Creating Device Policies and Device Rules
29 min
introduction device policies define the minimum standard a device must meet to be considered compliant with ivanti neurons for zero trust access (nzta) device policies are used when defining a nzta secure access policy for an application you can create device policies and attach to them one or more device rules as required rules are created as one of the following types antispyware checks compliance to designated anti spyware requirements antivirus checks compliance to designated anti virus requirements command runs a command on the client device to check against an expected value (macos client devices only) cve check checks for protection against a list of publicly disclosed common vulnerability and exposure (cve) notices (windows client devices only) file checks for the existence of a known file on the client firewall checks compliance to designated firewall requirements hard disk encryption if encryption software is installed on the client device, this rule type checks the device's hard disks for applied encryption location checks the client device's geographic location matches, or avoids, a list of defined locations mac address checks the client device's mac address netbios checks the client device's netbios domain name network checks the client device complies with a defined ip address and netmask range os checks the client device’s operating system meets a defined minimum standard process checks for the existence of a known process on the client port checks the client device's network interface ports patch management if patch management software is installed on a client device, this rule type checks for the existence of missing software patches registry checks for a value in a registry key (windows client devices only) risk sense supports allow access, block access and notify based on the risk level system integrity checks the system integrity of the client device (macos client devices only) time of day checks resource access requests against compliance with a time based access schedule restrictions exist for rule type availability on the following ivanti secure access client platform variants android clients are limited to rules based on jail break root and os ios clients are limited to rules based on jail break root , os , and time of day nzta includes a number of built in device rules and policies relating to antivirus software, suitable for general use to learn more, see the tenant admin guide creating device policies you can create device policies and attach to them one or more device rules as required to learn more on creating device rules, see creating device rules to create a device policy log into the controller as a tenant admin from the nzta menu, select the secure access icon, then select manage devices > device policies the device policies page appears this page lists all current device policies click create device policy a form appears to enable you to create the device policy at any point during this process, you can reset the form data by selecting reset fields enter a name for the device policy add a description for the device policy select each of the listed policy rules that are required in the device policy, or select create device rule to use the in line rule creation form to learn more about this process, see creating device rules docid\ hv3ap3c pt63gcmar5rmn (optional) in the rule requirement section specify for each end user device platform how you want to enforce your policy rules by choosing one of the following rule requirement options all of the above rules the end user device must comply with all rules defined in the policy any of the above rules the end user device must comply with at least one of the defined rules in the policy custom the end user device must comply with the conditions specified in a custom expression use the custom expression field to define an expression for the rules defined in this policy and how they should be evaluated you can use the boolean operators and, or and not, and also use parentheses to group or nest conditions the following is a list of sample custom expressions customexpr (customexpr) not customexpr customexpr or customexpr customexpr and customexpr as an example, where a policy has associated with it the rules "rule1", "rule2", and "rule3", the following expression is valid rule1 and (not rule2 or (not rule3)) when using custom expressions, consider the following points using not when using " not expr ", the negated expression evaluates to true if the outcome of expr is false and evaluates to false if the outcome of expr is true and, or, not precedence these operators are evaluated from highest to lowest precedence in this order not (from right), and (from left), or (from left) a combination of any device rule is allowed in an expression, except location, time of day, and network rules for example, the following expressions are not allowed windows process and locationrule windows process and networkrule windows process and time of day rule after you have set a platform and rule requirement, select apply to add the entry then, repeat this procedure if you want to add any rule requirements for other device platforms if you intend to add multiple rules of varying types to a device policy, be aware that individual rules might not by themselves guarantee allowed or denied access to an application depending on the outcome of other evaluated rules in a device policy, and the rule requirements settings configured here (optional) to provide custom remediation instructions for the policy, tick enable custom instruction and enter your remediation text into custom instruction this option also requires selection of a target platform these instructions are presented through ivanti secure access client when a device compliance check fails based on this policy \ this feature is applicable to windows and mac device policies only also note that custom instructions are restricted to a 500 byte limit and can contain only plain text or an html document with href links select create device policy the new device policy appears in the list of device policies repeat steps 3 7 to create all required device policies creating device rules before you begin, decide what kind of rule you want to create for each rule type, make sure you have the supporting parameters for example, if you are creating a network rule, make sure you know the ip address and netmask range you want to apply to create a device rule log into the controller as a tenant admin from the nzta menu, select the secure access icon, then select manage devices > device policies the device policies page appears this page lists all device policies and the associated rules click create device policy fill the create device policy form that appears for details, see creating device policies docid\ hv3ap3c pt63gcmar5rmn at any point during this process, you can reset the form data by selecting reset fields click create device rule the create device rule form appears create device rule select rule type and select one of the following options antispyware antivirus command cve check file firewall hard disk encryption location mac address netbios network os process port patch management registry risk sense system integrity time of day enter a rule name for your device rule (optional) enter a rule description for your device rule the remaining options are dependent on the rule type you selected for antispyware and firewall rules, see options for antispyware and firewall rules for antivirus rules, see options for antivirus rules for command rules, see