Skip to main content

Conditional Policy for URL Input Field

The conditional policy for the URL input field is a feature that allows for detailed management of access rights and isolation security policies for the created URL input field. Access can be controlled based on conditions such as members, location, and time, and various security policies can be applied.

Table of Contents

Basic

Policy Settings

Management


Basic Screen Composition

The conditional policy screen is composed as follows.

  • Conditional Policy Tab: A tab where you can apply conditional policies to apps created in Home
  • Priority: Display policy priorities (the smaller the number, the higher the priority)
  • Add Policy: Top left of the[➕ 정책 추가]Create a new policy with the button
  • Search: Policy name, members, target URL/category, usage status, and various other conditions can be searched.
  • Policy Application Status Inquiry: Policy List Top Button Bar of[정책 적용 현황 조회]View application history by policy and policies not applied with the button

You can search for policies based on various criteria, including not only the policy name but also members, target URL·category, conditions, enforcement policies, and usage status.

Types of Search Filters

FilterSearch MethodExplanation
Policy NameIncluded SearchSearch for policy names containing keywords
MembersInclude Search + Dropdown SelectionUser (Name·Email), Group, Department Search, Assignment/Exception Classification Selection, Multiple Selection Available
Target - URLIncluded Search + Dropdown SelectionSearch by registered URL name and address,모든 URLSelectable fixed values, multiple selections possible
Target - CategoryDropdown SelectionSearch by registered web category name
UsageDropdown SelectionUse / Not Use Selection
conditionIncluded Search + Dropdown SelectionSearch by location (IP), time, and device conditions, multiple selections available
Execution PolicyDropdown SelectionAccess Allow/Deny, Isolation Security Policy (All Allowed/Restricted Use), Additional Authentication Method Selection, Multiple Selections Possible

Target Search Details

  • URL Search: Enter the name or address of the registered URL, and a list will be displayed below with a partial match search.모든 URLis fixed at the bottom of the dropdown and is included in the search results only when selected directly. When searching for a specific URL, only the policies directly set for that URL will be searched,모든 URLThe policy is not included.
  • Category Search: Select a web category from the dropdown. Individual URLs belonging to the category are excluded from the search targets.

Member Search Details

  • When you enter a name or email in the search box, results are displayed in real-time in a dropdown.
  • 할당 / 예외You can search by distinguishing between cases where a tab is selected and assigned to a policy and cases that are exception handled.
  • 모든 구성원is fixed at the bottom of the dropdown and is included in the search results only when selected directly.

Detailed Condition Search

  • Location:위치 제한 없음or enter a registered location name to search. The results are위치명 | IP 범위It will be displayed in the format.
  • Time:시간 제한 없음You can search by entering the registered time name. The results are시간명 | 시간 범위It will be displayed in the format.
  • Device:모든 디바이스, Desktop, Tablet, MobileSelect 중.

Execution Policy Search Details

  • Access Policy: Allow Access / Block Access Selection
  • Isolation Security Policy: Allow All / Select Limited Use
  • Additional authentication methods: None / Email verification / OTP verification selection (applies only to access permission policies)

Search Condition Combination Rules

  • Between filters (AND condition): If you set multiple different filters, only the policies that satisfy all conditions simultaneously will be displayed.
  • Within Filter (OR condition): When multiple items are selected within the same filter, any policy that matches at least one will be displayed.
  • Each set condition is displayed in the form of tags, and the tags'×You can remove individual conditions with the button.

⚠️ Priority changes are not possible when search filters are applied. To change the priority, please clear all search filters.

Policy Application Status Inquiry

At the top of the policy list[정책 적용 현황 조회]Clicking the button opens a modal where you can view the application history of conditional policies and the non-applied policies by period.

Modal Configuration

  • Modal Title: Policy Application Status Inquiry
  • Query Period :[시작일] ~ [종료일]Calendar Selection
  • Tab: Applied Policies / Unapplied Policies
  • Download : Top right[↓]Download Excel of search results with button

Applied Policies Tab

For the specified period, to the user**Policies Actually Applied (Heating)**Displays the list.

