Policies allow/stop Access/Admin rights and configure Device/DNS settings. They include assignment criteria that define exactly when each Policy will be applied.
Before you start, pre-configure the following elements:
Entitlements: refer to Entitlements configuration
Ringfence: refer to Ringfence configuration
Admin roles: refer to Admin Roles configuration
Customized Claims: to set up customized claims for Policy assignment criteria, refer to Identity Provider
Scripts: create and upload any criteria scripts or user claim scripts or create (Assignment) Criteria expressions
Background information:
The role of Policies in provisioning rights, refer to: User/Device Access and System Administration
The use of Application Discovery to help identify the best Policy fit for groups of Entitlements
The claims available for creating Policy criteria expressions, refer to: User Claims, Device Claims, Claims in detail
Propagating changes to Policies, refer to: Disable, change or remove access
Use the Policies form for:
Creating new Policies to assign rights to one or many users/devices
Managing Client access rights using Entitlements
Adding or removing admin roles
Adding or removing device/Client settings
Adding or removing DNS settings used by the device
Stopping one or many users/devices from signing-in
Performing bulk actions
Performing actions using the action buttons provided (See below).
For details on completing the form, refer to configure Policies
Settings 
In the Settings menu, there is the option of Normal or Details view. Details expands the information for Entitlements.
Actions
The Admin UI tools page provides more information about the operations that can be performed.
Action Buttons
Action buttons are accessed by clicking the 3 dots to the right of each line item in the table or from the <Actions> button within the item. They are contextual, changing depending on the type of item and the state of the item.
Enable/disable Policy Status. This switch allows the status to be set to Enabled or Disabled.