---
title: "Creating Endpoint Groups"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35473957/Creating%20Endpoint%20Groups"
format: markdown
---
When applying security policies to multiple Infoblox Endpoint devices, you can make the process more efficient by organizing the endpoint devices into Infoblox Endpoint groups and then add the groups to the network scope when you create a security policy. Note that Infoblox endpoints comes with a default endpoint group called **All Infoblox Endpoints (default)** that is associated with the default global policy. You can assign an endpoint to an existing custom endpoint group at the time of its installation, thus bypassing its default assignment to the **All Infoblox Endpoints** group. Infoblox Endpoint can authenticate access by using a third-party identify provider (IdP) to enforce security policies within an endpoint group. You cannot modify or remove the default endpoint group. An endpoint group can have up to 250,000 endpoints assigned to it. 

> ⚠️ An endpoint can be assigned to an existing custom endpoint group rather than being assigned to the default endpoint group at the time it is installed. Metadata indicating the name of the custom endpoint group to which the newly installed endpoint has been assigned can be viewed in the endpoint service logs.

To create Infoblox Endpoint groups, complete the following:

1. From the Infoblox Portal, go to **Security** > **Threat Defense **> **Endpoints** > **Endpoint Groups**.
2. On the **Endpoints **page, select the** Endpoint Groups** tab, and click the **Create** button under the three vertical dots icon:dots:located to the right of the filtering field.
  
3. The **Create Endpoint Group** wizard page. The Create Endpoint Group wizard is composed of five configuration steps:
  1. Overview
  2. Authentication Settings
  3. Schedule Updates
  4. Network Settings
  5. Advanced Settings

### **Overview**

The *Overview* page of the Create Endpoint Group wizard to define the basic endpoint group details, assign tags, configure the group state, set the logging level, and specify when inactive endpoints are automatically removed.

![The Endpoint Group Creation Wizard screen 1 - Overview.](media://7a93b62b-e91e-4b36-8075-bb6e79da17b1)

On the *Overview* page, complete the following fields:

| **Fields ** | **Description** |
| --- | --- |
| **Endpoint Group Name** | Enter a unique name for the Infoblox Endpoint group. This field is required. |
| **Description** | Enter a brief description for the endpoint group. The description can contain up to 256 characters. |
| **Tags** | Add key/value tags to help identify or organize the endpoint group.<br>- Click **Add** to open the **KEY/VALUE** panel, then enter a key and value.
- To remove a tag, select the checkbox next to the tag and click **Remove**. |
| **Associated Policy** (uneditable) | An **associated policy **refers to the security policy that is linked to a specific Endpoint Group. An Endpoint Group is a collection of endpoints (devices) to which the same security policy is applied. |
| **State** | Enable or disable the endpoint group. The group is set to **Disabled** by default. Toggle the switch to the right to enable endpoints for the group. |
| **Log Level** | Select the logging level for the endpoint group. The available options are **INFO** and **DEBUG**. The default logging level is **INFO**. For information on Infoblox Endpoint system logging, see *[Endpoint System Logging](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/70354570)* |
| **Removal after inactivity (days)** | Enter the number of days after which inactive endpoints are automatically removed. The supported range is **15 to 180 days**. If you enter no value, a value less than 15, or a value greater than 180, an error message prompts you to enter a valid value. You can update this value after the group is created. The Infoblox Platform service monitors inactive endpoints for the configured period and removes endpoints that remain inactive. |

After completing the Overview page, click **Save** to save the configuration and exit the wizard, or click **Authentication Settings** in the side menu to continue to the next page of the **Create Endpoint Group** wizard.

### Authentication Settings

On the *Authentication Settings* page of the Create Endpoint Group wizard to configure the endpoint group’s authentication session, authentication server port, and authentication profile.

