Skip to main content

About Shield Policies

Abstract

Shield Policies let you apply different Cyber Shield protection settings to different User Groups in CloudConnexa — each policy bundles Domain Filtering and Traffic Filtering settings, and the Default Policy always protects Networks and Hosts.

Overview

Shield Policies provide per-group filtering in CloudConnexa by letting you apply different Cyber Shield protection settings to different User Groups.

Each Shield Policy bundles Cyber Shield settings under a name you choose, including:

  • Domain Filtering

    • Protection level

    • Content categories to block

    • Allow List

    • Block List

  • Traffic Filtering

    • Protection level

    • Filtering settings

You can assign a Shield Policy to one or more User Groups. There is no limit to the number of User Groups a policy can have.

For an overview of Cyber Shield, refer to About Cyber Shield.

How Shield Policies apply to users

Each User Group uses exactly one Shield Policy. CloudConnexa applies the Shield Policy assigned to the user's primary User Group. This means the primary User Group determines which Domain Filtering and Traffic Filtering settings apply to that user.

For more information about primary and secondary User Groups, refer to Assignment of a User to multiple User Groups.

Default Policy

Every WPC includes one Default Policy.

The Default Policy:

  • Can't be deleted.

  • Applies automatically to User Groups that aren't assigned to a custom Shield Policy.

  • Applies to newly created User Groups until you assign them to another policy.

  • Always applies to Networks and Hosts.

When you enable Shield Policies on an existing WPC, the Default Policy retains the existing Cyber Shield configuration. This means your current filtering behavior doesn't change until you create and assign custom policies.

Important

Networks and Hosts always use the Default Policy. You can't assign them to a custom Shield Policy.

Custom Shield Policies

Create custom Shield Policies when different User Groups need different Cyber Shield protection.

For example, you might configure:

  • A stricter policy for contractors.

  • A policy with different blocked content categories for students or guests.

  • A policy with stronger Traffic Filtering for privileged users.

  • Different Allow Lists or Block Lists for different departments.

A single custom policy can be assigned to multiple User Groups.

For more information about User Groups, refer to About User Groups.

Active and Inactive policies

Domain Filtering and Traffic Filtering are switched on or off per policy.

A policy's state is determined automatically:

Policy state

Behavior

Active

Domain Filtering, Traffic Filtering, or both are enabled.

Inactive

Both Domain Filtering and Traffic Filtering are disabled.

There's no separate on/off control for a Shield Policy.

An Inactive policy retains its configuration but doesn't apply Domain Filtering or Traffic Filtering.

Using the Default Policy and custom policies

You can use Shield Policies in several ways:

  • Default Policy only: All User Groups, Networks, and Hosts use the Default Policy.

  • Default Policy and custom policies: Some User Groups use custom policies, while unassigned User Groups, Networks, and Hosts continue using the Default Policy.

  • Custom policies for all User Groups: Every User Group uses a custom policy. Because Networks and Hosts always use the Default Policy, it can be Inactive — meaning they receive no filtering.

Important

Networks and Hosts always use the Default Policy. If the Default Policy is Inactive, Networks and Hosts don't receive Domain Filtering or Traffic Filtering.