Table Column Configuration

columnExplanation
PriorityCurrent priority number of the policy
Policy NamePolicy Name (Click to move to the edit details screen)
ExplanationPolicy Description
Policy Usage StatusCurrently in use / Not in use status
Application Frequency ↑↓Number of times the policy was applied during the inquiry period (thousands unit comma display, sortable)
Recent application date ↑↓The most recent date the policy was applied within the inquiry period (sortable)

💡 The application count and the most recent application date columns can be sorted in ascending/descending order. When sorting the application count in ascending order, policies with lower usage frequency can be quickly identified at the top.

How to use

  1. [정책 적용 현황 조회]Button Click → Modal Open
  2. Setting the query period (start date ~ end date)
  3. 적용된 정책Check Tab
  4. Sort by clicking the header of the application count or the most recent application date column.
  5. You can navigate to the detailed editing screen of the corresponding policy by clicking on the policy name.
  6. top right[↓]Download Excel of query results by clicking the button

Unapplied Policy Tab

during the set period**Policy that has never been applied (heating)**Displays the list.

Table Column Configuration

columnExplanation
PriorityCurrent priority number of the policy
Policy NamePolicy Name (Click to move to the edit details screen)
ExplanationPolicy Description
Policy Usage StatusCurrently in use / Not in use status

How to use

  1. [정책 적용 현황 조회]Button Click → Modal Open
  2. Setting the query period (start date ~ end date)
  3. 미적용된 정책Tab Selection
  4. Check the list of policies that were not applied even once during the specified period.
  5. You can navigate to the detailed editing screen of the corresponding policy by clicking on the policy name.
  6. top right[↓]Download Excel of query results by clicking the button

💡 By periodically checking for unimplemented policies and organizing unnecessary ones, you can reduce policy management complexity and optimize the security environment.

Get Policy

You can import and register a JSON file (single policy) or a ZIP file (multiple policies) that contains the backup of the conditional policy.

How to use

  • Download: Check item checkboxes > In the top button bar[정책 다운로드]Button Click
    • When selecting 1 item: Download JSON file
    • When selecting 2 or more: Download as a ZIP file.
  • Import:[정책 가져오기]Click the button to select and register the backed-up JSON file or ZIP file.

➕ Add Policy

[➕ 정책 추가]Clicking will take you to the new conditional policy page, where you can set the following items.

  • Policy Basic Information
  • condition
  • Execution Policy
  • Settings

📌 Policy Basic Information

Policy Name

  • Name (required): Up to 20 characters allowed
  • Description (optional): Up to 200 characters can be entered.

The conditional policy name is a required value, and you must enter a unique name to identify the policy.

Members

Set users or groups to include or exclude in this conditional policy.

  • allocation
    • All users: Apply policy to all users
    • Select user or group: Search and select a specific user or group
      • Search by entering a username or group name in the search box.
      • The selected user or group can be confirmed in the box below.
  • Exclusion
    • Specify users or groups to exclude from the policy
    • Excluded members are not subject to the policy regardless of allocation.
    • The 'All Users' option cannot be used in the exclusion items.
    • If you select members to exclude, you can check the list of excluded members in the box below.

Target

Select which targets to apply this conditional policy to.

Determining the Scope of Application

  • All sites accessed through the address bar
    • Apply policies to all websites accessed through the URL input field
    • Used when setting basic policies such as total block or total allow.
    • Usage Example: Create a site-wide blocking policy (set to low priority), create a separate policy for specific sites to allow (set to high priority)
  • 2nd Selection: Specify Specific Target (Displayed Only When Selecting Target Directly)
    • Registered Sites/Groups: Select individual sites or groups registered in the URL list. Use this when you want to apply policies to specific sites only.
      • Setting method: Click 'Select the sites registered in the address bar' → Select the desired site/group
    • Web Category: Apply policies by category. Efficient when applying uniform policies to sites of the same nature.
      • Setting Method: Click 'Select Web Category' → Choose the desired category (e.g., Games, Entertainment, Business, Academic Information, etc.)
      • Advantages: When a new site is classified into the corresponding category, policies are automatically applied.

