×
×
×
×

Application Control

Govern which applications run across your endpoints, manage permissions, and minimize your attack surface from a single console.

Introduction

Application Control lets you decide exactly which software is permitted to run — and which is not.

Monitoring application usage and permissions across the network is one of the most critical steps toward complete endpoint security. Unmonitored software has been linked to 16% of data breaches in 2023, making centralized control essential.

Endpoint Central gives administrators centralized allowlisting, blocklisting, and privilege management — helping organizations strengthen security, meet compliance requirements, and shrink the attack surface.

Getting Started with Application Control

Deployment starts with discovering every application on your endpoints, then grouping and governing them.

Discovery and categorization

After agent installation, Endpoint Central performs an agent-based scan to discover and categorize all applications installed across your endpoints. The results surface in the web console and form the foundation of your control policies.

Application groups

Administrators organize discovered applications into application groups — either allowlists (to permit execution) or blocklists (to restrict it). Groups can be built using a range of filters:

  • Trusted Vendors — permit or deny all executables from a given publisher.
  • Product Name — target specific products from any vendor.
  • Verified Executable — match by digitally signed executable file.
  • File Hash — the most granular rule; any change to the file breaks the match.
  • Folder Path — govern all executables under a specified directory.
  • Store Apps — cover Windows Store applications explicitly.

These groups are then associated with custom device groups and deployed under a chosen policy mode.

Policy modes

Choose how strictly policies are enforced based on your organization's readiness.

Audit Mode vs. Strict Mode

Policies operate in one of two modes. Audit Mode lets all allowlisted and unmanaged applications run while collecting events — ideal for building out your allowlist before enforcing restrictions. Strict Mode enforces zero-trust: only allowlisted applications can execute, and any unmanaged application is blocked immediately.

Key features

A summary of what Application Control Plus provides out of the box.

Allowlisting and blocklisting

Build application groups using advanced filters, enforce child process controls, and choose between Audit and Strict modes to match your security posture. Learn more.

Unmanaged application handling

Detect applications that fall outside your defined groups. Monitor them for assessment or block them outright to prevent unauthorized execution. Learn more.

Just-in-time access

Users can request temporary, time-bound access to unmanaged applications when business needs arise. Every request is tracked for a full audit trail. Learn more.

Blocked application reports

Generate detailed reports on access attempts, blocked applications, and actions taken — giving you complete visibility for compliance and investigation. Learn more.

Privilege management

Control elevated privileges and administrative access to reduce the risk of unauthorized system modifications. Learn more.

Related