Unapproved software and unauthorised processes can create a difficult balance: IT teams need to restrict execution without losing sight of what has been allowed, blocked or observed. Exceptions also need to be handled in a way that reflects individual users or group requirements.
Heimdal Application Control applies AppFencing rules to allow or block applications by path, MD5 hash or certificate validation. It restricts unauthorised interactions, supports approval and denial flows, and records execution activity for later review.
Application Control is suited to defining which software is permitted to execute under zero-trust policies and to blocking software that does not meet those rules. It also supports approval decisions for individual users and Active Directory groups, and provides execution records for reviewing allowed, blocked and passive-mode activity.
Centralised application and network policies can be applied across organisation or multi-tenant environments.
Heimdal Application Control is applicable to organisation and multi-tenant environments through the Heimdal agent and unified platform. Its approval flows can be applied to individual users or Active Directory groups.
Limits application execution to software that meets defined rules.
Keeps records of allowed, blocked and monitored executions for review.
Supports approval and denial decisions for users or Active Directory groups.
Centralises application and network policy application across the estate.
Define rules for software that is allowed to run in the environment.
Block applications that do not meet path, hash or certificate rules.
Apply custom approval and denial flows for Active Directory groups.
Review detailed reports and 90-day logs of application execution activity.
Armstrong discusses application execution requirements with customer IT teams, including the rules, approval needs and estate context that matter to them. These discussions help Armstrong recommend whether Heimdal Application Control is a suitable fit for controlling approved and unapproved software execution.