![The Endpoint Group Creation Wizard screen 2 - Authentication Settings.](media://ad27930f-4364-43b7-b826-4bbcd0183dcd)

On the *Authentication Settings* page, complete the following fields:

| **Fields ** | **Description** |
| --- | --- |
| **Session TTL** | Specify how long the IDP session persists. The default value is **8 hours**. After the IDP session disconnects, the connection must be manually re-established.<br>![Session TTL time options.](media://0f3a2fde-a0e1-40f3-b728-df3a8d690178) |
| **Authentication Server Port** | Specify the server port used to authenticate the endpoint group. The default TCP port is **9094**. This value represents the third-party IDP port number. |
| **Authentication Profile** | Click **Select Authentication Profile** to enable authentication for the endpoint group. Select an authentication profile from the list of profiles available for use with the endpoint group. The supported authentication protocols are **SAML** and **OpenID Connect**. For more information, see *[Adding an Authentication Profile to an Endpoint Group to Enforce a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35470899)*.<br>![Authentication Profile options.](media://8c6da7d6-b68b-4d96-8675-5b84dcf4f044) |

After completing the **Authentication Settings** page, click **Save** to save the configuration and exit the wizard, or click **Schedule Updates** in the side menu to continue to the next page of the **Create Endpoint Group** wizard.  
For information on managing access authentication, see *[Managing Access Authentication](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35396331)*.  


### **Schedule Updates**

On the *Scheduled Updates* page of the Create Endpoint Group wizard to configure how endpoint updates are installed, schedule update windows, and defer updates for a defined period.

![The Endpoint Group Creation Wizard screen 3 - Scheduled Updates.](media://a817a870-a05d-496c-8454-414dd5f05c49)

On the *Scheduled Updates* page, select one of the following update options:

| **Fields (options)** | **Description** |
| --- | --- |
| **Automatic Updates** | Select this option to install updates automatically. This is the default option. |
| **Schedule Updates** | Select this option to manually choose the day, time, and duration for endpoint updates. |
| **Defer Updates** | Select this option to defer updates. |

### **Automatic Updates**

If you select **Automatic Updates**, the system will automatically apply updates when they become available.

### **Schedule Updates**

If you select **Schedule Updates**, complete the following fields:

| ### **Schedule Updates Fields** | **Description** |
| --- | --- |
| **Days of the week to perform upgrades** | Select one or more days of the week when endpoint upgrades can be performed. |
| **Local Endpoint Time** | Select the local time of day when the upgrade window begins. |
| **Duration** | Specify how long the system can attempt to perform the update. You can select a duration from **4 to 10 hours**, in one-hour increments.<br>![Scheduling updates.](media://10180e48-cbcc-4302-b11f-36d909264339) |

### Deferring Updates

You can defer endpoint updates for up to **28 days**. Deferring updates allows you to choose a specific day of the week and local endpoint time for deployment, regardless of the original scheduled release date. This prevents you from having to adjust the deferred update schedule in the **Infoblox Portal** before each new Infoblox Endpoint update release.

- Scheduled deferred updates are performed based on the time zone of the local endpoint.

To defer updates, complete the following fields:

| **Defer Updates Field** | **Description** |
| --- | --- |
| **Always defer upgrades for** | Select the deferment period. You can defer updates from **1 day to 28 days**. The maximum deferment period is **28 days**. |
| **Days of the week to perform upgrades** | Select one or more days of the week when upgrades can be performed. Select **All** to allow upgrades on any day of the week. |
| **Local Endpoint Time** | Select the local time of day when deferred upgrades begin. |
| **Duration** | Select the number of hours during which updates can be performed. |
| ![Deferring updates.](media://b80f09d2-87f7-4840-8141-71cc085a7d2b) |

After completing the *Scheduled Updates* page, click **Save** to save the configuration and exit the wizard, or click **Network Updates** in the side menu to continue to the next page of the **Create Endpoint Group** wizard.  
For more information, see *[Scheduling Endpoint Group Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35374562)*. 

### **Network Settings**

On the *Network Settings* page of the **Create Endpoint Group **wizard to configure network location, Point of Presence selection, internal DNS resolvers, fallback DNS resolvers, and mobile endpoint domains.

