First of all, I appreciate all the information. However, I feel I may have explained poorly. I will try to do better.
example:
I create a GP with a single lvl7 rule blocking, say FB, then apply that GP to a client, it will block FB as intended. However, when I change that client back to normal, or even whitelisted, FB remains blocked.
If I edit the GP and remove the lvl7 rule, FB becomes accessible to the client that is no longer assigned to that GP. It's like there's an "update policy" button I'm missing, but that doesn't seem to be the case.
I am selecting the Group Policy to apply via the drop down in client details.
This is the only Group Policy that has been created.
My test group policy contains nothing but a single level 7 rule.
I am disconnecting from the network after changes are made.
I can reproduce this on other clients, as well as by recreating the Group Policy.
I am on the latest FW version.
I looked through the documentation you folks kindly provided, but am not seeing the issue there.
Any help is much appreciated