Using Policy Management

Using Policy Management

Policy Management provides customized settings for LDO organizations. This feature is available only for Org Admins and MSP Admins.

Feature Settings

To access Policy Management settings, navigate to Policy Management > Feature Settings in the left pane. 

Feature 

Patch Preferences:

  1. Automatically Install Patch Runtime Dependencies. Enabling this option installs Microsoft C++ on devices if it is not detected.
  2. Patch Security Mitigation Options.
    1. The organization accepts the risk of installing unsigned packages from LDO Patch. If this option is selected, you will see an "unsigned package" indicator displayed next to eye icon. all unsigned patch packages will be included in the recommended patch list with an indicator icon that the package is unsigned.
    2. Unsigned Patch updates will be hidden and not displayed for remote update through LDO. Any unsigned packages will not be visible in the Patches list.

    System Update Preferences:

    Adds the ability to schedule System Update activities across all eligible devices on your network. Enable or disable the following options:

    • Automatically Scan only for New Updates. Checks for new updates every Monday at 6am ET. New updates will automatically appear on System Update page.

    When this option is enabled, the date and time of the last scan are displayed on the App Management > System Update page, below the Check for updates link. This link is disabled for 30 minutes immediately after the last automatic scan is initiated.

    • Automatically Scan and Update. Lets Org/MSP Admins schedule when LDO should automatically scan eligible devices or groups. Multiple schedules can be created for different device group(s). Both Recurring and Maintenance Windows can be created.
      1. To Enable this feature, slide the corresponding button to turn it on. 
      2. Click Add New.
      3. Enter the name for the schedule.
      4. Select the Schedule Type.
      5. Select the Severity(ies), the Update Type(s), and a Frequency. 
        1. For Recurring updates: select the Day(s) of the week and Start time.
        2. For Maintenance: select Start and End date from the calendar, click Apply, then select Start and End times. You have the option to a Force Reboot once maintenance is concluded.
      6. Click Next.
      7. Select the Group(s) Name(s) or select Update all eligible devices
      8. Click Ok.
      9. Click Save at the bottom of the page.
    To modify, delete, or add groups to an existing schedule, open its accordion and click Edit. Follow the steps an confirm. If the selected schedule type is Maintenance, the update type cannot be modified.
    1. If the Testing functionality is enabled, LDO should deploy only the updates that have the Allowed to Deploy status.
    2. The same schedule applies to all eligible devices
    3. All automated updates can be monitored on the System Update page through the deployment process and then monitored on the System Update Status Report.
    • Automatically Install System Update Add-in. Auto installs System Update Add-in if it is not detected on device. This is required for System Update operations.

    NotesOnly online devices can be auto-scanned; offline devices will need to be manually scanned (on-demand).
    Only those updates with the Allowed to Deploy status will be included in the Auto Update.

    • System Update Messaging and Deferrals. Allows to configure System Update preferences for devices which require a reboot for the update to be applied.
      • Set the number of deferrals allowed to end user: This option defines the maximum number of times a user can postpone a Required Reboot for an update.
      • Set the time - in Minutes, Hour(s), or Day(s) - between the notification and the device reboot.

    The system will display a notification prompting the user to allow the reboot for the update. It will also show the total number of deferrals allowed and the number already used. 

    If the user still has a deferral available, they can click No to postpone the reboot. In that case, the System Update report will display the status Reboot Required for the corresponding device. 

    However, if no deferrals remain, they must save their work and click OK to proceed with the reboot.

    1. Update Testing. When enabled, this feature lets you select one or more devices or device groups to test a System Update. The update is flagged on the System Update page, and you can set a start and end date. It remains blocked from other devices until approved for rollout.

    2. Customize End User Dialogue Box. Add your company name and logo to personalize the dialog box shown to end users.

    Manage Accessories:

    1. Automatically Install Lenovo Dock manager:  Enabling this button allows the Lenovo Docking Station Manager to be installed automatically on the client device, but only if it is not already detected. 

    Feature controls:

    Acts as an additional security layer. When enabled, any user should be logged in to the LDO portal using Multi-factor Authentication (MFA) to perform specific operations.

    Auto Install of Intel vPro® Agent:

    Enables/Disables the automatic installation of the Intel vPro® agent on Intel vPro devices during the provisioning process.

    Notes
    These options are set to “Disabled” for all new organizations by default. Even if disabled, the manual installation option via the Device Management > Devices > Device Tray is still available.

    Automatic Device Cleanup:

    Enables automatic removal of devices that remain offline for a specified threshold period, which can be set in the Days text box. Device licenses are returned to the license pool and can be reassigned to another device for the remaining period. Click Save and Confirm.

    UDC  Logging: This option is disabled by default, and only errors are logged in the registry. Enabling it activates the Collect Logs button on the Device Management> Devices> Devices page. To turn on this feature, toggle the switch and click Save. This feature is available for Windows, Android and Linux devices.   For more details, refer to Managing Devices - Devices Page.