When trying to use a Policy Target Rule to apply a Web and Cloud Access Protection policy (WCAP) in Symantec Endpoint Security (SES), the agent does not switch to the desired Location or install and start using the WCAP feature.
Symantec Endpoint Security agents
A bug within the SES Cloud console UI allows SES admin to apply a WCAP policy to any Policy Target Rule other than Default. When WCAP is applied to any Policy Target Rule other than Default, it will not take affect.
When a WCAP policy is applied to a device, it installs the necessary client features to enforce the policy. This behavior is the same with a Feature Selection Policy. Since both of these policy types can add or remove Feature Sets from the agent, they are intended to only be applied to the Default policy target rule (also referred to as a Location) so the agent does not regularly change feature sets.
A fix is being developed for this issue which will not allow you to apply a WCAP policy to Policy Target Rules other than Default.
The Web and Cloud Access policy should be applied to the Default policy target rule. It should also be withdrawn from any Policy Target Rule other than Default since it will not take affect. To resolve the issue first remove the WCAP policy from any non-Default policy target rule, then apply WCAP only to the Default policy target rule.
CRE-24734