Since multiple policies can be added to a group, policy priority plays an important part in deciding which policies will be applied to a user.
Let's look at an example to understand policy priority. The group "Weekend Shift" has four members: Amelia, Arthur, David, and Eduardo. The group has two policies, Policy A and Policy B, applied to it. Arthur is excluded from Policy A, David is excluded from Policy B, and Amelia is excluded from both.
In addition to the two policies, there is also a Default Policy applied to all users in the organization. It will have the lowest priority, and it can't be excluded, reordered, disabled, or deleted.
| Amelia
| Arthur
| David
| Eduardo
|
Policy A
| 𐄂
| 𐄂
| ✓
| ✓
|
Policy B
| 𐄂
| ✓
| 𐄂
| ✓
|
Default Policy
| ✓
| ✓
| ✓
| ✓
|
Default Policy and Policy A have a password policy configured, and Policy B has a password policy and MFA configured.
Policy priority works in a top-to-bottom approach. When a user has more than one applicable policy, the topmost policy will be applied. If the top policy doesn't have one or more of the components (Password policy, MFA, Allowed IPs, Session management) configured, then those missing components will be applied from the policy with the next highest priority.
In our example, Amelia will have only the Default Policy applied for her, Arthur will have Policy B applied for him, David will have Policy A applied for him, and Eduardo will have A's password policy and B's MFA policy applied for him.
To reorder policy priority:
- Sign in to the Zoho One Admin Panel.
- Go to Security, then click Security Policies.
- Click and drag to reorder the policies. The topmost policy has the highest priority.