![The Endpoint Creation Wizard screen 4 - Network Settings.](media://9aa4a82e-5d9e-4f3b-ae95-ff19d057bfcc)

On the **Network Settings** page, complete the following sections as needed:

| **Fields** | **Description** |
| --- | --- |
| **IP Address** | Add the IP address where the endpoint group resides on the network. |
| **PoP Setting** | Use **PoP Settings** to improve performance by selecting a preferred **Point of Presence** according to region.<br>Select the preferred **Point of Presence** for the endpoint group. A PoP selection is required.<br>A PoP can be selected automatically or manually.<br>- **Automatic selection**:** **Select this option to have the PoP selected automatically. Set the **Auto Selection** switch to **On**. Auto Selection is enabled by default.
- **Manual selection**: Select this option to manually choose a preferred PoP. Set the
- **PoP locations**: When the manual PoP selection option is chosen, select a PoP server from among the following options: |

### Internal DNS Resolvers

To add an **Internal DNS Resolver**, click **Add** and complete the following fields:

| ### **Internal DNS Resolvers Fields** | **Description** |
| --- | --- |
| **DOMAINS LIST** | Click **Add** to open the list of available internal DNS resolver domain entries. |
| **FQDN/IP ADDRESS** | Enter the FQDN or IP address of the internal DNS resolver. |
| **FALLBACK TO NETWORK RESOLVER** | Enable fallback to the network resolver for domains in the list by toggling the switch to the **Enabled** position. Domains in the list are routed to the configured internal DNS resolver for resolution. |
| ![The Internal DNS Resolvers panel (expanded).  ](media://28c3e2c7-087b-466a-b15c-81a1e80c512a) |

Click **Add** to add the internal DNS resolver to the list.

- You can reorder the list of fallback DNS resolvers by clicking :selector: then dragging the members of the list into the desired position.
- For additional information, see *[Adding Internal DNS Resolvers and Fallback DNS Resolvers to an Endpoint Group](https://docs.infoblox.com/space/BloxOneThreatDefense/35470930/Adding+Internal+DNS+Resolvers+and+Fallback+DNS+Resolvers+to+an+Endpoint+Group)*.

### Fallback DNS Resolvers

To add a **Fallback DNS Resolver**, click **Add** and complete the following fields:

| ### **Fallback DNS Resolvers Fields** | **Description** |
| --- | --- |
| **FQDN/IP ADDRESS** | Enter the FQDN or IP address of the fallback DNS resolver. |
| **STATUS** | Enable the resolver by toggling the switch to the **Enabled** position. |
| **ENCRYPTED DNS** | Enable encrypted DNS by toggling the **Prefer Encryption** switch to the right, to the **Enforce Encryption** position. |
| ![2-fallback DNS Resolver.png](media://63226648-cbbd-41fe-ab47-0d47ebc4093b) |

Click **Add** to add the fallback DNS resolver to the list.

- You can reorder the list of fallback DNS resolvers by clicking :selector: then dragging the members of the list into the desired position.
- For additional information, see *[Adding Internal DNS Resolvers and Fallback DNS Resolvers to an Endpoint Group](https://docs.infoblox.com/space/BloxOneThreatDefense/35470930/Adding+Internal+DNS+Resolvers+and+Fallback+DNS+Resolvers+to+an+Endpoint+Group)*.

### Mobile Endpoint Domains

To add a **Mobile Endpoint Domain**, click **Add** and complete the following fields:

| **Mobile Endpoint Domains Fields** | **Description** |
| --- | --- |
| **Domain** | Enter a domain or subdomain. |
| **Description** | Enter a description for the mobile endpoint domain. |
| ![The Mobile Endpoints Domains panel (expanded). ](media://71204d1a-2c57-4056-98a5-c5c894c6c08d) |

Click **Add** to add the mobile endpoint domain to the list.

- You can reorder the list of mobile endpoint domains by clicking :selector: then dragging the members of the list into the desired position.
- For information on Infoblox Mobile Endpoint, see *[Managing Mobile Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955/Managing+Mobile+Endpoint)*.

After completing the *Network Settings* page, click **Save** to save the configuration and exit the wizard, or click **Advanced Settings** in the side menu to continue to the next page of the **Create Endpoint Group** wizard.

### **Advanced Settings**

On the *Advanced Settings* page of the Create Endpoint Group wizard to configure offline protection, tamper protection, and on-premises protection for the endpoint group.

Configure a custom IP address when required to address interoperability issues with VPN, SSE, or SASE solutions. These settings should be enabled only when recommended by Infoblox Support. Custom addresses must use an IP address within the **127.0.0.0/24** range.

