Is there a way to apply different policies in a group to different devices without having to create sub-groups?
I understand there can only be a single policy active on a group at a time, but it becomes cluttered if we have to make a sub-group each time an Endpoint needs a specific exclusion/protection alteration.
We have been advised to use tags, but I've looked that function up and it doesn't prevent us from creating sub-groups?
Bottom line is we would like to easily manage excluding one device from something in a policy and not another.