Skip to main content

User & Group Policy

Give different people different rules on the same network. The policy is resolved from the user signed into DashX Connect on the device — so a shared laptop follows whoever is logged in, not the machine.

Priority

User > Group > All > Device > endpoint default

The first match wins. A rule assigned directly to a person always beats their group; a group beats the catch-all; the device assignment is the fallback when nobody is signed in.

Assign a policy

  1. Go to Secure Access → DNS Filtering → User & Group Policy.
  2. Choose the target type: User, Group, Device or All directory users.
  3. Pick the specific user, group or device in the second select (there is none for All directory users).
  4. Pick the policy.
  5. Click Assign.

The assignment appears in the list below with a target badge (USER, GROUP, DEVICE, ALL DIRECTORY USERS). You can change the policy straight from the row's select, or Remove the assignment.

If the group list is empty

You will see: "No groups found — groups appear after directory users are synced from your IdP/LDAP."

Groups are not typed in here — they arrive with your directory sync. Configure the source under Secure Access → Identity → Sources & Users and run Sync now, then come back.

A sensible starting set

TargetPolicy
All directory usersStaff — categories on, schedule during work hours
Group ExecutivesStaff-relaxed — threats only
Group InternsRestricted
Device reception-kioskGuest Wi-Fi

Assign the broad rule first, then add the exceptions. Devices with nobody signed in fall back to their endpoint policy or the org default.

note

Attribution works the other way too: because the resolver knows which user was signed in, a block in Insights / Logs names the person, not just an IP address.