The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Policy assignment rule priority

Prev Next

You can prioritize rules for policy assignment to simplify policy assignment management.

When you assign priority to a rule, it is enforced before assignments with a lower priority. In some cases, the outcome can be that some rule settings are overridden.

For example, consider a user who is included in two policy assignment rules, rules A and B. Rule A has priority level 1, and allows included users unrestricted access to Internet content. Rule B has priority level 2, and heavily restricts the same user's access to Internet content. In this scenario, rule A is enforced because it has higher priority. As a result, the user has unrestricted access to Internet content.

How multi-slot policies work with policy assignment rule priority

Multi-slot policies are used when a policy setting needs to be shared among users or system groups.

Rule priority is not considered for multi-slot policies.

  • If a single rule containing multi-slot policies of the same product category is applied to a user, all settings of the multi-slot policies are combined.
  • If multiple rules applied to a user contain multi-slot policy settings, all settings from each multi-slot policy are combined.

As a result, the user gets a policy that combines the settings of each rule.

For example, when these rules consist of multi-slot policy assignments, the settings for both policies are applied without regard to priority.

You can prevent application of combined settings from multi-slot policies across multiple policy assignment rules by excluding a user (or other Active Directory objects) when creating the policy assignment rule.