Handle exceptions more easily
Today is quite hard to create simple exceptions. For example: Lets say we have a main user policy that uses a Web filtering policy, a QoS policy, a default routing policy and an App filtering policy.
Now, lets say we have a user inside this policy that should get a specific web site access that is currently blocked in the web filtering policy. Also, another user needs to get more/less bandwithd than everyone else. Also, a user have to get routed through a specific link and not follow the default route balance. Also, another user must have an application allowed.
This will force us to create SEVERAL policies in the "unified policy schema". So, instead of a clean set of rules with some exceptions inside them, we will have to replicate the main policy several times and make adjustments in the specific policies, that should now receive maintenance and attention for every global policy decision.
A unified policy is a Good Thing™ from a theoretical perspective but it is really messing things up in a real world environment.