US2021360038A1PendingUtilityA1

Machine policy configuration for managed devices

Assignee: VMWARE INCPriority: Jan 4, 2019Filed: Jul 28, 2021Published: Nov 18, 2021
Est. expiryJan 4, 2039(~12.4 yrs left)· nominal 20-yr term from priority
H04L 41/0894H04L 63/205H04L 63/20H04L 41/0816H04W 4/50H04L 41/0843H04L 41/0813H04L 41/0266H04L 41/50H04W 12/37H04L 41/0893
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed are various examples for managing and customizing policy configurations on user devices enrolled in an enterprise management service. The policy configurations can include machine policies and/or user policies. An administrator can customize a baseline including a list of policies supported by an operating system of managed user devices. A management component on the user devices can obtain the baseline specified by the administrator from a managing service and apply the policies to the user device.

Claims

exact text as granted — not AI-modified
Therefore, the following is claimed: 
     
         1 . A system for policy enforcement, the system comprising:
 at least one computing device; and   at least one application executable in the at least one computing device, wherein the at least one application, when executed, causes the at least one computing device to at least:
 present a series of user interfaces via an administrator console accessed by an administrator client device, the series of user interfaces being configured to:
 facilitate a search and review of a plurality of policies supported by an operating system, the plurality of policies comprising at least one of a machine policy or a user policy that define a behavior of a device; and 
 facilitate a creation of a customized baseline for a group of managed devices managed by a management system, the customized baseline corresponding to a list of policies selected from the plurality of policies and defined by an administrator of the management system via one or more interactions with at least one user interface of the series of user interfaces; 
 
 generate a baseline configuration file for the plurality of managed devices identifying the list of policies; and 
 cause the baseline configuration file to be distributed to the plurality of managed devices. 
   
     
     
         2 . The system of  claim 1 , wherein, when executed, the at least one application causes the at least one computing device to at least obtain a user interface request to a review a predefined policy template defining a list of recommended policies, the customized baseline being based at least in part on the list of recommended policies in the predefined policy template. 
     
     
         3 . The system of  claim 2 , wherein, when executed, the at least one application causes the at least one computing device to at least receive one or more modification requests to at least one of add or remove one or more policies to the list of recommended policies, the customized baseline being based at least in part on the one or more modification requests to the list of recommended policies in the predefined policy template. 
     
     
         4 . The system of  claim 2 , wherein the predefined policy template corresponds to an industry specific template. 
     
     
         5 . The system of  claim 1 , wherein a particular policy included in the list of policies is a non-registry policy, and individual managed devices or the plurality of managed devices are configured to generate a command-line input to apply the particular policy using a command line interface of the operating system. 
     
     
         6 . The system of  claim 1 , wherein, when executed, that at least one application causes the at least one computing device to at least identify the plurality of policies supported by the operating system. 
     
     
         7 . The system of  claim 1 , wherein the plurality of policies are included in a policy catalog that is organized in a hierarchical configuration according to at least one of the operating system, an operating system versions, or a policy type. 
     
     
         8 . A computer-implemented method for policy enforcement, comprising:
 presenting, by at least one computing device, a series of user interfaces via an administrator console accessed by an administrator client device, the series of user interfaces being configured to:
 facilitate a search and review of a plurality of policies supported by an operating system, the plurality of policies comprising at least one of a machine policy or a user policy that define a behavior of a device; and 
 facilitate a creation of a customized baseline for a group of managed devices managed by a management system, the customized baseline corresponding to a list of policies selected from the plurality of policies and defined by an administrator of the management system via one or more interactions with at least one user interface of the series of user interfaces; 
   generating, by the at least one computing device, a baseline configuration file for the plurality of managed devices identifying the list of policies; and   causing, by the at least one computing device, the baseline configuration file to be distributed to the plurality of managed devices.   
     
     
         9 . The computer-implemented method of  claim 8 , further comprising obtaining a user interface request to a review a predefined policy template defining a list of recommended policies, the customized baseline being based at least in part on the list of recommended policies in the predefined policy template. 
     
     
         10 . The computer-implemented method of  claim 9 , further comprising receiving one or more modification requests to at least one of add or remove one or more policies to the list of recommended policies, the customized baseline being based at least in part on the one or more modification requests to the list of recommended policies in the predefined policy template. 
     
     
         11 . The computer-implemented method of  claim 9 , wherein the predefined policy template corresponds to an industry specific template. 
     
     
         12 . The computer-implemented method of  claim 8 , wherein a particular policy included in the list of policies is a non-registry policy, and individual managed devices or the plurality of managed devices are configured to generate a command-line input to apply the particular policy using a command line interface of the operating system. 
     
     
         13 . The computer-implemented method of  claim 12 , further comprising identifying the plurality of policies supported by the operating system. 
     
     
         14 . The computer-implemented method of  claim 8 , wherein the plurality of policies are included in a policy catalog that is organized in a hierarchical configuration according to at least one of the operating system, an operating system versions, or a policy type. 
     
     
         15 . A non-transitory computer-readable medium embodying a program executable in at least one computing device, wherein when executed, the program causes the at least one computing device to at least:
 present a series of user interfaces via an administrator console accessed by an administrator client device, the series of user interfaces being configured to:
 facilitate a search and review of a plurality of policies supported by an operating system, the plurality of policies comprising at least one of a machine policy or a user policy that define a behavior of a device; and 
 facilitate a creation of a customized baseline for a group of managed devices managed by a management system, the customized baseline corresponding to a list of policies selected from the plurality of policies and defined by an administrator of the management system via one or more interactions with at least one user interface of the series of user interfaces; 
   generate a baseline configuration file for the plurality of managed devices identifying the list of policies; and   cause the baseline configuration file to be distributed to the plurality of managed devices.   
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein, when executed, the program further causes the at least one computing device to at least obtain a user interface request to a review a predefined policy template defining a list of recommended policies, the customized baseline being based at least in part on the list of recommended policies in the predefined policy template. 
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , wherein, when executed, the program further causes the at least one computing device to at least receive one or more modification requests to at least one of add or remove one or more policies to the list of recommended policies, the customized baseline being based at least in part on the one or more modification requests to the list of recommended policies in the predefined policy template. 
     
     
         18 . The non-transitory computer-readable medium of  claim 16 , wherein the predefined policy template corresponds to an industry specific template. 
     
     
         19 . The non-transitory computer-readable medium of  claim 15 , wherein a particular policy included in the list of policies is a non-registry policy, and individual managed devices or the plurality of managed devices are configured to generate a command-line input to apply the particular policy using a command line interface of the operating system. 
     
     
         20 . The non-transitory computer-readable medium of  claim 15 , wherein the plurality of policies are included in a policy catalog that is organized in a hierarchical configuration according to at least one of the operating system, an operating system versions, or a policy type.

Join the waitlist — get patent alerts

Track US2021360038A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.