> For the complete documentation index, see [llms.txt](https://docs.faronics.com/faronicsdeploy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.faronics.com/faronicsdeploy/policies-scheduling-and-automation/create-a-policy/create-a-windows-policy.md).

# Create a Windows Policy

## Before you Start

Make sure you have the following configured before you start:

* Faronics Deploy Agent Installed on the Computers you wish to install the applications on.

## How to Create a Windows Policy

<figure><img src="/files/ol4lceMS7U7A2RA0gOYb" alt=""><figcaption><p>Create a Windows Policy</p></figcaption></figure>

1. Select the **Control Grid** tab on the top menu bar.
2. Navigate to the **Policies** tab.
3. Click the **CREATE NEW POLICY** drop-down menu.
4. Select **WINDOWS POLICY** from the menu.
5. Enter a name for the policy, **Seattle Office**, in this example.

<figure><img src="/files/m74FQPPG3qyMPXWQyH0E" alt=""><figcaption></figcaption></figure>

6. Select an update mode, **Semi-Automatic** in this example.
7. Select a schedule mode, **Once a day**, in this example.
8. Set the time delay for maintenance mode after booting; the default is **15 min**.
9. **Optional**: Check the box to **Notify User that computer is entering maintenance mode**. Default is enabled.
10. &#x20;**Optional**: Check the **Allow Snooze** box to allow the user to snooze maintenance mode. Default is enabled.
11. **Optional:** Enter a **Password** to protect against unauthorized uninstalling of the Deploy Agent.
12. **Optional**: Check the **Enable proxy** box if your computers require a proxy to reach the Deploy cloud server.<br>

    <figure><img src="/files/QY9z01ts0j9atOGdE3tY" alt=""><figcaption><p>Enable Proxy</p></figcaption></figure>
13. &#x20;If you enabled the proxy setting, enter a **Proxy Address**. *Otherwise skip to Applications step 1*.
14. Enter the proxy **Port**.
15. **Optional**: Check the User Authentication box to require authorization for the proxy. Default is disabled.
16. Select the User Authentication type from the drop-down list, **BASIC**, **NTLM**, or **DIGEST**.
17. Enter the **Username** for the proxy.
18. Enter the **Password** for the proxy.
19. Enter the **Domain** for the proxy.

**Applications**

<figure><img src="/files/XQezxzqyojyfb5bj3nak" alt=""><figcaption><p>Managed Applications Updates Configuration</p></figcaption></figure>

1. Select **Applications** on the left menu.
2. The **Managed Applications** will be configured to update based on the [Policy Update Mode](/faronicsdeploy/policy-update-mode.md) selected in step 6 (**Semi-Automatic** in this example).&#x20;

{% hint style="info" %}
The **Semi-Automatic** default settings are used; if you make any changes to the application Update Modes, the policy will become a custom policy. See [Policy Update Mode](/faronicsdeploy/policy-update-mode.md) and [Policies (Windows)](/faronicsdeploy/policies-windows.md) for further information on policies.
{% endhint %}

3. The **Winget Applications** are on the tab to the right of Managed Applications; click the tab to display and configure the settings for all Winget Applications installed.

<figure><img src="/files/zW3fWCx5k8v3sa98PANB" alt=""><figcaption><p>Winget Applications Updates Configuration</p></figcaption></figure>

**Windows Updates**

<figure><img src="/files/zSjJpwdZmorF0NV2Rwue" alt=""><figcaption><p>Windows Updates Configuration for Policy</p></figcaption></figure>

1. Select **Windows Updates** in the menu on the left.
2. **Optional:** If you do not want Faronics Deploy to manage the Windows Updates for **this policy** (this will only affect computers connected to this policy), check the **do not manage Windows Updates** box; **skip to step 19**.&#x20;
3. By default, the **Automatic Install** is selected for the **Windows Updates**; you can click the grid alongside any **Windows Update Type** that you do not wish to automate.
4. **Optional**: If you wish to **Manage driver updates**, check this box. Once this is enabled, **Drivers** will appear as a category in the list of managed updates.

![Manage Driver Updates (Experimental) are Enabled](/files/7g5bxB5EBrChnAnAYrwt)

5. **Optional:** Check the **Download and keep Windows Update ready when available**. Default is enabled.
6. **Optional:** Check the **Force auto reboot prior to installation if user is logged in** box. Default is disabled.
7. **Optional:** Check the **Allow user to defer reboot (if required)** box if you wish to enable this and enter a number of times to allow this to occur before it becomes mandatory to reboot, a maximum of 5 times. Default is unchecked.
8. Select a **Patch Scan Frequency**, Once every 6, 12, or 24 hours. Default is set to 24 hours.
9. Scroll down to the **Additional Settings for Windows 10**, and choose when updates are installed, either **Semi-Annual Channel (Targeted)** (this is the default) or **Semi-Annual Channel**.&#x20;

{% hint style="info" %}
**Semi Annual Channel (Targeted)** - Ready for most people.                       &#x20;

**Semi Annual Channel** -  Ready for widespread use in organizations.

For further information on Additional Settings for Windows 10, see [Policies (Windows)](/faronicsdeploy/policies-windows.md#windows-10-additional-settings)
{% endhint %}

10. **Optional:** Set a **Feature Update Deferral**; this can be set from 0 - 365 days. The default setting is 0.&#x20;
11. **Optional:** Set the **Quality Update Deferral**; this can be set from 0 - 30 days. Default is 30 days.

**Anti-Virus**

<figure><img src="/files/O8EuEXHODU4gtjYBQHLi" alt=""><figcaption><p>Enable Anti-Virus for the Windows Policy</p></figcaption></figure>

1. Select **Anti-Virus** in the menu on the left.
2. Click the **ENABLE ANTI-VIRUS** button.
3. Configure your virus settings. See [Faronics Anti Virus & Firewall Protection Configuration](/faronicsdeploy/anti-virus/faronics-anti-virus-and-firewall-protection.md) for further information on Anti-Virus, Firewall , & Computer Settings.

**Remote**

<figure><img src="/files/p8ivQvDkRXBIyv1ywFZy" alt=""><figcaption><p>Enable Remote PRO</p></figcaption></figure>

1. Select **Remote** in the menu on the left.
2. Check the box if you want to ask for user permission before remotely accessing a computer (this will apply to all remote access methods).

{% hint style="info" %}
This is configurable even if you don't have the Remote Pro functionality enabled on your license.
{% endhint %}

3. Click the green **ENABLE REMOTE PRO** button.&#x20;

{% hint style="info" %}
This will install Remote Pro on all computers that have this policy.
{% endhint %}

4. Click Install to confirm that you want to install Remote Pro on all computers with this policy.

![](/files/KptKiNI8mjvu6IdmmGeP)

5. Select the server that is geographically closest to you from the drop-down list.

<figure><img src="/files/UAW2QAHhwbHiJP6iXo5C" alt=""><figcaption><p>Select a Connection Server</p></figcaption></figure>

6. If you wish to remove Remote PRO from all computers on this policy click the **UNINSTALL REMOTE PRO** button.
7. Click the **SAVE** button.

{% hint style="success" %}
A Windows Policy has successfully been created.
{% endhint %}
