All Products
Search
Document Center

Secure Access Service Edge:Configure trigger templates

Last Updated:Jun 20, 2026

Secure Access Service Edge (SASE) allows you to create custom trigger templates and configure baseline elements. You can select an existing trigger template when configuring dynamic policy trigger conditions to simplify the process.

Background information

The SASE dynamic decision-making feature detects and responds to security threats in real time. It allows you to configure dynamic policies to automatically adjust security measures and take action on devices that match policy conditions.

Configure trigger templates

  1. Log on to the Secure Access Service Edge console.

  2. In the left-side navigation pane, select Dynamic Decision-making > Trigger Templates.

  3. On the Trigger Templates tab, click Create Template.

  4. In the Create Template panel, configure the Trigger Templates based on the following table.

    Parameter

    Description

    Template Name

    Enter a name for the template. The name must be 2 to 32 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).

    Trigger Settings

    Configure one or more trigger conditions and specify the logical relationship between them. For more information about the parameters, see Trigger configuration parameters.

    The panel also contains a Description field that supports up to 100 characters. In the trigger settings area, click + Add Condition to add conditions with an AND relationship within the same group. Click + Add Group to add condition groups with an OR relationship. For each rule, you can use multi-level drop-down lists to select a data category, a specific attribute, a comparison operator, and a target value.

  5. Click OK.

The following operations are available:

  • Filter: Filter by Template Name.

  • Edit: Click Details in the Operation column to edit the trigger template information in the Details panel.

  • Delete: Click Delete in the Actions column to delete the trigger template.

Configure baseline elements

The system provides four built-in baseline elements for compliance checks in dynamic policies. You can configure these elements to simplify setting trigger conditions.

  1. Log on to the Secure Access Service Edge console.

  2. In the left-side navigation pane, select Dynamic Decision-making > Trigger Templates.

  3. On the Baseline Element tab, click the drop-down list in the upper-left corner to configure baseline elements for different operating systems.

    The available operating systems are Windows and macOS.

  4. Click Configure in the Operation column. In the Configure panel, configure the baseline element based on the following table.

    Parameter

    Description

    Applicable operating system

    High-risk Port Enabled

    Configure the port numbers that must be disabled.

    Windows, macOS

    High-risk Software Used

    Select the high-risk software that must be blocked. In addition to the default software, you can add more software options. For more information about how to add software to the blacklist, see the software blacklist.

    Windows, macOS

    Antivirus Software Disabled

    Select from the list of built-in antivirus software. You cannot add other antivirus software options.

    Windows, macOS

    Windows Automatic Updates Not Enabled

    This default setting checks whether Windows automatic updates are enabled.

    Windows