RMM Policies
Decide what gets monitored, and on which machines - thresholds, Defender alerting, and remote access deployment.
Overview
Policies define what the RMM agent watches on a device, what scripts it runs, and how it handles Windows updates. Build a policy once, assign it broadly, and every covered machine follows it. The agent pulls its effective policy at startup and hourly, so changes reach devices automatically.
Monitors
Each monitor has an on/off toggle (and, where relevant, a threshold). Turn a monitor off and the agent stops raising that alert; change a threshold and the agent uses your value.
- Performance - CPU %, low memory %, and low disk space % thresholds, plus high uptime.
- Stability - blue screens, application crashes, and reboots.
- Hardware - drive SMART health and Device Manager errors.
- Security - firewall disabled, failed logons (with a threshold), and new local users.
- Windows Defender - threat detections, remediation/scan failures, and protection health (see Virus Alerts).
- Device Offline - alerts when a machine stops checking in past the minute threshold you set, and clears automatically when it returns. (This one is evaluated by the server, since an offline agent can't report itself.)
Setup Scripts
Scripts that run when a device comes under the policy. Choose a run condition: If Never Run (run once per device), If Not Run Within N Days (re-run periodically), or Always (keep it applied - runs at most once per day). Good for one-time configuration or ongoing enforcement of a setting.
Recurring Scripts
Scripts on a schedule - hourly, daily, weekly (choose days), or monthly (choose day of month), at the time you set. Every covered device runs them on that cadence. Runs and results appear in the asset's Script History.
Updates
Opt into automatic Critical and/or Security Windows update installation. The agent installs approved updates during an overnight window (roughly 3-5 AM local time; a machine that's never on overnight is caught up if it goes more than a week without patching). Feature updates and drivers are never auto-installed. Enable Auto Reboot to let the agent restart when an update requires it - it warns the user first and only reboots inside the overnight window.
Comet Backup
On a custom policy, a Comet Backup tab lets you set the cloud-backup storage amount (in GB or TB) for the devices that policy governs. The quota is applied to the customer's Comet Backup account when the backup client is deployed to one of their devices. The tab appears only when Comet Backup is configured in App Center → Comet Backup; system (plan-linked) policies instead take their storage amount from the maintenance plan's "Cloud Backup (optional)" setting. Because Comet provisions one backup account per customer, the quota applies to that customer's whole account.
Assignment
Policies attach at three levels, with the most specific winning: device > folder > customer. The folder tree supports drag-and-drop organization, and maintenance-plan folders are created automatically as devices enroll. A tenant-wide default policy covers new devices that don't match anything more specific.
The policy editor's Assignments tab manages this directly: click + Assign Policy to apply the policy to a customer, a folder, or a single device; each existing assignment shows the owning customer and a Remove button; and you can expand a customer or folder assignment to see exactly which devices it covers (each links to its asset page).
Remote Access Deployment
Policies can enable RustDesk remote access - the agent deploys and configures the RustDesk client automatically on every asset the policy covers. (For one-off machines, use the Install RustDesk button on the asset page instead. Setup lives in App Center > RustDesk.)
System Policies
Built-in system policies align with your maintenance plan tiers, using your custom plan names and colors, so Bronze/Silver/Gold devices get monitoring appropriate to what the customer pays for.
Alerts raised by policies land on the asset page and in your alert views, and can trigger Automated Remediation.