![The Endpoint Group Creation Wizard screen 5 - Advanced Settings.](media://91db372c-dcac-4eb4-b1b3-0bd0964787bf)

On the **Advanced Settings** page, complete the following sections as needed:

| **Section** | **Description** |
| --- | --- |
| **Offline Protection** | Enable offline protection to prevent roaming devices from accessing restricted domains when they cannot communicate with **Infoblox Threat Defense Cloud**. This can occur when the endpoint cannot connect to [http://csp.infoblox.com](http://csp.infoblox.com) or when there are issues with Infoblox anycast addresses. Offline protection is turned off by default. To enable basic offline protection, toggle the **Offline Protection** switch to **On**. The **Default Block** custom list is used as the offline protection list. |
| **Tamper Protection** | Enable tamper protection to help prevent unauthorized changes to the endpoint configuration. Tamper protection is turned off by default. Toggle the switch to the right to turn tamper protection on.   
For more information, see *[Endpoint Tamper Protection](https://docs.infoblox.com/space/BloxOneThreatDefense/1613135922/Endpoint+Tamper+Protection)*.<br>**Manage Password protection**  
Add a password for tamper protection or generate a system-created password. |
| **On-Premise Protection** | Configure the endpoint group to detect when an endpoint is protected by an on-premises DNS or DFP configuration. On-premises protection is enabled by default. |

### On-Premise Protection settings

In the **On-Premise Protection** section, complete the following fields:

| **On-Premise Protection** **Fields** | **Description** |
| --- | --- |
| **State** | Toggle the switch to **Enable**. On-premises protection is enabled by default. |
| **FQDN** | Use the default **probe.infoblox.com**, or define a custom, unique FQDN. Do not use a parent second-level domain, such as http://example.com. |
| **TXT Record** | Use the default TXT record, click **Generate random TXT record**, or define your own TXT record. |

Ensure that your on-premises DNS or DFP configuration is set up so the probe FQDN and TXT record behave as expected according to the bypass mode documentation.

After completing the **Advanced Settings** page, click **Save** to save the configuration and exit the wizard.  
For more information, see *[Checking Endpoint Status](https://docs.infoblox.com/space/BloxOneThreatDefense/35374388/Checking+Endpoint+Status)*.  
  
  
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>  



***CURRENT **

When applying security policies to multiple Infoblox Endpoint devices, you can make the process more efficient by organizing the endpoint devices into Infoblox Endpoint groups, and then add the groups to the network scope when you create a security policy. Note that Infoblox endpoints comes with a default endpoint group called **All Infoblox Endpoints (default)** that is associated with the default global policy. You can assign an endpoint to an existing custom endpoint group at the time of its installation, thus bypassing its default assignment to the **All Infoblox Endpoints** group. Infoblox <span style="color: #000000"> Endpoint can authenticate access by using a third-party identify provider (IdP) to enforce security policies within an endpoint group. </span>You cannot modify or remove the default endpoint group. <span style="color: #000000">An endpoint group can have up to 250,000 endpoints assigned to it. </span>

> ⚠️ An <span style="color: #000000">endpoint can be assigned to an existing custom endpoint group rather than being assigned to the default endpoint group at the time it is installed. Metadata indicating the name of the custom endpoint group to which the newly installed endpoint has been assigned can be viewed in the endpoint service logs.</span>

To create Infoblox Endpoint groups, complete the following:

