Home > Policy Enforcer > Create and Apply a Policy Enforcer Profile
Export to PDFAfter creating Policy Enforcer profiles, you can apply them to the selected SharePoint Online nodes.
To apply a profile to one or more nodes in SharePoint Online, complete the following steps:
On the Policy Enforcer tab, expand the tree in the Scope field and select one or more nodes (from the group level to the site level) where you want to apply the profile.
Click Create or Apply Profile on the ribbon to enter the Create or Apply Profile page.
View the message bar on the top of the Create or Apply Profile area or a pop-up window to display these details about the applied profiles for the selected nodes.
When you select one node in the scope tree:
If there is no profile applied on this node, a message bar appears on the top of the Create or Apply Profile area. This message informs that you can choose a desired option from the Profile Name section to apply a profile to this node.
If there is a profile applied on this node, the currently applied profile’s name is displayed in the message bar. You can perform the following operations:
To edit the currently applied profile, click Edit and enter the profile on the Edit Profile page.
To apply a new profile to this node, select a desired option from the Profile Name section.
If this node is inheriting rules from its parent node, the inherited profile’s name is displayed in the message bar. You can perform the following operations:
To edit the inherited profile, click Edit and edit the profile on the Edit Profile page. Changes you make on this page will affect the parent node and all its sub-nodes which are inheriting the rules and settings.
To apply a unique profile to this node, click Stop Inheriting to stop inheriting the rules and settings from the parent node and then choose a desired option from the Profile Name section to apply a new profile to this node.
After you break a particular node’s profile inheritance, use the Inherit button to make it inherit the profile from its parent again.
When you select more than one node in the scope tree:
If there is no profile applied on the selected nodes, a message bar appears on the top of the Create or Apply Profile area. This message says you can choose a desired option from the Profile Name section to create or apply a new profile for the selected nodes.
If any of the selected nodes has a profile applied or is inheriting rules from a parent node, a pop-up window appears to display the profile applied status of the selected nodes. In this window, you can view the current profile or inherited profile on each selected node and then select whether apply another profile to these nodes in bulk.
To apply a new profile to the selected nodes in bulk, click Proceed Anyway to access the Create or Apply Profile page and then choose a desired option from the Profile Name section to create or apply a new profile for the selected nodes.
If you do not want to make any changes to the selected nodes in bulk, click Cancel to exit the Create or Apply Profile interface.
In the Create or Apply Profile area, configure the following settings:
Profile Name – Select one of the following radio buttons to apply a profile to the selected nodes in the scope tree:
To reuse an existing profile, select Reuse an existing profile and select a profile from the drop-down list. This option expands the scope of the original profile. Select this option to reuse an existing profile in a different scope. The rules and settings in the existing profile cannot be modified from this screen.
To create a new profile based on an existing profile, select Configure new rules and settings based on an existing profile and select an existing profile to copy from the drop-down list. Use this selection to modify the rules and settings of an existing profile and save the modification as a new one with a different profile name.
To create a new profile with new rules and settings, select Create my own rules and settings and start to configure the rules and settings for a new profile.
Rules – To add rules into this profile, complete the following steps:
Click Add Rule below the Rules table or on the ribbon. The Add Rule window appears, displaying all of the available rules for the selected scope. For more information on Policy Enforcer rules, refer to Table of Policy Enforcer Rules.
Select the checkboxes of the rules that you want to apply on the selected scopes on the corresponding tabs.
Click OK to add the selected rules to this profile and return to the Create or Apply Profile interface. All of the added rules are displayed in the Rules table.
To configure a specific rule, click the corresponding rule name in the Rules table, or select the checkbox of the rule and then click Configure Rule on the ribbon. The Configure Rule window appears.
You must activate at least one rule for each profile. You cannot save a profile with no active rules.
Source Collection Policy – Select one of the previously-configured source collection policies for the event types to be monitored by Policy Enforcer from the drop-down list, or select New Source Collection Policy to create a new one. If a policy has not been configured yet, refer to Configure the Source Collection Policy for details. After selecting a policy from the drop-down list, click View to view details about the selected source collection policy.
Retention Policy – Specify the retention period by selecting an option from the drop-down list for keeping the job data associated with this profile.
Send Periodic Reports – Select the Send periodic reports to therecipients configured in each rule checkbox to send daily or weekly reports for the violations of each rule in this profile to the recipient configured in the corresponding rule and then configure the frequency for the periodic reports:
Send daily reports at… – To send daily reports, click this radio button and then configure when to send the report every day by selecting a time from the drop-down list.
Send weekly reports every … at… – To send weekly reports, click this radio button and then configure when to send the report every week by selecting the day of the week and the time of the day from the drop-down lists.
After completing the configuration of a profile, click Apply > Apply or Apply > Apply and Run Now to apply the profile to the selected nodes. If you have selected more than one node in the scope tree, and some of the selected nodes already have a profile applied to them or are inheriting rules from a parent node, you must configure the conflict resolution in the pop-up window before applying the profile in bulk.
Click Apply > Apply on the ribbon to apply the rules and settings to the selected SharePoint Online nodes. The applied profile will be displayed on the Scheduled Job Monitor page. Policy Enforcer will start the jobs to scan SharePoint Online after one interval configured for the Auditor Mode or Scan Mode in this profile’s source collection policy. If “Day(s)” is selected as the interval for the Scan Mode, Policy Enforcer will start the jobs of Scan Mode rules at the specified start time.
Click Apply > Apply and Run Now on the ribbon to apply the profile to the selected SharePoint Online nodes and run the job immediately.
The Policy Enforcer jobs associated with the rules of Auditor Mode or Scan Mode are based on their respective intervals configured in the corresponding source collection mode. That is to say, the same profile might run the jobs of Auditor Mode rules and Scan Mode rules based on two different intervals.