Unmanaged Applications: Request Access
Let users request access to blocked applications in Strict Mode — keeping security intact while avoiding unnecessary productivity loss.
How Request Access works
Request Access is a controlled bridge between a blocked application and a user who has a legitimate need for it.
The purpose of Request Access
When an application control policy runs in Strict Mode, unmanaged applications are blocked by default. Request Access gives users a way to surface legitimate needs without bypassing security — they submit a request with a justification, an administrator reviews it, and the response determines what happens to the application.
Administrators receive email notifications for incoming requests and can act on them directly from the dashboard. This reduces friction for users with genuine needs while keeping the administrator in control of what gets approved.
Submitting an access request
When a blocked application is launched in Strict Mode, users are prompted to request access on the spot.
The request prompt
When a user attempts to launch an unmanaged application in Strict Mode, they see a notification explaining that the application is blocked. From this notification, the user can submit a request by providing a written reason for needing access.


Reviewing and responding to requests
Administrators access incoming requests from the dashboard and choose a disposition for each application.
Request response options
Once a request arrives, the administrator reviews the user's justification and selects one of the following actions:
- Add to Allowlist — grants access and moves the application into the allowlisted group.
- Add to Blocklist — explicitly denies access and moves the application into the blocklisted group.
- Reject — declines the request without any policy change; the application remains unmanaged.
- Move to Existing App Group — places the application into an already-defined application group.

Configuring email alerts for requests
Set up email notifications so administrators are alerted immediately when a new request comes in.
Email notification setup
Incoming access requests are sent by email to the configured address. To set this up:
- Navigate to Alert Settings under Settings.
- Enter the desired email address(es) in the Alert for Requested Apps field.
- Click Save.