1. From the Infoblox  Portal, click In the Infoblox Portal, go to **Security** > **Threat Defense **> **Endpoints** > **Endpoint Groups**.
2. On the **Endpoints **page, select the** Endpoint Groups** tab, and then click the **Create** button.
3. On the **Create Endpoint Group** page, complete the following:
  - **Endpoint Group Name **(required**)**: This is a required field. Enter a name for the Infoblox Endpoint group. Ensure that you enter a unique name for each endpoint group.
  - **Description**: Enter a brief description about the group.
  - <span style="color: #000000">**Associated Policy**</span><span style="color: #000000">: This field displays the associate security policy when you add the group to the policy. It shows </span><span style="color: #000000">**Default Global Policy**</span><span style="color: #000000"> by default.</span>
  - <span style="color: #000000">**State**</span><span style="color: #000000">: Endpoint group state is set to disabled by default. Toggle the switch to the right to </span><span style="color: #000000">**Enable Endpoints**</span><span style="color: #000000">.  </span>
  - <span style="color: #000000">**Tamper Protection**</span><span style="color: #000000">: Endpoint group tamper protection is set to off by default. Toggle the switch to the right to turn tamper protection on. </span>
  - <span style="color: #000000">**Log Level**</span><span style="color: #000000">: Select the level of logging. The default logging level is </span><span style="color: #000000">**Info**</span><span style="color: #000000">. For information on Infoblox Endpoint system logging, see </span><span style="color: #000000">[Endpoint System Logging](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/70354570)</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Automatically remove endpoints after a period of inactivity**</span><span style="color: #000000">: To automatically remove endpoints due to inactivity, enter a value from 15 to 180. "If you specify no value, a value between 1 and 29, or a value greater than 180, then an error message will ask you to specify a different value. You can adjust the value any time after the group is created. If you specify 0, automatic removal will be disabled. Infoblox Platform</span><span style="color: #172b4d"> service will monitor the status of inactive endpoints during configurable period of time (from </span><span style="color: #000000">15</span><span style="color: #172b4d"> to 180 days) and then remove the remaining inactive endpoints.</span>
  - <span style="color: #000000">**Tags**</span><span style="color: #000000">: In the Tags section, complete the following:</span>
    - <span style="color: #000000">Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to open the </span><span style="color: #000000">**KEY/VALUE **</span><span style="color: #000000">panel to assign a tag or tags to an endpoint group. To remove a tag from an endpoint group, select the checkbox located to the left of the tag entry, then click </span><span style="color: #000000">**Remove**</span><span style="color: #000000">. </span>
    - <span style="color: #000000">In the editable field, add a key and a value..</span>
    - <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close **</span><span style="color: #000000">to save your configuration.</span>
  - <span style="color: #000000">**Authentication Settings**</span><span style="color: #000000">:</span>
    - <span style="color: #000000">**Session TTL**</span><span style="color: #000000">: </span><span style="color: #172b4d">Specify the period of time the IDP session is to persist. The default is 8 hours. After IDP session disconnects, manually connection needs to be established.</span><span style="color: #000000"> </span>
    - <span style="color: #000000">**Authentication Server Port**</span><span style="color: #000000">: </span><span style="color: #172b4d">Specify the server port that will be used to authenticate the endpoint group. The default TCP port is 9094. This is the third party IDP port number.</span>
    - <span style="color: #000000">**Authentication Profile**</span><span style="color: #000000">: Click </span><span style="color: #000000">**Select Authentication Profile**</span><span style="color: #000000"> to enable authentication. select an authentication profile from the list of profiles available for use with the endpoint group. The available authentication protocols are SAML and OpenID Connect. For more information, see </span><span style="color: #000000">[Adding an Authentication Profile to an Endpoint Group to Enforce a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35470899)</span><span style="color: #000000">.</span>
      - <span style="color: #000000">For information on managing access authentication, see</span><span style="color: #ff0000"> </span><span style="color: #ff0000">[Managing Access Authentication](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35396331)</span><span style="color: #ff0000">.  </span>
  - **Internal DNS Resolvers:**
    - An internal DNS resolver is a local DNS server that maintains authoritative information for internal domains and handles DNS requests for clients inside your network. You can configure internal resolvers so that any DNS queries for domains specified within your internal configuration are directed to your internal DNS infrastructure instead of being forwarded externally.
