×
×
×
×

Application Control Audit & Reports

Discover what's installed, identify unmanaged software, and audit blocked access attempts — all from one place.

Discovered application reports

These reports summarize every application and executable detected across your managed endpoints.

Discovered Products

All discovered applications across all vendors are listed here. The report can be filtered by OS platform (Windows or macOS) and by whether each application is associated with an application control policy or not.

Discovered Apps Report showing a table of applications with vendor, name, and policy association columns.
Discovered Products — all applications detected in your environment, with policy association status.

Discovered Unverified Executables

Applications consist of multiple executable files, each of which should carry a valid digital signature from its vendor. This report surfaces executables whose digital signature cannot be verified. Any tampered or unsigned executable will be blocked from running — making this report critical for maintaining a trusted execution environment.

Unverified Executables Report showing executables with failed or missing digital signatures.
Discovered Unverified Executables — executables that lack a valid digital signature.

Discovered Store Applications

All Windows 10 and Windows 11 Store applications running on managed endpoints are listed here.

Store Apps Report showing Windows Store applications detected on managed endpoints.
Discovered Store Applications — Windows Store apps running across your environment.

Discovered Child Processes

Child processes are processes launched by a running application. This report captures them so administrators can decide whether to permit or restrict them. Allowing only authorized applications to spawn child processes significantly reduces the risk of process-injection attacks and other exploitation techniques.

Note
Child processes of an application run even when the parent application is blocklisted. Review this report to understand the full execution footprint of your installed software.

Child Process Report listing processes spawned by running applications.
Discovered Child Processes — all child processes initiated by applications on managed endpoints.

Unmanaged application reports

Identify software that exists outside any application control policy so you can decide what to do with it.

Unmanaged Products

All applications that are not governed by any application control policy are listed here. Filterable by OS platform (Windows or macOS), this report is the starting point for eliminating policy gaps.

Unmanaged Apps Report showing applications without any associated policy.
Unmanaged Products — applications present in your environment with no governing policy.

Unmanaged Executables

Individual executables that are not included in any application control policy are listed here. Filterable by OS platform.

Unmanaged Executables Report showing individual EXE files without policy coverage.
Unmanaged Executables — individual executable files outside policy scope.

Unmanaged Store Applications

Windows 10 and Windows 11 Store applications that are not covered by any application control policy are listed here.

Unmanaged Store Apps Report showing Windows Store applications without policy coverage.
Unmanaged Store Applications — Store apps not yet governed by a policy.

Event audit reports

Track enforcement activity — blocked access attempts, elevation requests, and privilege usage — for compliance and investigation.

Blocklisted Application Access

This report logs every attempt to launch an application that is explicitly blocked by policy. Use it for compliance evidence and to monitor whether users are attempting to run prohibited software.

Blocked App Access Report showing a log of attempts to run blocklisted applications.
Blocklisted Application Access — every enforcement event for explicitly blocked applications.

Blocklisted Store Application Access

This report tracks execution attempts for Windows Store applications that have been explicitly blocked. It provides a dedicated view for enforcing store-specific restrictions.

Blocked Store App Access Report showing attempts to run prohibited Windows Store applications.
Blocklisted Store Application Access — enforcement events for blocked Store apps.

Related