Policy Setting Strategy Example

  • Scenario 1: Basic Blocking + Selective Allowance
    • Policy A (Priority: 2) — Target: "All sites accessed via the address bar", Enforcement Policy: Access Block
    • Policy B (Priority: 1) — Target: "Direct Selection of Target" → Business, Academic Information category, Implementation Policy: Allow Access
  • Scenario 2: Differential Control by Category
    • Game/Entertainment Blocking Policy — Target: "Direct Selection of Target" → Games, Entertainment Category, Enforcement Policy: Block Access During Work Hours
    • Business Site Allowance Policy — Target: "Direct Selection of Target" → Business, Cloud Category, Enforcement Policy: Access Allowed

condition

Set conditions such as location and time to be used for policy judgment. Based on the assigned conditions, determine the user's access environment and decide whether to apply the policy.

Location Conditions

You can choose from the following two items for the location (IP) condition.

  • All Locations (Default): Apply policy at all locations without specific location conditions.
    • Exception Selection: To exclude only specific locations among all locations, specify the locations to be excluded through 'Exception Selection'.
  • Select Registered Location: Choose from the locations registered in the Conditions section of the Security365 Management Center.
    • Click 'Select a Location' to check the list of registered locations.
    • [+위치 등록]: Click to add a new location condition
    • Exception Selection: Use 'Exception Selection' to exclude specific locations from the selected locations.

Time Condition

You can choose from the following two time conditions.

  • All Time (Default): Always apply policy without specific time limits
    • Exception Selection: To exclude only specific time zones among all times, specify the time to be excluded through 'Exception Selection'.
  • Select Registered Time: Choose from the registered times in the conditions section of the Security365 Management Center.
    • Click 'Select a Time' to check the list of registered times.
    • [+시간 등록]: Click to add a new time condition
    • Exception Selection: Use 'Exception Selection' to exclude specific time zones from the selected time.

Condition Management Notes

  • The location and time conditions can be registered/deleted/edited in the [Condition Items] menu of the Security365 Management Center.
  • Use exception selection to finely configure when complex conditions are required.

Execution Policy

Access Policy

Sets the access permissions when a member of the subject to which this conditional policy applies attempts to connect.

Access Permission

  • Access Block: Completely block URL access under the specified conditions.
  • Access Allowance: Allows URL access and additional authentication methods can be configured.

Additional authentication methods (can only be set when access is allowed)

  • Not used: Accessing the target without additional authentication
  • Email Verification: An input field for the verification code appears, and the verification proceeds.
    • Time limit: 5 minutes
    • If you do not receive the verification code within the time limit, click 'Resend Verification Code'
  • OTP Authentication: Guidance on QR code and recovery key during initial registration, proceed with authentication by entering the authentication code after registration.

⚠️ If authentication fails, a notification popup stating "Authentication has failed." will be displayed, and access to the target will not be possible.

Isolation Security Policy

Set policies to control user behavior when accessing the URL. For all behavior control items, you can choose whether to allow or block.

Behavior Control Items

  • Keyboard input: Allow/Deny Settings
    • When blocked: "Input via keyboard is prohibited by policy." notification is displayed at the bottom center.
  • Site Navigation: Allow/Deny Settings
    • Allowed: Free movement to all sites
    • Block: Access not allowed outside the connected domain
    • When accessing a blocked site: Redirect to the "This action is prohibited by policy." guidance page.
  • File Upload: Allow/Deny Settings
    • Additional settings when allowed
  • File Download: Allow/Deny Settings
    • When blocked: "This action is prohibited by policy. Downloading is prohibited by policy." Move to the guidance page, return to the previous screen with the close button.
    • Additional settings when allowed
      • Extension restriction: Control file extensions using block / allow method (belowExtension Restrictions — Block / Allow MethodReference)
      • Repository Selection
        • My PC File Folder: Download files to the user's local PC
        • SHIELDGate File Box: Save files to SHIELDrive storage (storage can be specified)
        • SHIELDViewer: A feature that allows you to preview files in SHIELDViewer when downloading files.
          • Sub-option — Download button on the preview success screen
            • PDF Download: Allow/Block conversion of the original to PDF (Default: Allow)
            • Download Original: Allow/Block Download of Original Document (Default: Block)
            • CDR Download: Allow/Block Download After Decontamination Processing Through CDR (Default: Block)
          • Sub-options —Provide download button when preview is not available(PDF · Original · CDR Allow/Block respectively, belowProvide download button when preview is not availableReference)
          • Operation: A preview of SHIELDViewer opens in a new tab, displaying only the corresponding download button based on the set options.