options for command rules for cve check rules, see options for cve check rules for file rules, see options for file rules for hard disk encryption rules, see options for hard disk encryption rules for location rules, see options for location rules for mac address rules, see options for mac address rules for netbios rules, see options for netbios rules for network rules, see options for network rules for os rules, see options for os rules for process rules, see options for process rules for port rules, see options for port rules for patch management rules, see options for patch management rules for registry rules, see options for registry rules for risk sense rules, see options for risk sense rules for system integrity rules, see options for system integrity rules for time of day rules, see options for time of day rules select create rule to create the device rule the new rule is added to the list of device rules options for antispyware and firewall rules select platform and select one of the following options windows mac using the selected platform, nzta populates the lists of vendors and products that can be selected for this rule (optional) select select vendors and use the drop down list to select or deselect one or more product vendors when done, select anywhere outside of the list each selected vendor is added to the panel below the drop down list to remove a selection, select the corresponding x indicator (optional) select select products and use the drop down list to select or deselect one or more products when done, select anywhere outside of the list each selected product is added to the panel below the drop down list to remove a selection, select the corresponding x indicator while both vendor and product fields are optional, you must select at least one vendor or product for your rule (optional) to set advanced options for this rule, select advanced configuration the following options are provided enable monitoring of this rule in ivanti secure access client options for antivirus rules select platform and select one of the following options windows mac using the selected platform, nzta populates the lists of vendors and products that can be selected for this rule (optional) select select vendors and use the drop down list to select or deselect one or more product vendors when done, select anywhere outside of the list each selected vendor is added to the panel below the drop down list to remove a selection, select the corresponding x indicator (optional) select select products and use the drop down list to select or deselect one or more products when done, select anywhere outside of the list each selected product is added to the panel below the drop down list to remove a selection, select the corresponding x indicator while both vendor and product fields are optional, you must select at least one vendor or product for your rule select enforcement level and select one of the following options high moderate low (optional) to set advanced options for this rule, select advanced configuration the following options are provided add a maximum allowed time limit since the last successful system scan, in days add a maximum allowed age limit for the most recent virus definition file update, either by number of available updates or by number of days enable monitoring of this rule in ivanti secure access client options for cve check rules this rule type is applicable to windows devices only select one of the following options to check all supported cves, select require all supported cve checks to check a list of specific cves, select check for specific cve , then use the select cve checks drop down control to select or deselect cves to be included to remove a selected cve from the list, select the "x" button adjacent to the cve tag options for command rules this rule type is applicable to macos devices only in this release, command type is limited to "defaults read command" only this runs the /usr/bin/defaults read command on the client device enter a value in argument1 to represent the path of the property list file to read for example, /applications/utilities/terminal app/contents/info plist enter a value in argument2 to represen t the property key name for example, cfbundleshortversionstring enter one or more expected values to be returned by the command, as a comma separated list " " (wildcard) values are also accepted options for file rules this rule type is applicable to windows and macos devices only select platform and select one of the following options windows mac enter a full file name and path in file name for example, "c\ test txt" or "/users/exampleuser/downloads/test txt" select checksum type and select one of the following options md5 sha256 enter the checksum value for the file select mode and select one of the following options allow select this to allow access where the file exists and is valid deny select this to deny access if the file does not exist or is invalid options for location rules select mode and select one of the following options allow select this to enable access for devices identified as being present at one of the set locations in the rule deny select this to disallow access for devices identified as being present at one of the set locations in the rule use the "add a location" section to define one or more geographic locations to which the current mode applies select a country , state (optional), and city (optional) to add the location, select add repeat the above steps for each location you want to add to the rule multiple "allow" and "deny" locations are possible in a single rule, with each added location identified by a green (allow) or red (deny) tag in the list to remove a location, select the "x" button adjacent to the location tag options for hard disk encryption rules this rule type is applicable to windows and macos devices only select the device platform to which this rule applies select the vendors and associated encryption products you want this rule to check choose which hard drives you want the rule to check to check all drives detected on the client device, select all drives to check specific drives on the client device, select specific drives , then enter the drive identifiers required select advanced configuration to provide additional rule configuration ( specific drives only) to ensure the rule does not trigger a failure where one or more of the specified drives are not detected, select consider policy as passed if the drives are not detected to ensure the rule does not trigger a failure where detected drives are currently undergoing encryption, but are not yet fully encrypted, select consider policy as passed if the drive encryption is in progress options for mac address rules select platform and select one of the following platform options windows mac enter the mac address as a comma separated list (without spaces) of mac addresses in the form hh\ hh\ hh\ hh\ hh\ hh where the hh is a two digit hexadecimal number duplicate mac addresses are not supported select mode and select one of the following options allow select this to enable access from a listed mac address deny select this to disallow access from a listed mac address options for netbios rules select platform and select one of the following platform options windows mac enter the netbios domain names as a comma separated list (without spaces) of domain names each name can be 15 characters duplicate names are not supported select mode and select one of the following options allow select this to enable access from a listed netbios domain name deny select this to disallow access from a listed