You can create a template computer group in your parent organization, allowing you to easily duplicate policies to computer groups in other organizations.
To start, make sure you are in your parent organization.
Navigate to the ‘Devices’ page using the left-hand menu, then select ‘Groups’ from the top right corner of the page. Select the button labeled ‘+ Computer Group’ at the top left corner of the page.
Selecting this will display a side-panel labeled ‘Create Computer Group’. This will provide you with all settings to create your template group. Within the ‘Computer Group Details’ section, add in the name of your group. Your group name must follow the format of ‘Template-{enter group name here}’. In the example below, we have named the Template group ‘Template-testgroup’.
Select the ‘Create’ button at the bottom of the page, then navigate to the ‘Application Control’ module using the ‘Modules’ dropdown on the left-hand side of the page.
Select the ‘Policies’ tab using the top-right button, then change the ‘Applies To’ dropdown to the name of the organization you have just created.
Your new organization will be created with no policies in it by default as ThreatLocker recognizes this as a Template group.
You can now add new policies to this Template group. Add the policies that you would like to be added to the group, excluding any ThreatLocker Default Policies. The ThreatLocker Default Policies will be added to the new Computer Group you will create to receive the duplicated policies.
Navigate to the Organizations page using the left-hand menu, then select the Organization you want to copy these policies to.
Navigate to the ‘Devices’ page, then select the ‘Groups’ tab.
Select '+ Computer Group' from the top of the page to create a group that will receive the templated policies.
In the popout window, name this computer group the second half of the name of your template group. In this example, the template is named Template-testgroup, and the target group is named testgroup.
Note: You must create a new group for this to take effect. Policies from the Template group will only populate into groups created after the Template group and policies are made. This will not work for existing groups that share the same name. It will also not work for policies added to the Template group after the recipient group(s) have been created
Navigate to Modules > Application Control > Policies.
Select this group from the dropdown menu under 'Applies To'. You will see that this group contains all the default ThreatLocker policies, including the default deny policy, and also all the policies you created in the template group.
You can repeat this process across multiple child organizations as needed.