⚠️ SHIELDGate file storage (SHIELDrive storage) precautions

  • The member must be assigned to SHIELDrive storage to be available.
  • Unable to download files if there is no storage allocation
  • Storage allocation can be configured in the admin page by clicking on the Files menu and then selecting the Storage Management menu.

Only approved files are allowed

When using upload approval in SHIELD Drive, the files to be uploaded to the business system**Limited to files in the approved repository (approved).**does.

Setting valueFile Box Screen
AllowShow only repositories designated as approved
Block (default)Show all storage allocated to the user
  • Approval is obtained in advance by the user on SHIELD Drive. SHIELD Gate does not process approval requests or approvals.
  • The existing policy is차단It operates as a value, so there is no change.

⚠️ When using grade control togetherOnly repositories that meet both the allowed grade and approval conditionsIt will be displayed. If there is no rating assigned upon approval, the approval box will appear empty, so please check the rating assignment of the approval box.

Provide download button when preview is not available

When encountering a document that cannot be opened with SHIELDViewer, you can separately configure which download button to provide.

Existing download options (PDF · Original · CDR) arePreview screen opened normallyControls the button. This option isPreview unavailable screenIt only controls the button, so it can be set to prevent downloading the original under normal circumstances and only allow downloads when previewing is not possible.

screenReferencing OptionsExposed Button
Preview successfulExisting download optionsButton set to allowed
Preview not availableProvide download button when preview is not availableButton set to allowed (excluding PDF)

Applicable Situations

  • Unsupported extension (exe, zipetc.)
  • Excel cell count exceeded (total sheet limit 1 million cells)

⚠️ Preview unavailable screen shows**The PDF download button is not displayed.**Documents that have not been previewed do not have conversion results, so there is no PDF available for provision. Even if PDF is set to allowed, the buttons that are actually displayed are Original and CDR.

Existing Policy

The existing policy is**Copy the existing download option values as they are.**It works. If you do not change the settings, there will be no change in operation.

The default values for the new policy are the same as the existing options — Allow PDF · Block Original · Block CDR.

Extension Restrictions — Block / Allow Method

Select the method for controlling file upload and download extensions.격리 보안 정책 > 파일 보안 > 파일 업로드 / 파일 다운로드ofExtension LimitationsSet in.

Select Extension Control Method

Select one of the two methods from the method selection button at the top of the extension limit.

  • Block Extension: Only the registered extensions are blocked, and all others are allowed. (Existing method)
  • Allowed extensions: Only the registered extensions are allowed, and all others are blocked.

Registering Extensions

  • Enter the extension one by one in the input field and**[+]**If you add it with a button, it will be displayed in the form of a chip.
  • Enter only the file extension. For example:png ( .pnglike thispngwill be registered.)
  • The input box guidance is displayed as "Enter the extensions to block." / "Enter the extensions to allow." depending on the method.
  • If you enter an already added extension again, a message will be displayed saying "This extension has already been added."

⚠️ File upload and file download**Cannot be set as "Allowed Extensions" at the same time.**If one side is changed to "Allow Extensions," the other side will automatically switch to "Block Extensions."

User Guidance When Blocked

If the file is blocked due to extension restrictions, a message "Attachment Request Failed" will be displayed on the user screen, along with the following information.

  • Allowed extensions: (List of extensions registered as allowed in the "Allowed Extensions" method)
  • Blocked file: (blocked file name)

Clipboard Access

Controls copy/paste between the isolated browser and the user PC. If clipboard access is allowed, copy and paste can be set in 3 stages respectively.

OptionvalueAction
Copy in the isolated browserAllowCopy from the isolated browser clipboard to the PC clipboard.
Internal AllowanceThe isolation browser only copies to the clipboard of the browser and does not copy to the PC clipboard.
BlockYou cannot copy or cut in the isolated browser.
Paste in Isolation BrowserAllowYou can paste the contents of the PC clipboard into an isolated browser.
Internal AllowanceYou can only paste the contents of the clipboard from the isolated browser into the isolated browser.
BlockCannot be pasted into the isolated browser.
  • Each direction is set independently. The ability to copy → paste (internal movement) within the isolated browser is determined by the combination of the two values.
  • The existing allow/block settings are respectively허용 / 차단It continues with. The operation of the existing policy does not change.
  • 클립보드 액세스If not allowed, the entire direction setting will be disabled, and when blocked, a message saying "Clipboard usage is prohibited by policy." will be displayed at the bottom center.

