You can change the name, description, or permissions lists associated with an existing Access Control Policy, but you cannot change the OS Type or Cloud Administration Group for the policy. You also cannot change the Rule Type associated with a Windows Access Control Rule.

If a VM contains one or more disks associated with the policy you are changing, Cryptographic Security Platform Vault communicates the changes at the VM's next heartbeat. If the policy is associated with disks on more than one VM, this means that policy changes may not take effect on all associated disks at the same time because the VMs may be on different heartbeat schedules. If you want to force the update on a particular VM immediately, you can use the hcl heartbeat command on that VM.

Procedure

  1. Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. Navigate to the Access Control Policies tab.
  4. Click on the policy you want to change. The Cryptographic Security Platform Vault webGUI displays details about the policy and its associated rules in the Details area under the Policy table.
  5. Select Actions > Edit Policy.
  6. On the Details tab in the Edit Policy Wizard Details wizard, you can change the policy name or description if desired. You cannot change the OS Type or the Cloud Administration Group specified for the policy.
  7. If you want to edit the rules associated with the policy, click the Rules tab and do any of the following:

    • To add a new rule type, click Add. You can specify one filesystem-level rule, one block-level access rule, and any number of folder-level rules per policy.
    • To delete an existing rule, click the associated selection check box and click Delete.

      Note: The rule list cannot be empty, so you can only delete a rule if a second rule already exists in the list.

    • To change an existing rule, click the associated selection check box and click Edit. On the Details tab you can change the rule name or description, but you cannot change the rule type. If you want to change the rule's permissions list, click the Permissions tab and make the desired changes. Make sure that any entries you add contain a valid local VM user or group name, an NT service name, or a valid Active Directory (AD) user or group name.

      Important: If any of the local users in the permissions list are invalid, the Policy Agent issues an alert and does not apply the Access Control Policy. If access controls were already enabled for the disk, the Policy Agent continues to use the previous access control settings until the VM reboots. If the permissions list contains invalid entries when the VM reboots, the Policy Agent disables all access controls for the disk.

      We strongly recommend that you only specify AD users and groups so that the removal of a local user account cannot invalidate the entire Access Control Policy. If the Policy Agent encounters an invalid AD account entry, it simply ignores that entry and enables the rest of the Access Control Policy.

      For security reasons, we also recommend that you do not add SYSTEM as a whitelisted user.

      For the domain, you can select one of the following:

      • Local—This account is local to the Windows VM.
      • NT Service—This is a virtual account under which a Windows Service is running on the VM.
      • AD-Domain-Name—This account comes from the selected domain in the AD defined for the Cloud Admin Group associated with this policy.

      Note: The permissions list for a filesystem-level rule or a folder-level rule cannot be empty, so you cannot select all entries and click Delete. You must first de-select at least one entry before you can delete the others.

      If any of the entries in the permissions list are groups, make sure the order of the entries is correct.

      When the Policy Agent receives an access request, it processes the permissions list in order, from top to bottom. As soon as it finds an entry that matches the account that requested the data, it assigns that permission level to the user and stops processing the permissions list. If you have added an entry to deny a particular user access but the user is part of a group that was granted permission higher in the list, that user's request for access will be granted. For details, see Windows Access Control Rule Processing.

  8. When you are finished changing the policy, click Done. Cryptographic Security Platform Vault applies the changes to the associated disks the next time the VMs containing those disks heartbeat with Cryptographic Security Platform Vault.

What to Do Next 

If you want to force an update on one or more VMs so that the Access Control Policy changes are applied before the next scheduled heartbeat, you can log into the VMs as an administrator and use the hcl heartbeat command.