User & Group Policy
Give different people different rules on the same network. The policy is resolved from the user signed into DashX Connect on the device — so a shared laptop follows whoever is logged in, not the machine.
Priority
User > Group > All > Device > endpoint default
The first match wins. A rule assigned directly to a person always beats their group; a group beats the catch-all; the device assignment is the fallback when nobody is signed in.
Assign a policy
- Go to Secure Access → DNS Filtering → User & Group Policy.
- Choose the target type: User, Group, Device or All directory users.
- Pick the specific user, group or device in the second select (there is none for All directory users).
- Pick the policy.
- Click Assign.
The assignment appears in the list below with a target badge (USER, GROUP, DEVICE, ALL DIRECTORY USERS). You can change the policy straight from the row's select, or Remove the assignment.
If the group list is empty
You will see: "No groups found — groups appear after directory users are synced from your IdP/LDAP."
Groups are not typed in here — they arrive with your directory sync. Configure the source under Secure Access → Identity → Sources & Users and run Sync now, then come back.
A sensible starting set
| Target | Policy |
|---|---|
| All directory users | Staff — categories on, schedule during work hours |
Group Executives | Staff-relaxed — threats only |
Group Interns | Restricted |
Device reception-kiosk | Guest Wi-Fi |
Assign the broad rule first, then add the exceptions. Devices with nobody signed in fall back to their endpoint policy or the org default.
Attribution works the other way too: because the resolver knows which user was signed in, a block in Insights / Logs names the person, not just an IP address.