netbios domain name options for network rules enter the ip address and netmask from which you want to either allow or deny access multiple ip addresses are not supported select mode and select one of the following options allow select this to enable access for the given ip address and netmask deny select this to disallow access for the given ip address and netmask options for os rules select platform and select one of the following options windows mac ios android the remaining fields are dependent on your choice of platform where you selected a platform of windows or mac , select os name and select an operating system edition for example, "windows 2008" or "macos mojave" then, select os version and select the version number or service pack associated with that edition of the operating system for example, "sp2" or "10 14 3" to not enforce the version number, select "ignore" where you selected a platform of ios or android , select equality and select one of the following options pertaining to how you want to enforce operating system versions numbers above below equal then, select os version and select the version number you want to check against options for process rules this rule type is applicable to windows and macos devices only select platform and select one of the following options windows mac enter a process name for example, "explorer exe" select checksum type and select one of the following options md5 sha256 enter the checksum value for the process executable select mode and select one of the following options allow select this to allow access where the process exists and is valid deny select this to deny access if the process does not exist or is invalid options for port rules select platform and select one of the following platform options windows mac enter the ports as a comma separated list (without spaces) of ports port ranges are supported duplicate ports are not supported select mode and select one of the following options allow select this to enable access from a listed port deny select this to disallow access from a listed port options for patch management rules this rule type is applicable to windows and macos devices only select the device platform to which this rule applies select the vendors and associated patch management products you want this rule to check the presence of (optional) select advanced configuration to view more options choose the severity levels of missing patches you want to check in this rule critical important moderate low unspecified/unknown for some products, the patch severity level might not be detectable in this case, select unspecified/unknown to detect missing patches choose the category types of missing patches you want to check in this rule security update rollup update critical update regular update driver update service pack update unknown for some products, the patch category might not be detectable in this case, select unknown to detect missing patches options for registry rules this rule type is applicable to windows devices only select rootkey and select one of the following options hkey local machine hkey users hkey current user hkey current config hkey classes root enter a subkey for the registry path select key type and select one of the following key types string dword binary enter a key name enter a value for the registry key tick the 64 bit checkbox to use the 64 bit registry store leave this checkbox unticked to use the 32 bit registry store the following example values would create a rule to ensure the client device contained a registry key hkey local machine\software\pzta with a value 123 field value rootkey hkey local machine subkey software key type string key zta value 123 64 bit ticked options for risk sense rules risksense provides vulnerability management and prioritization to measure and control cybersecurity risk the cloud based risksense platform uses a foundation of risk based scoring, analytics to identify critical security weaknesses with corresponding remediation action plans, dramatically improving security and it team efficiency and effectiveness integrating risksense's vulnerability risk rating (vrr) scores with nzta provides an additional layer of security by isolating and preventing vulnerable devices from connecting to the zta network thereby protecting enterprise resources this rule type is applicable to windows only enter the rule name enter the rule details select risk level and select one of the following options low medium high critical select action and select one of the following options allow select this to allow access when the risk level is low or medium block select this to block the access based on the risk level notify select this to notify the user about the risk identified options for system integrity rules this rule type is applicable to macos devices only to enable this rule type, select enable options for time of day rules this rule type applies a resource restriction (allow or deny access) based upon a specified period frequency within a defined date and time range enter the following parameters select the frequency with which you want the rule to apply inside the date range you specify custom apply the rule for the whole period continuously between the start date/time and end date/time daily apply the rule for the specified days in each month enter a comma separated list of numerical days (1 31), for example "1,5,19,28" weekly apply the rule for the specified days of each week for select days , select the checkbox for each day on which you want the rule to apply monthly apply the rule for all days in the specified months for month , select one or more months from the drop down list enter the start date and end date to apply to the selected period frequency for custom rules, the date range entered here is continuous for daily, weekly, and monthly rules, each day in the range is executed individually according to the selected times and frequency start and end date values are optional for daily , weekly , and monthly frequencies if not specified, the rule applies indefinitely enter the start time and end time to apply to the selected period frequency for custom rules, the times are applied with the corresponding start and end date to provide a continuous period within which the rule applies for daily, weekly, and monthly rules, the times are applied for each day in the schedule all times are applied as utc timezone values your zta gateways must also use utc time for the rule schedule to apply time periods for daily, weekly, and monthly rule frequencies are restricted to the 24 hours in a single day, such that you cannot enter an end time that is earlier than the start time therefore, in cases where you want to apply a rule allowing access for a time period that spans across midnight into the next day, add separate rules for each day in the range covering the time period for that day only for example, to allow access during the period 21 00 monday until 12 00 tuesday, configure the following rules rule 1 period weekly , days monday , start time 21 00 , end time 23 59 , mode allow rule 2 period weekly , days tuesday , start time 00 00 , end time 11 59 , mode allow choose the mode that should apply during the specified times allow devices accessing resources to which this policy is applied are authorized only during the selected days and times deny devices accessing resources to which this policy is applied are not authorized during the selected days and times next steps after you have created your device policies, move on to define your applications see creating applications and application groups
