Skip to content

Manage Policies

Policies exclusively define reusable organization rules. Use them for sign-in behavior, security restrictions, network and access controls, update expectations, printing, and monitoring. Applications, Desktop Experience, appearance, kiosk behavior, and assignment belong to Blueprints and do not appear as Policy settings.

  1. Open Configuration > Policies.
  2. Select the Policy you want to change.
  3. Review each changed value and its effect on linked Blueprints.
  4. Expand Advanced settings only when you need a less common category. Only one category opens at a time.
  5. Select Save & Deploy. The bar names the version your edits become and how many Blueprints and computers follow this Policy. The confirmation lists every affected Blueprint; confirm, and Cybex creates a new version of each of them composed with the Policy change and rolls it out to its computers in one step. When your organization uses James, each version is prepared first and starts by itself as soon as preparation finishes. A Blueprint whose update is still running is skipped — its new version waits on the Deploy page until that update finishes.
  6. Select Save instead to record the Policy change without touching any computer. Every Blueprint that follows the Policy gets a prepared version; deploy them from the Deploy page, where you can also try each one on a test computer first.

Policy changes never bypass the release and rollout process: each Blueprint still gets its own immutable version and its own rollout, and the Deploy page shows every one of them.

Rename, delete, and revision information live under Management. Wi-Fi networks are managed under Advanced settings > Network and save immediately; they are not part of the Policy draft shown by the save bar.

A Policy can let people sign in to managed computers with their Microsoft Entra ID or Google Workspace account, either with a one-time sign-in code or with their directory password at the login screen. Directory connections and organization-wide local account groups are configured once under Settings > Sign-in sources. The Policy then selects the source its computers use. Follow Set up directory sign-in to choose a source, test the connection, and deploy the resulting Policy change safely.