    - When you assign an internal resolver to an Endpoint Group, the resolver will handle all DNS queries for domains defined in the associated **Internal Domains List**. This ensures that internal domains—such as corporate services, private application endpoints, and internal-only namespaces—are consistently resolved by your internal DNS servers.
      - To associate an Internal Domains List with an Endpoint Group:
        - Click **Add** to open the list of available internal domain lists.
        - In the **Name** column, select the internal domains list you want to apply.
    - The domains in that list will be routed to the configured internal DNS resolver for resolution.
    - For information on using internal domains lists with an endpoint group, see [Adding an Internal DNS Resolver or Fallback DNS Resolver to an Endpoint Group](https://docs.infoblox.com/space/BloxOneThreatDefense/35470930/Adding+Internal+DNS+Resolvers+and+Fallback+DNS+Resolvers+to+an+Endpoint+Group).
  - **Fallback DNS Resolver**:
    - A fallback resolver acts as a safety net. If the main DNS path via Infoblox fails, DNS queries are directed to this pre-configured local DNS resolver to maintain continuity. To add a fallback DNS resolver to an Endpoint Group, complete the following:
    - For information on creating custom fallback resolvers, see [Endpoint Custom Fallback Resolvers](https://docs.infoblox.com/space/BloxOneThreatDefense/1770061828/Endpoint+Custom+Fallback+Resolvers).
  - **Bypass Mode**: By enabling Infoblox Endpoint bypass mode for a Infoblox Endpoint group, you can define your own domain and response for On-Prem DNS service protected by DNS Firewall. For information on enabling bypass mode see <u>[Infoblox Endpoint Bypass Mode](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35404862)</u>.
    - To enable Bypass Mode for an endpoint group, complete the following:
      - **State**: Toggle the State switch to **Enable** from the default disabled state to enable bypass mode for the endpoint group.
      - **FQDN**: Use the default FQDN or a custom FQDN.
      - **TXT Record**: Use the default TXT Record or a custom TXT record by clicking **Generate random TXT record**.
  - **Basic Offline Protection**: By enabling Infoblox Endpoint offline protection for a Infoblox Endpoint group, you can you can prevent roaming devices to access restricted domains (defined with the Default block list) when they can’t communicate with Infoblox’s Threat Defense Cloud. For example, scenarios such as failures when connecting to csp.infoblox.com or issues with Infoblox anycast addresses.
    - To enable basic offline protection, complete the following:
      - Toggle the Offline Protection switch to the **On** position. Your Default Block custom list is used as your offline protection list.
      - Click **Add** to modify the Default Block custom list. For information on Custom Lists, see the topic on [Custom Lists](https://docs.infoblox.com/space/BloxOneThreatDefense/35473695/Custom+Lists).
  - **Management Passwords**: By enabling Infoblox Management Passwords for a Infoblox Endpoint group, you can protect Endpoints that are part of the group from being uninstalled, stopped, or disabled by anyone who does not have the management password from the local machine. To enable the management of passwords for an endpoint group, complete the following:
    - **State**: Toggle the State switch to **Enable** from the default disabled state to enable password management for the endpoint group.
    - <span style="color: #111111">**Management Password**</span><span style="color: #111111">: </span><span style="color: #000000">Alternatively, you can click Generate random password to use a system generated password. In all cases, remember to save the password elsewhere since once the password is saved, it cannot be viewed in the Infoblox  Portal again. The management password must contain a minimum of 8 characters including one uppercase letter, one lower case letter, one numeral, and one special character. Do note that the management password is required to disable or stop Infoblox Endpoint service or to uninstall Infoblox Endpoint. </span>
    - <span style="color: #000000">To reset a password, disable password management by toggling the </span>State<span style="color: #000000"> switch to the disabled position and save the configuration. Now you can go in and apply a new management password and resave the configuration.</span>
  - <span style="color: #000000">**Schedule Updates**</span><span style="color: #000000">: You can update endpoint groups automatically or defer updates from 0 to 28 days. Deferring can be useful when you want to validate the release of a new endpoint on a few devices prior to updating the endpoint for all users on your network. To schedule an update, specify the following:</span>
    - <span style="color: #000000">**Automatic Updates**</span><span style="color: #000000">: Select this option to have updates installed automatically.</span>
    - <span style="color: #000000">**Schedule Updates**</span><span style="color: #000000">: Select this option to manually choose the day, time, and duration for updates.</span>
      - <span style="color: #000000">**Day & Time**</span><span style="color: #000000">: Schedule a day and time for updates. </span>
      - <span style="color: #000000">**Duration**</span><span style="color: #000000">: Specify the period of time the system will attempt to perform an update. Select 4 to 10 hours, in one-hour increments. </span>
