Application Control Plus

Controls which applications run and how users gain elevated access on endpoints.

For endpoint environments that need application execution policies and limited privilege elevation.

Control endpoint application execution and privilege elevation

Endpoint policies can be difficult to introduce when IT teams do not have a clear view of the applications in use or the effect that a rule will have. Excessive local administrative access also gives users broader privileges than a particular task requires.

Application Control Plus identifies applications across endpoints and provides audit mode to review execution and policy impact before rules are enforced. It applies allowlist and blocklist policies for application execution, while enabling approved applications or tasks to be elevated without disclosing administrator passwords.

Where Application Control Plus is used

Application Control Plus is suited to controlling approved and unapproved software across endpoints, including reviewing unmanaged executions and application block attempts. It also supports task-specific elevation where standard users need access to selected administrative tools or Control Panel applets without receiving full administrator rights.

Fits within these solutions

Application Control
Privileged Access Management
Ransomware Protection
Endpoint Protection

Delivery & deployment

On-Premises Software
SaaS / Cloud

Suitable environments

The product applies to endpoint environments where IT teams need to discover running applications, assess policy impact and enforce application execution or privilege policies.

Benefits

Restricted Software Execution

Limits application execution to software approved under policy.

Safer Policy Rollout

Audit mode shows policy impact before execution rules are enforced.

Limited Admin Access

Users can elevate a defined task without receiving full administrator rights.

Recorded Control Activity

Activity trails and reports provide records of application and elevation controls.

Capabilities

Application Allowlist Rules

Creates rules that allow trusted applications to run on endpoints.

Application Blocklist Rules

Creates rules that block unapproved or risky applications according to policy.

Application Discovery

Identifies applications running across endpoints.

Policy Audit Mode

Audits application execution and policy impact before enforcement.

Task-Specific Elevation

Elevates approved applications or tasks without sharing administrator passwords.

Control Activity Records

Records activity trails and reports for application and elevation controls.

Common Use Cases

Review Running Applications

Identify applications in use across endpoints before defining execution rules.

Test Execution Policies

Audit proposed application policies before applying them to endpoint execution.

Block Unapproved Software

Apply policy to block applications that are not approved for endpoint use.

Elevate Administrative Tools

Allow standard users to use selected built-in administrative tools without full admin rights.

Part of (depending on licence)

Resources

Screenshots

How would you like to proceed?