One approach you may want to use to verify the policy is working locally, is by creating a policy that flags an incident with a keyword. Select something like: thisismysecretkeyword (or some string together). Enable the policy to create the pop-up notification for the user as a response rule. This will enable you to verify that the incidents are even being generated in the first place.
If you do indeed get the popup function, then it might be something on the Enforce side. Restarting the server is usually a safe bet. If you can't restart the system or would prefer not to, you can restart the services manually.
If you are still having an issue, post back and let the folks here know.