Configure and Manage Device Policies and Overrides for Your Company

Device Policies allow you to communicate expectations and enforce device requirements to access Venn's Blue Border using Security Compliance Checks. You may choose to use these policies to ensure the security of the devices where users are accessing Blue Border.

As a Company Manager, you can set Default Device Policies, which are applied to all Venn users as a baseline. You can also create Policy Overrides, which allow you to set Device Policies that supersede the default policy for a single user or a group of users.

Learn more about how Device Policies and Overrides work and Venn's available Device Policies.

View Device Conditional Access Settings, Policies, and Overrides

To view your Device Conditional Access Settings, Policies, and Overrides:

  1. Navigate to the Admin Portal.
    • In your browser, go to https://login.venn.com/ and sign in if prompted. Then, click Open Admin Portal.
    • From the desktop app, click the Open web app icon.png Open web app icon. Then, click Company Admin in the top right.
  2. Click Policy Admin and select Device Policy in the menu at left.
  3. Click the Desktops and laptops or Mobile devices tab depending on what type of policy you would like to view or adjust.

On the Device Policy page, you will see your Conditional Access setting at the top of the page, then your company's default Device Policies and any Policy Overrides that have been created at the bottom of the page.

  • Required device policies will have a green icon to the left of them
  • Recommended device policies will have an orange icon to the left of them
  • Disabled device policies will have a gray icon to the left of them

Device Policy Admin.jpg

Each Policy Override will list who they apply to and which policies differ from the default company policy.

You will see a yellow warning symbol if an override matches the default company policy.

Device Policy Admin_Policy Override_Warning.png

Learn more about how Device policies and overrides work.

Manage Conditional Access Settings

You can determine whether or not to implement Conditional Access for your Device Policy, which enforces device requirements to access Blue Border for required Security Compliance Checks.

Conditional Access can be set to:

  • Disabled: Users can still access and work within Venn whether or not their device passes or fails the checks. 
  • Enabled: Users will only be able to log in if their devices pass all required compliance checks. If Conditional Access is enabled, you can also choose to enable Continuous Conditional Access, which applies conditional access at login and continuously while the user is working in Blue Border.

Learn more about conditional access.

To manage your conditional access settings:

  1. Follow the steps above to navigate to the Device Policy Admin page.
  2. Click Change in the top right corner of the page.

    Device Policy Admin_Conditional Access.jpg

  3. Choose the conditional access setting you would like to put in place and click Apply.

    Device Policy Admin_Conditional Access Options.jpg

Set or Change Your Company's Default Device Policy

To set or change your company's Default Device Policy:

  1. Follow the steps above to navigate to the Device Policy Admin page.
  2. Under Default policy, click Edit icon.png Edit  to the right of the policy you would like to modify.
  3. Make adjustments as needed.
    1. Click the toggle next to the security compliance check description to enable or disable the policy.
      • If the policy is disabled, it will not be checked.
      • If the policy is enabled, it will be checked when users log in to Venn and continuously monitored when they are logged in. 
    2. If the policy is enabled, choose whether to require or recommend that users' devices pass the security compliance check.
      • Required: Users will be notified if their device doesn't pass this required check.
        • Users will be prevented from logging in to Venn on their device if they fail this check when Conditional Access is enabled.
        • Users will be logged out of Venn if their device goes out of compliance with this check when Continuous Conditional Access is enabled.
      • Recommended: Users will be notified if their device doesn't pass this recommended check. They will not be prevented from accessing Venn on their device if they fail this check.
  4. Click Apply.

    Device Policy Example.png

If you click Revert to managed, all policies will be reset to Venn's default settings in your Default Policy. You can resume self-managing your Default Policy by clicking Change next to a policy you would like to modify and confirming that you would like to self-manage your policy.

Create a Device Policy Override

To create a Device Policy Override:

  1. Follow the steps above to navigate to the Device Policy Admin page.
  2. Click Add override to the right of the Policy overrides section.

    Device Policy Admin_Create Override.jpg

  3. Give the override a name that describes who it will apply to and/or why the override is being created.
  4. Select the User, Group of people, or Group of devices (IP range) that you would like the override to apply to. 
    • User: Select a user from the dropdown. Type to search for a user by first or last name if needed. You can only apply a policy override to one individual user at a time. If you would like to create an override that applies to more than one person, consider using one of the group options described below.
    • Group of people: Select a group from the dropdown. Type to search for a group if needed. If you would like to create a new user group to assign a policy override to, you can create a new user group if needed and manage which users are in each group.
    • Group of devices (IP range): Specify an IP range and click Add IP range to add additional ranges if needed. This option is typically used to allow certain behaviors such as printing when users are in a company office or connected to the company network.
    • Data Tag: Identify users based on information in their user record such as their email address, mobile phone number, or title.

      Override_IP_Range_additional.png

  5. Your default policies will appear for reference. Click  Edit icon.png Edit to the right of the policy that you would like to differ from the default.

    Device Policy Admin_Change Override.jpg

  6. Make adjustments and click Apply.
  7. Click Apply in the bottom right corner of the Policy override screen.

The Policy Override will be added to your Policy Overrides list at the bottom of the Device Policy Admin page.

Change or Remove a Policy Override

To change or remove a policy override:

  1. Follow the steps above to navigate to the Device Policy Admin page.
  2. Locate the override you would like to change or remove and click Edit icon.png Edit in the Policy overrides section.

    Device Policy Admin_Edit Override.jpg

  3. Make your modifications.
    • To change a policy, click Edit icon.png Edit next to the policy you want to modify, make adjustments, and click Apply.
    • To remove a policy, click Delete icon.png Delete next to the policy you want to revert to the default and click Delete in the confirmation window.

      Device Policy Admin_Change:Remove Override.jpg

  4. Apply your changes.

    • To apply the adjustments you made to the Policy Override, click Apply in the bottom right.
    • To remove the Policy Override entirely, click Delete in the bottom right and then in the confirmation window.

    Device Policy Admin_Edit Override_Apply.jpg

Reorder Device Policy Overrides

If a user qualifies for more than one Policy Override (by name, by user group, by IP address, or by data tag), Overrides will be prioritized in the order in which they appear in the list of Overrides. 

To reorder Device Policy Overrides:

  1. Follow the steps above to navigate to the Device Policy Admin page.
  2. Hover over the left side of an override to reveal the drag and drop icon. Click the icon and drag it to the appropriate position to reorder the overrides.

    Device Policy Admin_Reorder Overrides_Drag and Drop.gif

Learn more about how Device Policies and Overrides work.

Update Device Retention Policy

The Device Retention Setting governs how long devices stay on the Device Inventory in Company Admin, which lists devices where Venn has been downloaded.

This setting has been moved to the Device Inventory page. Learn more here.

Was this article helpful?