You can assign Disk Encryption policies to devices and device folders. You cannot assign a Disk Encryption policy to device groups, users, user groups, or user folders.
A device can apply only one Disk Encryption policy. When multiple Disk Encryption policies are assigned to a device through different objects (the device, group, or folder), the Full Disk Encryption Agent must determine a single effective policy to enforce on the device. Effective policies are discussed in Section 4.0, Effective Policy.