Just want to jump in here... If you set a policy up it will apply to all areas the policy group is applied to. So if you setup a policy and apply it to the Default Policy Group, all servers (Endpoint, Discover, Network Monitor, etc) that have that policy group would get the policy.
Does that make sense?
If I wanted to limit a policy to just an endpoint, then i would have to create a policy group (Endpoint Policy Group) and then apply that group just to my Endpoint server.
Drop me a note if that doesn't make sense