×
×
×
×

Unmanaged Applications: Request Access

Let users request access to blocked applications in Strict Mode — keeping security intact while avoiding unnecessary productivity loss.

Prerequisite
Request Access is only available when the associated application group is deployed in Strict Mode with the request access option enabled.

How Request Access works

Request Access is a controlled bridge between a blocked application and a user who has a legitimate need for it.

The purpose of Request Access

When an application control policy runs in Strict Mode, unmanaged applications are blocked by default. Request Access gives users a way to surface legitimate needs without bypassing security — they submit a request with a justification, an administrator reviews it, and the response determines what happens to the application.

Administrators receive email notifications for incoming requests and can act on them directly from the dashboard. This reduces friction for users with genuine needs while keeping the administrator in control of what gets approved.

Note
When a request is approved, access is granted to all computers in the specified custom group — not just the machine from which the request was made.

Submitting an access request

When a blocked application is launched in Strict Mode, users are prompted to request access on the spot.

The request prompt

When a user attempts to launch an unmanaged application in Strict Mode, they see a notification explaining that the application is blocked. From this notification, the user can submit a request by providing a written reason for needing access.

Application request prompt shown to the user when they attempt to launch a blocked application in Strict Mode.
The request prompt — users provide a reason when attempting to launch a blocked application.

Request access alert displayed to the user in Strict Mode with a text field for entering a justification.
Request access alert — the user enters a justification before the request is submitted to the administrator.

Reviewing and responding to requests

Administrators access incoming requests from the dashboard and choose a disposition for each application.

Request response options

Once a request arrives, the administrator reviews the user's justification and selects one of the following actions:

  • Add to Allowlist — grants access and moves the application into the allowlisted group.
  • Add to Blocklist — explicitly denies access and moves the application into the blocklisted group.
  • Reject — declines the request without any policy change; the application remains unmanaged.
  • Move to Existing App Group — places the application into an already-defined application group.

Administrator view of an application access request showing the request details and response action options.
The admin request view — review the user's justification and choose a disposition for the application.

Configuring email alerts for requests

Set up email notifications so administrators are alerted immediately when a new request comes in.

Email notification setup

Incoming access requests are sent by email to the configured address. To set this up:

  1. Navigate to Alert Settings under Settings.
  2. Enter the desired email address(es) in the Alert for Requested Apps field.
  3. Click Save.

Alert Settings screen showing the Alert for Requested Apps email field.
Alert Settings — configure the email address that receives notifications for incoming application access requests.

Related