Drift Alignment Alert Policy

A drift-alignment alert policy defines the drift detection frequency at which drift detection jobs are initiated to monitor for configuration deviations between the tenant and baseline standards. It also defines the workflows for drift notification that specify when notification emails are triggered and who receives them. A drift-alignment alert policy takes effect only after the relevant baselines have been deployed to the tenant.

The Drift-alignment alert policy tab displays all available policies of this type. A built-in policy, named Default drift-alignment alert policy, is provided for immediate use. This default policy has the Workflows for drift notification set to Empty and Drift detection frequency set to 24 hours. To view the detailed information about a specific policy, click its name to open the policy details page.

Create a Policy

Refer to the following steps to create a drift-alignment alert policy:

  1. Click Create above the policy table to open the Create drift-alignment alert policy page.

  2. Complete the following information:

    • Policy name – Enter a name for this policy.

    • Description – Enter an optional description.

    • Tenant scope – Select the tenants where you want to apply this policy and click Apply. Tenant assignment can also be completed after you create the policy. For detailed instructions, refer to Apply a Policy to Tenant.

    • Workflows for drift notification – Select the workflows for drift notification that specify when notification emails are triggered (e.g., when the detected configuration deviations have not been processed after a specified number of days) and who receives them. If there is no available workflows, click Create workflow to create a new workflow.

    • Drift detection frequency – Select an interval (hours) to set the frequency for drift detection job. This setting determines the maximum number of drift detection job executions per day (starting at 00:00).

      Once a baseline is successfully deployed to a tenant, scheduled drift detection jobs will automatically start based on the configured interval to continuously monitor for configuration deviations between the tenant and baseline configurations.

  3. Click Create to create the policy.

Apply a Policy to Tenant

A tenant can be associated with only one drift-alignment alert policy. Applying a new policy of this type will override the existing one. The Tenant scope column in the policy table displays the tenants where a policy has been applied.

Refer to the following steps to apply a drift-alignment alert policy to tenants:

  1. Select the policy that you want to apply to tenants.

  2. Click Apply to tenant.

  3. Select the tenants where you want to apply this policy and click Apply.

  4. Click Apply.

Remove a Policy from Tenant

Each tenant must have one drift-alignment alert policy applied. If you remove a drift-alignment alert policy from a tenant, the default drift-alignment alert policy will be automatically applied.

Refer to the following steps to remove a drift-alignment alert policy from a tenant:

  1. Select the policy that you want to remove from the tenant.

  2. Click Apply to tenant.

  3. Click the Remove button next to the tenant. Click Remove in the pop-up confirmation window.

  4. Click Apply.

Delete a Policy

To delete a policy that is no longer needed, select the policy and click Delete. Please note that policies currently assigned to any tenants cannot be deleted until they have been removed from all associated tenants.