Field notes
Why baseline policies belong before a full endpoint rollout
Many estates install an endpoint agent first and write policies later. That order feels fast, yet it leaves each device on product defaults that rarely match how staff in eThekwini actually work—shared counters, warehouse scanners, and finance laptops with different risk profiles.
A baseline policy pack answers three questions before mass deployment: which protections are mandatory on every machine, which exclusions keep payroll and point-of-sale software usable, and who can change those settings after handover. Without those answers, technicians spend weeks chasing false positives instead of closing coverage gaps.
Start with a pilot group that mirrors your estate: one office desktop, one remote laptop, and one server role if you protect servers with the same product. Tune detection sensitivity, USB handling, and update rings on that group. Only then expand. The pilot should run long enough to catch weekly batch jobs, not just a single login day.
Document exclusions with a business owner named beside each entry. Anonymous exclusions grow quietly and become the reason auditors flag your environment months later. Service Hazelpoint includes this documentation step in every Endpoint Protection Setup engagement so the next admin inherits clarity, not folklore.
If you already deployed agents widely, treat a baseline exercise as a reset: export current policies, compare them to written company rules, and rebuild a single approved pack. Policy Alignment Review work often sits beside this reset when boards want evidence that practice matches paper.