Business → Device policies (business.devices, Warda Business,
beta; internal/admin/devicepolicy.go): a policy for each kind of device,
the kinds being the groups of devices (network
equipment, NAS and servers, TVs and consoles, printers, cameras, connected
objects, guests, and the groups made by the administrators). A policy is
made of what already exists, kept where it always was; the page gathers
it:
- Policies by kind of device: a row per group with its devices (and the people of the directory whose devices follow it), its Protections (the profile of the group), safe search, its Blocked services, its Data loss prevention actions and whether the company Baseline rules cover its profile; the profile of the devices given to nobody under it.
- Change a policy: an editor per group (profile, blocked services,
actions by channel, "Like the whole network"); applied at once.
PUT /api/v1/business/devices/{group id}{"profile": "…", "services": […], "dlp": {"<channel>": "allow|alert|block|"}}(each field optional;ruleswritten, andhouseholdwritten for the profile). - A new device goes by itself, within ten minutes, into the group it looks
like (
devices.classify), and so gets its policy at once. The computers and phones of the staff follow their person, and the group of devices given to their group of the directory (see Users of the directory). - Compliance: the devices seen this week that escape a policy — Given to nobody, Kind not recognised, Does not ask Warda (the silent machines of the network check, devices or not yet), Ways around the filter: n (encrypted DNS, VPN or proxy blocked this week), In quarantine — with their person and when they were last seen; a warning when a router announces another IPv6 DNS server (every device can then go around its policy).
GET /api/v1/business/devices (rules read) gives policies
(group_id, key, name, profile, effective, devices, people,
services, dlp, safe_search, baseline), unknown_profile,
channels, services, kinds, compliance (device_id, mac,
label, person_name, reasons, bypass, seen_at) and
ipv6_bypass. Later: a strict mode for the connected objects (only the
names they used while learning).