Analyze expired rules in access control policy

Analyzing expired rules in access control policy is a policy management feature that

  • lists rules that were configured with a time range and the time range has expired

  • provides rule information such as the date on which the rule expired, hit count, last hit time, and the time range, and

  • enables remediation of expired rule observations through selective actions.

Expired rules remediation options

You can remediate expired rules using these methods:

  • All expired-rule observations in the category

  • Selected expired-rule observations

  • Selected expired rules

For selected expired rules, you can choose these actions:

  • Move to disabled state

  • Move to delete state

Note

Only selected rules are changed when you apply remediation.

The Expired Rules tab displays this information in the interface.

The Expired Rules tab shows selected expired-rule observations and available actions, including moving rules to a disabled or delete state.