Use the Multi-Tenancy Admin Console to configure protection policies and manage device policy groups across all your organization's tenants.
About Policy Inheritance
Individual WS1 MTD tenants apply protection policy settings to devices using the logic described in the later sections. By default, newly added tenants do not inherit any settings from the Multi-Tenancy Admin Console.
Policy Inheritance Across the Organization
The Default Policy Group in the Multi-Tenancy Admin Console represents your organization's default settings. Any new group you create in the Multi-Tenancy Admin Console starts from these settings.
Inheriting Default Organization Policies on Tenants
When Omnissa provisions a new WS1 MTD tenant, or when you first set up Multi-Tenancy for an existing environment, each tenant uses its own local Default Group to determine policy settings. Additional groups on that tenant start from the local Default Group's settings.
Important: Initially, there is no relationship between your organization-level settings and the settings on each tenant until you assign a default policy group to a tenant. For more information see, Setting a Tenant's Default Device Policy Group, the tenant retains its local settings.
Once you assign a default policy group to a tenant from the Multi-Tenancy Admin Console and click Reset Defaults on the tenant, the tenant links to the Multi-Tenancy Admin Console. Subsequent changes to the tenant's default policy group at the organization level push automatically to the tenant.
Example: The "Tenant 1: USA" tenant initially has no default policy group assigned in the Multi-Tenancy Admin Console, which is the expected state when Multi-Tenancy is first configured. All protection policy settings continue to behave as they would on a standalone tenant. For example, the custom "USA Execs" group inherits its default settings from the tenant's local Default Group and is not affected by the Multi-Tenancy Admin Console.
To push configuration from the Multi-Tenancy Admin Console, assign "USA Default" as the tenant's default policy group and click Reset Defaults on the tenant. This removes the tenant's original local Default Group and links the tenant's protection settings to the Multi-Tenancy Admin Console. Any subsequent changes to "USA Default" or the organization's Default Policy Group are propagated to the tenant. Groups on the tenant that inherit settings from the Default Group then inherit their settings from "USA Default."
Inheriting Non-Default Group Policies on Tenants
When you assign a default policy group to a tenant, custom groups on that tenant that use inherited settings inherit those settings from the newly assigned default group.
Example: If a tenant has a custom "C-Suite" group and you assign "USA Default" as the tenant's default policy group, any inherited settings in "C-Suite" are sourced from "USA Default."
When you create a new custom policy group in the Multi-Tenancy Admin Console and assign it to a tenant, the tenant creates an unlinked local copy of the group. Subsequent changes made to the group in the Multi-Tenancy Admin Console do not propagate to the tenant's local copy.
Modifying a Non-Default Group on Multiple Tenants
Pushing a non-default device policy group to a tenant creates an unlinked copy of the group. To update the policy across multiple tenants, push a new group, move the devices on each tenant to the new group, and then remove the old group from each tenant.
Note: Do not remove the old device policy group from a tenant until all devices have been moved to another group. Otherwise, the devices automatically move to the tenant’s default group.
To modify a custom group from the Multi-Tenancy Admin Console and push changes to one or more tenants:
-
Create a new policy group in the Multi-Tenancy Admin Console:
a. Click Tenants, then the Device Policy Groups tab.
b. Click Create Group in the upper right.
c. Enter a name and description and click Create Group.
-
Assign the new group to the tenant(s) you want to update:
a. Click the Tenants tab, then the row for the tenant.
b. Click the Device Policy Groups tab and click Add device policy groups.
c. Select the new policy group and click Add. Repeat for each tenant that needs the updated group.
-
Move all devices from the old custom group to the updated version:
a. Open the tenant and click Manage Tenant.
b. Click Devices in the left navigation bar.
c. Filter to show devices in the old device group.
d. Select all matching devices, and in the Transfer To: dropdown select the updated device group, then confirm the transfer.
-
Delete the old custom group from the tenant:
a. Return to the Multi-Tenancy Admin Console.
b. Click the Tenants tab, then the tenant you just updated.
c. Click the Device Policy Groups tab.
d. Click the trash icon to remove the old, now-empty device group.
-
Repeat steps 3 and 4 for each tenant you are updating.
이 페이지가 도움이 되었나요?