Kaspersky Security Center

Conditions for a device moving rule

May 3, 2024

ID 238503

Expand all | Collapse all

When you create or copy a rule to move client devices to administration groups, on the Rule conditions tab you set conditions for moving the devices. To determine which devices to move, you can use the following criteria:

  • Tags assigned to client devices.
  • Network parameters. For example, you can move devices with IP addresses from a specified range.
  • Managed applications installed on client devices, for instance, Network Agent or Administration Server.
  • Virtual machines, which are the client devices.

Below, you can find the description on how to specify this information in a device moving rule.

If you specify several conditions in the rule, the AND logical operator works and all the conditions apply at the same time. If you do not select any options or keep some fields blank, such conditions do not apply.

Tags tab

On this tab, you can configure a device moving rule based on device tags that were previously added to the descriptions of client devices. To do this, select the required tags. Also, you can enable the following options:

  • Apply to devices without the specified tags
  • Apply if at least one specified tag matches

Network tab

On this tab, you can specify the network data of devices that a device moving rule considers:

  • DNS name of the device
  • DNS domain
  • IP range
  • IP address for connection to Administration Server
  • Connection profile changed
  • Managed by a different Administration Server

Applications tab

On this tab, you can configure a device moving rule based on the managed applications and operating systems installed on client devices:

  • Network Agent is installed
  • Applications
  • Operating system version
  • Operating system bit size
  • Operating system service pack version
  • User certificate
  • Operating system build
  • Operating system release number

Virtual machines tab

On this tab, you can configure a device moving rule according to whether client devices are virtual machines or part of a virtual desktop infrastructure (VDI):

  • This is a virtual machine
  • Virtual machine type
  • Part of Virtual Desktop Infrastructure

Domain controller tab

On this tab, you can specify that it is necessary to move devices included in the domain organizational unit. You can also move devices from all child organizational units of the specified domain organizational unit:

  • Device is included in the following organizational unit
  • Include child organizational units
  • Move devices from child units to corresponding subgroups
  • Create subgroups corresponding to containers of newly detected devices
  • Delete subgroups that are not present in the domain
  • Device is included in the following domain security group

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.