Does a user need to log off and log on again so new security rules become active?
No, logging off is not required for security changes to take place. Changes made to the client from the Endpoint Protector Administrative and Reporting Tool take place in a matter of seconds (depending on the set refresh interval) and do not require user interaction. For new security settings / policies etc to be applied to protected client PCs a network connection between client and server is required.