This message was deleted.
# citrix-vad
s
This message was deleted.
d
When talking baseline, I think of the unfiltered policy that applies to everything unless over-ridden. This policy I mix user and computer policies. Otherwise, I don't mix computer and user policies, but that's usually because they often apply differently to different sets of users or computers and it makes more sense in our environment to do things this way.
w
I prefer to keep them separated when and where possible. It simplifies troubleshooting.
👍 1
j
I think this is architect-specific, there is no real best practice here. For me, i like baselines per function. So I tend to never touch the unfiltered policy except to make sure its last, and then I baseline security, printing, audio, video, connectivity in individual policies, and then from there exempt/alter accordingly -> this may be overkill, but it works and ticks the CCS boxes on engagements (and makes things nice to track to be fair)
o
really admin preference - big thing for us is baseline and then relaxed policies above the catch all/baseline policy - I don't separate user and computer.
d
Completely agree with the baseline then relax per use case above that as per @James Kindon and @Oz Zy comments. Splitting it out depends on how the org works IMHO.
💯 2