  - <span style="color: #000000">**Defer Updates**</span><span style="color: #000000">: Updates can be deferred for a maximum of 28 days with the flexibility to choose a specific day of the week and time for deployment, regardless of the original scheduled release date. The option to defer upgrades for a period of up to 28 days with ability to select a day and time means the deferred update schedule does not have to be adjusted within the Infoblox  Portal in the anticipation of each new Infoblox Endpoint update release. Scheduled deferred updates are performed based on the timezone where the local endpoint resides. For information, see </span><span style="color: #172b4d">[Scheduling Endpoint Group Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35374562)</span><span style="color: #172b4d">. </span>  
To defer updates, perform the following:
    - <span style="color: #000000">**Always defer upgrades for**</span><span style="color: #000000">: From among the list of options, select a deferment period. You can select a duration period of  1 day to 28 days, with a maximum deferment period of 28 days.   </span>
    - <span style="color: #000000">**Days of the week to perform upgrades**</span><span style="color: #000000">: Select a day or days of a week upgrades are to be performed. Or, select </span><span style="color: #000000">**All**</span><span style="color: #000000"> to perform upgrades on all days of the week. </span>
    - <span style="color: #000000">**Choose local endpoint time zone and duration**</span><span style="color: #000000">:</span>
      - <span style="color: #000000">Select a time of day the upgrades are to commence.</span>
      - <span style="color: #000000">Select a duration period (in hours) where updates are to be updated.</span>
  - <span style="color: #000000">**Advanced Settings**</span><span style="color: #000000">: In Advanced Settings, the </span><span style="color: #292a2e">IP address can be configured by the user to accommodate potential interoperability issues with VPN/SSE/SASE solutions. These settings should be enabled per a support recommendation only. </span><span style="color: #000000">Custom addresses must use an IP </span>address within the range** 127.0.0.0/24**.
  - <span style="color: #000000">**PoP Settings**</span><span style="color: #000000">: To improve performance, select a preferred Point of Presence (PoP) according to the region. You can select a PoP manually or have it selected automatically. To select a PoP manually, set the toggle switch </span><span style="color: #000000">**Auto Selection**</span><span style="color: #000000"> to the </span><span style="color: #000000">**OFF**</span><span style="color: #000000"> position, select a preferred PoP from the </span><span style="color: #000000">**Point of Presence**</span><span style="color: #000000"> drop-down list. To have a PoP selected automatically, set the switch to the </span><span style="color: #000000">**ON**</span><span style="color: #000000"> position. </span><span style="color: #000000">**Auto Selection **</span><span style="color: #000000">is set to On by default. </span>
  - <span style="color: #000000">**Mobile Endpoint Domains**</span><span style="color: #000000">: One or more domains must be added to an endpoint group if the deployment of Infoblox Mobile Endpoint is done using a QR code.  After scanning the QR, the user will receive a prompt to enter an email address to perform validation. The domain(s) will be matched to the user's email address as configured in Mobile Endpoint Domains. If it matches, the validation will be successful and if it does not match it will not work. </span>  
<span style="color: #000000">For information, see </span><span style="color: #000000">[Deployment of MDM-less Mobile Endpoint Using QR Code](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/429293681)</span><span style="color: #000000">. </span>  
<span style="color: #000000">To add a mobile endpoint domain to an endpoint group, perform the following:</span>
    - <span style="color: #000000">Click </span><span style="color: #000000">**Add **</span><span style="color: #000000">to add the following information:</span>
      - <span style="color: #000000">**Domain**</span><span style="color: #000000">: Add the name or names of the desired mobile domain(s). </span>
      - <span style="color: #000000">**Description**</span><span style="color: #000000">: Provide a description for the added mobile domain(s). </span>
      - <span style="color: #000000">**Search**</span><span style="color: #000000">: Copy/paste the name of a mobile endpoint domain into the search field to verify it has been added to the list or to view its description. </span>

## Adding an Internal DNS Resolver or Fallback DNS Resolver to an Endpoint Group

4. Click **Save** to save the current configuration and proceed to the next configuration screen, or click **Save & Close** to complete the endpoint group creation process.   


For information on moving a Infoblox endpoint to an endpoints group. see *[Moving an Infoblox Endpoint to an Endpoint Group](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35374578)*.

To view addition information on endpoint groups, see the following:

- <u>*[Viewing Endpoint Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35408355)*</u>
- <u><span style="color: #000000">*[Enabling and Disabling an Endpoint Group](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35470822)*</span></u>
- <u>*[Editing Endpoint Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35404952)*</u>
- <u>*[Removing Endpoint Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35437093)*</u>