A Policy Object is a reusable set of configuration settings that can be applied to devices. With policy objects, you can create a set of policies once and apply them to multiple devices. Different policy objects can be applied to different sets of devices, so you can customize policies to meet your organization's needs.
Policy objects must be given a name and priority, and can optionally be given a description. An object's name and description are for your reference only, and don't affect how the policy object works, nor are they displayed to end-users outside of the Vexluna backend. Higher priority overrides lower priority; for example, priority 10 outranks priority 0, which outranks priority -10.
Policies
A policy object contains one or more policies. A policy is an individual setting to be applied to a device.
The policy object editor lists all available policies that you can configure. Each policy may be either Not Configured, Enforced (via the Enforce option), or Suppressed (via the Suppress option).
Not Configured: This is the default state of a policy. If you don't configure a policy, it won't be applied to devices.
Enforce: If a policy is enforced, then it will be applied to devices which have the policy object assigned to them.
Suppress: A suppressed policy has no effect on the device itself, but it prevents the same policy from being enforced by any policy object at the same or lower priority level (see Priority Resolution).
A policy may stand alone or may have additional settings that you can configure. For example, Siri ▸ Block Siri can only be on or off; if it's enforced, then Siri is blocked on the device. Otherwise, Siri is allowed.
Some policies have additional settings that need to be configured in order for the policy to take effect. For example, Wallpaper ▸ Set home screen wallpaper must have a wallpaper image selected, in addition to being enforced.
Device Support
Each policy in the policy editor indicates which devices support that policy, the minimum OS version, and whether the device must be supervised to enforce the policy. If a policy is assigned to a device that doesn't support it, that policy is ignored.
Priority Resolution
If multiple policy objects are assigned to the same device, they are evaluated on a policy-by-policy basis from lowest priority to highest priority. Priority may be negative, zero, or positive. Higher priority overrides lower priority; for example, priority 10 outranks priority 0, which outranks priority -10.
If the same policy is configured inside of multiple policy objects assigned to a device, these rules are followed for determining how to apply the policy to the device:
Higher priority policy objects always win
At the same priority level, Enforce beats Not Configured, and Suppress beats Enforce
Examples
This table lists some example configurations and the resulting policy that's applied to the device. A blank cell indicates Not Configured.
Policy Object A (priority 0) | Policy Object B (priority 0) | Policy Object C (priority 10) | Result |
|
|
| Do not enforce (not configured) |
| Enforce |
| Enforce |
| Suppress |
| Do not enforce (suppressed) |
Enforce | Suppress |
| Do not enforce (suppressed) |
Enforce | Suppress | Enforce | Enforce |
Enforce | Enforce | Suppress | Do not enforce (suppressed) |
Overlapping Policies With Settings
If the same configurable policy (e.g. Set home screen wallpaper) is enforced by multiple policy objects on the same device, then all of the configurable options from the highest priority policy object will be applied, and lower-priority configurable options are ignored.
If multiple policy objects exist at the same priority, one of the policy objects' configurable options will be used, but exactly which object's options are applied is not predictable. Avoid this configuration and instead use priority levels when applying the same configurable policy in multiple policy objects.
Some configurable policies have special merge behavior when multiple copies apply to the same device: