All Products
Search
Document Center

Secure Access Service Edge:Create a security baseline

Last Updated:Jul 17, 2026

Customize security baselines to define compliance standards for terminals that access your intranet applications, based on your enterprise's specific requirements.

Background

The SASE security client collects specified terminal attributes in real time. You can configure a security baseline template and integrate it with access control policies for your intranet. Only trusted terminals that meet the security baseline requirements can connect to the intranet.

Procedure

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Endpoint Management > Security Baselines.

  3. Click Create Policy, and in the Create Security Baseline Template panel, configure the trusted terminal matching policy.

    The SASE security client collects trusted attributes from terminals on your corporate intranet in real time. It supports Windows, macOS, Android, and iOS operating systems.

    Parameter

    Description

    Basic Configurations

    Attribute Group Name

    Set a name for the security baseline.

    The name must be 2 to 100 characters long and can contain letters, digits, hyphens (-), and underscores (_).

    Baseline Configurations

    Time Range

    Set the time range for the security baseline policy. This includes the Policy Expiration Time and Policy Effective Time.

    If the Policy Expiration Time conflicts with the Policy Effective Time, the expiration time takes precedence.

    Terminal Type

    Specify the type of terminal that can access the intranet applications in the Zero Trust policy:

    • Unlimited

    • Desktop terminals only

    • Mobile terminals only

    Secure Wi-Fi

    Specify the Wi-Fi networks that corporate terminals must use to access the intranet. Terminals connected to unlisted Wi-Fi networks cannot access the intranet applications in your Zero Trust policy. You can add up to 10 Wi-Fi names. This feature is available only for Windows and macOS.

    Each name must be 2 to 50 characters long. To add multiple names, separate them with a comma (,). You can add up to 10 names.

    Security Process

    Specify the names and file paths of required security processes on corporate terminals. Terminals without the specified processes cannot access the intranet applications in your Zero Trust policy. You can add up to 5 security processes.

    Each name must be 2 to 50 characters long. To add multiple names, separate them with a comma (,). You can add up to 10 names.

    Firewall

    Once enabled, computers without an active built-in firewall cannot access the intranet applications in your Zero Trust policy.

  4. Click OK.

    The security baseline appears in the baseline list. SASE evaluates endpoint access against the baseline based on your settings.

    You can also perform the following operations:

    • Edit: Click Details. In the Details pane, view or modify the target security baseline template.

    • Delete: Click Delete to delete the target security baseline template.

Next steps

When you create an intranet Zero Trust policy, bind an existing attribute group to it. Trusted terminals that meet the attribute group's configuration can then access the corporate intranet. For more information, see Configure a Zero Trust policy.