Paste 내부 허용if set to

The contents of the PC clipboard are not transmitted to the isolated browser. Even if the user copies on the PC and pastes,Last copied content in the isolated browser clipboardThis will be entered.

Cutting

Cutting is**Copying and pasting are both allowed.**Only works in. Paste차단If set to __PH_0__, cutting will also be blocked. If cutting occurs when there is no place to paste, only the original will be deleted, resulting in data loss.

Operation by Setting Combination

copyPasteExportImportInternal MovementCutting
AllowAllowOOOO
AllowInternal AllowanceOXOO
AllowBlockOXXX
Internal AllowanceAllowXOXO
Internal AllowanceInternal AllowanceXXOO
Internal AllowanceBlockXXXX
BlockAllowXOXX
BlockInternal AllowanceXXXX
BlockBlockXXXX

⚠️ 복사 = 내부 허용 + 붙여넣기 = 허용You cannot paste content copied from an isolated browser in the combination. If internal copy-pasting is needed, pasting is also required.내부 허용Set to.

⚠️ 복사 = 내부 허용 + 붙여넣기 = 차단The combination is saved, but the copied content cannot be pasted anywhere. To prevent copying itself, you need to stop copying.차단Set to.

User selection after warning

Copy and Paste차단If set to, under경고 후 사용자 선택You can check.

If checked, a confirmation modal will be displayed when the user attempts to copy and paste, and the user will계속 진행or취소Select.

itemContent
Location격리 브라우저에서 복사 · 격리 브라우저로 붙여넣기of차단subordinate
formCheckbox (default: off)
Activation Conditionsthe direction차단only when.허용 · 내부 허용cannot be selected in
Setting UnitIndependent in each direction. You can only apply copy or paste.

Action Based on User Selection

User Selectionresult
Continue 진행Copying and pasting will be performed.
CancelNo action is performed.

Both results are recorded in the log. The administrator can distinguish and verify the cases that proceeded after the warning and those that were canceled in the log.

⚠️ 경고 후 사용자 선택is an action blocked by the administrator**Settings that allow users to pass themselves.**It is. Use this when you want to maintain the block while allowing exceptions and keeping a record of that fact.

Session Maintenance

After the idle time has passed, the isolated browser session will be reclaimed. Set the retention time according to the nature of the screen, and choose how to display the screen after the session has been reclaimed.

itemSettings
Session PersistenceUsed / Unused. If unused, all values below will not be applied.
Viewing Screen Retention TimeApplied to the screen with no keyboard input (in minutes)
Work Screen Retention TimeApplied to the screen where keyboard input has occurred at least once (in minutes)
Idle Processing Method정지 화면(default) /잠금 화면

Screen Judgment and Maintenance Time Criteria

  • A screen where keyboard input has occurred at least once is classified as a working screen and will not revert back to a viewing screen. The type of input is not distinguished.
  • Retention time isElapsed time since the last operationCalculates as __PH_0__. After opening the screen, it is not the total usage time.
  • It is not considered idle while the video is playing.
  • Calculations are done individually for each screen (tab). If one screen is stopped, it does not affect other screens.
  • The judgment result and remaining time are not displayed on the user screen.

Idle Processing Method

MethodScreen after session retrieval
Stop Screen (Default)The last screen you were viewing is frozen as it is. It does not display any guidance message.
Lock ScreenA solid color background covers the last screen and displays a guide message. It is used in business systems where the screen content needs to be obscured.
  • When the user clicks on the screen or scrolls, a notification saying "You have not used it for a certain period of time, and the session will be resumed." is displayed in the lower right corner, and the previous address is reopened in a new session. Once the page is opened, the notification automatically disappears.
  • The mouse cursor movement alone will not resume.
  • Only the previous address will be restored. The site login status, content being entered, and scroll position may not be restored.
  • If it cannot be resumed due to resource shortage or simultaneous connection limit, you can try again with the message "It cannot be resumed at this time."
  • Session retrieval and resumption are all recorded in the logs.

