:
시간 제한 없음You can search by entering the registered time name. The results are시간명 | 시간 범위It will be displayed in the format. - Device:
모든 디바이스,Desktop,Tablet,MobileSelect an option.
Search Condition Combination Rules
- Between filters (AND condition): If you set multiple different filters, only the policies that satisfy all conditions simultaneously will be displayed.
- Filter inside (OR condition): If you select multiple items within the same filter, any policy that matches at least one will be displayed.
- Each set condition is displayed in the form of tags, and the tags'
×You can remove individual conditions with the button.
⚠️ Priority changes are not possible when search filters are applied. To change the priority, please clear all search filters.
Get Policy
- You can import and register a JSON file (single policy) or a ZIP file (multiple policies) that contains the backup of the conditional policy.
[How to Use]
- Download: Check the item checkbox > Click the [Download Policy] button on the top button bar
- When selecting 1: Download JSON file
- When selecting more than 2: Download as a ZIP file.
- Import: Click the [Import Policy] button to select and register the backed-up JSON file or ZIP file.
➕ Add Policy
**[➕ Add Policy]**Clicking will take you to the new conditional policy page, where you can set the following items:
- Policy Basic Information
- condition
- Execution Policy
- Settings
📌 Policy Basic Information
Policy Name
- name(Required): Up to 20 characters can be entered
- Description(Optional): Up to 200 characters can be entered.
- The conditional policy name is a required value, and you must enter a unique name to identify the policy.
Members
Set users or groups to be included or excluded from this conditional policy.
allocation
- All users: Apply policy to all users
- Select User or Group: Search and select a specific user or group
- Search by entering a username or group name in the search box.
- The selected user or group can be confirmed in the box below.
Exclusion
- Specify users or groups to exclude from the policy
- Excluded members are not subject to the policy regardless of assignment status.
- The 'All Users' option cannot be used in the exclusion list.
- If you select members to exclude, you can check the list of excluded members in the box below.
condition
Set conditions such as location and time to be used for policy judgment. Based on the assigned conditions, determine the user's access environment and decide whether to apply the policy.
Location Conditions
You can choose from the following two items for the location (IP) condition:
- All Locations(default): Apply policy at all locations without specific location conditions
- Exception selection: To exclude only specific locations among all locations, specify the locations to be excluded through 'exception selection'.
- Select Registered Location: Select from the locations registered in the conditions section of the Security365 Management Center.
- Click 'Select a Location' to check the list of registered locations.
- [+Location Registration]: Click to add a new location condition
- Exception Selection: To exclude a specific location from the selected locations, use 'Exception Selection'
Time Condition
You can choose from the following two time conditions:
- All time(Default): Always apply policy without specific time limits
- Exception selection: To exclude only specific time zones among all times, specify the time to exclude through 'exception selection'.
- Select Registered Time: Select from the registered time in the conditions section of the Security365 management center.
- Click 'Select a Time' to check the list of registered times.
- [+Time Registration]: Click to add a new time condition
- Exception Selection: To exclude a specific time zone from the selected time, use 'Exception Selection'
Condition Management Notes
- The location and time conditions can be registered/deleted/edited in the [Condition Items] menu of the Security365 Management Center.
- Use exception selection to finely configure when complex conditions are required.
Execution Policy
Access Policy
- Set access permissions for assigned users and groups.
-
Desktop Registration
- Select whether to allow desktop registration.
-
Desktop Access
- Choose whether to allow access to the registered desktop.
-
Additional authentication methods
- Not in use: Accessing the target without additional authentication
- Email Verification:
- The authentication code input window appears, and the authentication proceeds.
- Time limit: 5 minutes
- If you do not receive the authentication code within the time, click 'Resend Authentication Code'
- OTP Authentication:
-
QR Code and Recovery Key Instructions for Initial Registration
-
Enter the authentication code after registration to proceed with authentication.
-
⚠️ When authentication fails
- "Authentication has failed." Display alert popup
- Unable to access the specified target
-
Isolation Security Policy
Set policies to control user behavior on the desktop. All behavior control items can choose whether to allow or block.
Behavior Control Item
Screen Marking
- Activation/Deactivation settings available
- When activated: Display a watermark containing username, email information, etc. on the screen.
- Data Leakage Prevention and Enhanced Accountability
Policy Settings
You can set the usage and validity period of this conditional policy.
Usage status
- use: The policy is activated and works immediately
- Not in use: The policy is disabled and not functioning
Expiration Date
- when not set: Operate indefinitely
- Expiration Date Usage:
- Checking the 'Expiration Date' item activates the calendar.
- Set the period by selecting the start date and end date.
- Policy operates only during the set period.
💡 Policy Application Priority
- If multiple policies conflict, the policy with a higher priority (a smaller number) will be applied.
- You can adjust the priority by dragging and dropping in the policy list.
- If multiple policies are set for the same conditions, the most restrictive policy takes precedence.
- Policy priorities are important for the effective management of policies, so they should be set carefully.
Priority Quick Move
After selecting a policy, you can quickly change the priority using the following methods.
- Move to top / Move to bottom: Move immediately to the top or bottom
- Priority Move Dropdown: Select the desired number to move directly to a specific location
⚠️ Priority changes are not possible when search filters are applied. Please proceed after clearing all filters.
Download Policy Status
You can download the list of conditional policies as an Excel (.xlsx) file. This is provided separately from the existing JSON backup feature.
- Full Download: Save all registered policy information as an Excel file
- Download Search Results: Save only the results with the current search filter applied as an Excel file
💡 JSON download is for policy backup and restoration, while Excel download is used for status analysis and reporting purposes.