Policy insights in access control policy

Policy insights in access control policy is a monitoring feature that

  • tracks rule usage through hit count information from all devices assigned to the policy

  • provides filtering capabilities based on actions, hit information, and time periods, and

  • enables rule management through disable or delete operations for unused or underutilized rules.

Policy insights filtering options

The Policy Insights tab has a Hit Count section that initially lists any rules that have never been triggered (Never Hit Rules). The hit count information is from all devices that are assigned to the policy. You can change criteria and see other hit count information, for example, Not Hit Rules for the past six months, or Hit Rules over a selected time period. You can filter the rules using the actions set in the rules, hit information, and time period:

  • Never Hit Rules—Rules that have never been hit from the time they were created.

  • Hit Rules—Rules that have been hit in the selected time period.

  • Not Hit Rules—Rules that have not been hit in the selected time period.

Select the rules that you want to disable or delete, and select Disable Rules or Delete Rules. These changes are staged until you select Apply Remediation. First, disable the rules when you want to measure their impact before deleting them.

Policy insights interface
The policy insights interface displays hit and not hit rules within a selected time period, allowing users to manage rule statuses by disabling or deleting them before applying changes.