Content Filtering Evaluation order

VBAL's picture

Using AD usernames and workgroups.... and creating different configuration policies for content filtering.  Is there an evaluation order to allow or block access to categories if an user belong to multiple Organizational Units or workgroups and each group has a different policy ??

Example : 

Policy # 1 - Apply to workgroup HR - All Content Filtering categories Allowed
Policy # 2 - Apply to workgroup Managers - All categories are blocked

What is the behavior for an user member of the HR and Managers groups ??

Is the evaluation order only for malware detection ??

Thanks

Filed under: ,
Sergi Isasi's picture

Policy Evaluation is Top

Policy Evaluation is Top Down.  If a user is in more than one group, the highest policy which contains that user's workgroup will be the policy applied to that end user.

Product Manager
Web Gateway & IM Manager