Skip to main content
Cisco Meraki Documentation

Applying Group Policies to Systems Manager (MDM) Devices using Tags

Sentry Policies enable dynamic group policy applications in Security Appliances and Wireless networks based on clients' device posture or user information collected from Systems Manager MDM or Agent-enrolled endpoints.  

Creating MDM Sentry Policies

  1. Configure a group policy (or policies) on the desired Security Appliance or Wireless network.
    2017-07-20 09_03_39-Group policies configuration - Meraki Dashboard.png
  2. Navigate to Network-wide > Configure > Group policies.
  3. Under the "Systems Manager Sentry Policies section", click Add a new group policy MDM scope.
  4. Select the Systems Manager network that contains the devices and tags to be used.
  5. Choose the Tag scope that determines how the specified Tags will be used. For more information, refer to the article on using tags in Systems Manager.
  6. Select any desired Tags that will be matched against. These can be manual or auto tags.
  7. Select the group policy that should be applied to devices matching the tag criteria.
  8. If additional policies need to be created, repeat steps 3-7 as needed. 
  9. Click Save Changes.

2017-07-20 09_44_34-Sentry Policies - Meraki Dashboard.png

Remember that policies are processed in descending order based on priority (leftmost column) and only apply to the first match. Thus, only the highest priority policy will be used if a device is within the scope of two or more policy mappings. To reorder the policies, drag the move icon (four-directional arrow) in the Actions column.

Deleting or Modifying Sentry Policies

To delete a Sentry policy:

  1. Click the X in the Actions column for the desired policy.
  2. Click Save Changes.


To modify a Sentry policy:

  1. Make any desired changes to any of the columns.
  2. Click Save Changes.
  • Was this article helpful?