You assign a policy to a client computer through a group. Every group has exactly one policy of each protection type that is assigned to it at all times. Typically, you create separate groups for clients that run different platforms. If you put clients that run different platforms into the same group, be aware that each client platform ignores any settings that do not apply to it.
Unassigned policies are not downloaded to the client computers in groups and locations. If you do not assign the policy when you add the policy, you can assign it to groups and locations later. You can also reassign a policy to a different group or location.
Policies are assigned to computer groups as follows:
At initial installation, the Symantec default security policies are assigned to the My Company parent group.
The security policies in the My Company parent group are automatically assigned to each newly created child group. Newly created child groups inherit from My Company by default.
New groups always inherit from their immediate parent group. If you create a hierarchy of child groups, each one inherits from its immediate parent, not from the top-level parent.
You replace a policy in a group by assigning another policy of the same type. You can replace a policy that is assigned to the My Company parent group or to any child group.
The user interface in the Assign policy dialog box conveys the following additional information:
A folder icon indicates a group.
A round icon indicates a location.
On a group icon, a check mark in a green circle indicates that this policy is assigned to all of the locations in the group.
On a location icon, a check mark in a green circle indicates that this policy is assigned to this location.
Text that is grayed out means that the group or location inherits its policy from its parent group.