Setting Scope and Existing Policies

  • both valuesCompany-specific upper limitis limited. The upper limit is set by SOFTCAMP at the company level.
  • The existing policy applies the previously set retention time to both the viewing and working values without any changes in operation. To keep the working screen for a longer time, please change the working screen retention time directly.

Screen Marking

  • Activation/Deactivation settings available
  • When activated: Display a watermark containing information such as username and email on the screen. Strengthen data leakage prevention and accountability tracking.
  • The screen mark display method can be customized in the 'Business System > Security Screen Settings > Screen Marking/Watermark Settings' menu.

Print Watermark

  • Available for use/not use setting
  • When activated: Display a watermark containing information such as username and email on the screen. Strengthen data leakage prevention and accountability tracking.
  • The watermark display method can be customized in the 'Business System > Security Screen Settings > Screen Marking/Watermark Settings' menu.

Video Conference Mode

  • Activate in business systems that require video conferencing
  • Activation Limitations: SHIELDGate shortcut function unavailable (shortcut icon in the upper right corner not provided)
  • Settings for Optimizing Video Conference Performance

Context Menu

  • Available for use/not use setting
  • When activated: Individually control the context menu items displayed when right-clicking in the RBI browser by target.
  • Context Menu Settings > Clicking the link opens the detailed settings slide. The current setting status is summarized text (e.g:32개 표시 | 2개 숨김) is indicated.

Context Menu Detailed Settings

Control the menu items to be displayed for each clickable target area individually with ON/OFF.

areaExplanation
Page Background AreaContext menu displayed on right-clicking empty space (Back, Forward, Refresh, Print, View Page Source, Inspect, etc.)
Text selection areaContext menu displayed after right-clicking on text after dragging (copy, print, etc.)
linkMenu displayed when right-clicking on a link (Open in new tab, Copy link address, etc.)
imageMenu displayed when right-clicking on an image (Save image, Copy image, etc.)
videoMenu displayed when right-clicking on the video (Play/Pause, Save Video, etc.)
AudioMenu displayed when right-clicking on audio (Play/Pause, Save Audio, etc.)
Input FieldContext menu displayed when right-clicking in the text input field (Cut, Copy, Paste, etc.)
  • Each item within the area is controlled by an individual ON/OFF toggle,전체 ON / 전체 OFFYou can toggle all items in the area at once with the button.
  • bottom초기화Clicking the button will reset all items to their default values.
  • If all items in a specific area are OFF, the context menu will not be displayed when you right-click in that area.
  • Copy차단If set to __PH_0__, the copy-related menu items for images, videos, and audio will be hidden from the context menu.

⚠️ Shortcut Integration: If you set the menu item to OFF, the associated keyboard shortcuts will also be blocked. (e.g.: Print item OFF →Ctrl + PBlock)

⚠️ Browser Top Button Restrictions: Setting the back/forward/refresh menu items to OFF does not block clicks on the navigation buttons at the top of the browser. Shortcuts(Alt+←, F5Only (etc.) will be blocked.

  • Video/Audio: You can control the basic playback-related menu for video and audio, and it is applied based on the standard context menu items of the browser.
  • Shortcut keys: The browser's default shortcut keys associated with context menu items are controlled together, while custom shortcut keys are excluded.

Data Security — Sensitive Information Input Inspection

Input Prompt Firewall (formerly Custom Overlay) feature checks sensitive information (such as regular expressions) in the text entered by the user,Before the original text is delivered to the siteControls. This item is displayed according to company settings.

Settings

  • Input Sensitive Information Check (ON/OFF): This turns the check on or off for the policy target. It operates as follows depending on the check method.
  • Self-Check (Regular Expression): When the check is turned ON, you can set the regular expression selection (choose from the list registered in sensitive information management, new additions possible) and log options.
    • Log storage scope: All cases / Only blocked cases
    • User input content included: Whether to include the text entered by the user in the inspection log.
  • External Integration: Only the inspection ON/OFF setting is configured, while regular expressions and log detail settings are handled by the external inspection system.

If this item (Data Security > Input Sensitive Information Check) is not visible, you need to enable the input prompt firewall. Please contact SOFTCAMP.

