Applying Policies to Users or Active Directory Groups

2 min. readlast update: 09.29.2026

When creating policies, you can apply them to a limited number of users or Active Directory groups. When applying a policy to a specific user, consider service accounts that might be required.  

For example, if you want to permit iTunes for only your C.E.O., you can add his domain\CEOName to the policy. However, iTunes also requires additional services to run, that run under the system account. In this case, you would also want to add the SYSTEM account to the policy.  

To apply a policy to limited users, first navigate to either the ‘Application Control’ or ‘Storage Control’ page using the ‘Modules’ dropdown menu. 

Picture 

If you are in the ‘Application Control’ page, select the ‘Policies’ tab on the top right side of the page. 

Picture 

Now, in either the ‘Storage Control’ or ‘Application Control’ > ‘ Policies’ page, select the policy you wish to edit. 

Picture

A popout window titled ‘Edit Application Policy’ will now appear. 

Picture

Navigate to the ‘Applies To*’ section of the page, then select the button labeled ‘Selected Users & Groups’. Selecting this button will cause a new input field to appear. 

Picture 

In this field, enter the username of the person you wish to apply this policy to. When adding a username, you can use wildcards. For example: *\SYSTEM 

Picture 

Important: An azure username can be input into this textbox without having the Azure Integration. Be sure the username is inserted exactly as it appears in the Unified Audit.

Azure Integration/Active Directory Sync

Usernames can be entered manually without an Azure integration or the Active Directory Sync Service. However, configuring either option allows Azure/Active Directory groups to be populated automatically in the dropdown for easier selection.

To add a group, select the Azure/Active Directory group from the dropdown and click the + button. Group selection requires either an active Azure integration or the Active Directory Sync Service.

For setup instructions, see:

Select ‘Save’ at the bottom of the page if you are in the ‘Application Control Policies’ page or ‘Create’ if you are in ‘Storage Control’. Deploy policies after your new policy has been created.

Was this article helpful?