Allow for complete control of the base policy in Sophos Central Endpoint Protection.
It would be nice to have the ability to enable, disable, and/or fully customize all aspects of the base policy in Cloud endpoint protection. For example, some organizations may not want or need peripheral (device) control but currently you cannot disable it in the base policy. As the base policy is always assigned to computers/users, in addition to any custom policy, if you disable it in the custom policy (that is higher in rank than the base) the base policy turns it back on. What's the point of disabling it in a custom policy if the base overrides it.
The other option would be to allow for the removal of the base policy from a computer after a custom policy has been assigned to that user/computer.
The reason behind this request is every aspect of an AV system (threat, web, device control, etc.) adds a load to the client system, regardless of how small that load is. To fully optimize the performance of an AV system, unwanted portions should be disabled which you are not currently able to do.