New Policy
Navigate to the sidebar menu: Protection > Policies and click + Add policy button.
Creating a New Policy
This step is critical as it defines the fundamental behavior and scope of your new security profile. Fill out the fields as follows:
Policy Name
Enter a recognizable name for the policy.
- Example: "Guest Wi-Fi", "Office Staff - Standard", or "Strict Protection".
If you plan to have multiple policies, use a naming convention that helps you identify
Policy Type
Choose the baseline behavior for this profile. This choice determines whether you can customize the rules later.
- Standard: Select this option for maximum flexibility. A Standard policy allows you to fully customize every aspect of the protection.
When you select Standard, a Starting Template section will appear below. You must choose a baseline configuration:
Malware & Threats: Pre-configured to block malicious websites, phishing, and proxy bypass attempts.
Malware and Unwanted Contents: A broader protection profile that blocks malware and unwanted content categories, and automatically activates SafeSearch.
Start from scratch: Creates an empty policy with no preset rules, allowing you to build the configuration entirely from the ground up.
Best for: Most business networks, guest Wi-Fi, and custom use cases.
- Restricted: Select this option for a "locked-down" profile. In a Restricted policy, the core security rules (Malware and Content categories) are pre-set and locked. However, you retain control over specific settings like SafeSearch and Exceptions (Allow/Block lists).
Best for: Enforcing a strict, non-negotiable security standard where no local administrative overrides should be allowed.
Shared Policy
This setting is critical for Managed Service Providers (MSPs) or organizations with a multi-tenant hierarchy. It determines the scope and visibility of the policy across your organization structure.
- Disabled (Default): The policy is only visible and usable within the current organization.
- Enabled: The policy becomes a "Master Policy." It will be visible to all related Sub-Organizations or tenants you manage. They can assign this policy to their networks, but they cannot modify its settings.
Finalizing Setup
Once you have made your selections, click the Add button at the bottom right to save the policy.