Core Values

  • Prevention: Unlike the existing method that detects after transmission, it inspects and blocks before the input is sent externally.
  • Original text not leaked: Designed to only transmit results that have passed inspection, preventing sensitive information from being sent to external services or remote screens.
  • Bypass Blocking: It prevents bypassing inspections by performing checks and judgments at control points rather than on the user local, thus blocking local tampering to skip inspections.
  • Judgment·Record: It judges text·files as pass·block and leaves the entire process in the audit log.

Policy Settings

You can set the usage and validity period of this conditional policy.

Usage status

  • Use: The policy is activated and takes effect immediately.
  • Not in use: The policy is disabled and does not operate.

Expiration Date

  • If not set: Operates indefinitely
  • Expiration Date Usage: Checking the 'Expiration Date' item activates the calendar.
    • Set the period by selecting the start date and end date.
    • Policy operates only during the set period.

💡 Policy Application Priority

  • If multiple policies conflict, the policy with a higher priority (a smaller number) will be applied.
  • You can adjust the priority by dragging and dropping in the policy list.
  • If multiple policies are set for the same conditions, the most restrictive policy takes precedence.
  • Policy priorities are important for the effective management of policies, so they should be set carefully.

Priority Quick Move

After selecting a policy, you can quickly change the priority using the following methods.

  • Move to Top / Move to Bottom: Move instantly to the very top or very bottom
  • Priority Move Dropdown: Select the desired number to move directly to a specific position.

⚠️ Priority changes are not possible when search filters are applied. Please proceed after clearing all filters.

Download Policy Status

You can download the list of conditional policies as an Excel (.xlsx) file. This is provided separately from the existing JSON backup feature.

  • Download All: Save all registered policy information as an Excel file
  • Download Search Results: Save only the results with the current search filter applied as an Excel file.

💡 JSON download is for policy backup and restoration, while Excel download is used for status analysis and reporting purposes.

Management of Default Execution Policy

This is a feature that allows you to pre-set and manage default values that are automatically filled in the execution policy and isolation security policy items when registering a new conditional policy. It reduces repetitive manual settings and prevents setting omissions and input errors.

Accessing the Default Value Management Screen

The button bar on the right side of the top of the policy list[집행정책 기본값 관리]Click the button.

[+ Policy Registration]  ...  [Execution Policy Default Management]

※ The URL input field and the app's default values are managed independently. Changing the default value in one menu does not affect other menus.

Default Value Setting Range

The items that can be set in the default value management screen are as follows.

itemWhether to apply default valuesNote
Policy Name / DescriptionUnique input for each policy
Members / TargetUnique designation for each policy
Conditions (Location·Time)Set directly for each policy
Execution Policy (Access Policy · Additional Authentication)
Isolation Security Policy (Keyboard, File, Clipboard, Session, Context Menu, etc.)
Settings (Usage Status · Validity Period)

Save Default Value

After setting the execution policy and isolation security policy items in the default value management screen,[저장]Click the button.

Actionresult
[저장]ClickThe current settings are saved as the default values for this menu. They will be automatically applied when registering new policies.
[취소]ClickReturn to the list screen without saving changes
Default value not set (initial)Display in system initial value (fully allowed, not set) state

Automatic application upon registration of new policy

[+ 정책 등록]When clicked, the execution policy and isolation security policy items are automatically filled with the default values saved. Enter the policy name, members, targets, and conditions, and register by modifying only the necessary items.

statusAction
When a default value is setExecution Policy · Isolation Security Policy has been reset to default.
If no default value is setInitialize to system default values (same as existing operation)
If manually modified after automatic applicationThe modified value takes precedence and does not affect the default value.

※ Automatic application only applies to initial value settings during new registration. It does not affect existing saved policies.

Apply default values in bulk to the selected policy

After selecting the policy with checkboxes in the list, the top button bar of[집행정책 기본값 적용]By clicking the button, you can overwrite the enforcement policy and isolation security policy items of the selected policy with the current default values in bulk.

How to use

  1. Select the checkbox for the policy to apply the default value from the list.
  2. in the top button bar[집행정책 기본값 적용]Click the button.
  3. Check the default values to be applied in the confirmation dialog (execution policy · isolation security policy summary).
  4. [기본값 적용]When you click the button, the default values for the selected policy will be applied immediately.

⚠️ The default values are saved immediately. The policy name, description, members, targets, conditions, and settings are not changed.

⚠️ If no default value is set, the system's initial value will be applied.