Application Control

⌘K

Overview

Application Control lets you govern which software can run on managed endpoints. You define application groups, enforce them through deployment policies, and monitor blocked or flagged activity through the violations log, giving you full visibility and control over what runs on your organization’s devices across Windows, Linux, and macOS.

Why Application Control Matters

Uncontrolled software on endpoints is one of the most common paths for security incidents, licensing violations, and productivity loss. Application Control addresses this by letting you:

  • Block known risky, unauthorized, or non-business software from running.
  • Restrict devices to an approved (allow-listed) set of applications.
  • Enforce rules by product/software name, vendor, executable, file hash, or folder path.
  • Apply enforcement selectively to specific device groups, with exceptions.
  • Track violations in real time and identify which devices and users are triggering them.

Prerequisites

  • A Zecurit account with administrator access
  • The Zecurit agent installed and running on target endpoints
  • At least one device group set up under Groups and Devices
  • Appropriate permissions to view and manage Application Control

Module Structure

Application Control is organized into three tabs:

TabPurpose
Application GroupDefine named collections of software to block or allow, matched by product, vendor, executable, file hash, or folder path
DeploymentEnforce an application group on real devices via a published policy, with a chosen enforcement action and target scope
ViolationsReview real-time logs of every blocked, warned, or audited application event across your fleet

How the Pieces Fit Together

  1. Define: Create one or more application groups under Application Group, specifying what software should be blocked or allowed.
  2. Enforce: Build a deployment policy under Deployment that attaches those groups, chooses an enforcement action, and scopes it to the right devices.
  3. Monitor: Publish the policy and review activity in Violations to confirm it’s working as intended.
  4. Refine: Adjust group rules or target scope based on observed violations, then repeat the cycle.

A Typical Rollout

An IT team introducing a new restriction (for example, blocking an unauthorized remote access tool) would typically:

  1. Go to Application Group and create a Block List group matching the tool by Vendor, tagged with a High risk level.
  2. Go to Deployment and build a new policy that attaches this group, starting with the Audit Only enforcement action so no devices are disrupted yet.
  3. Publish the policy company-wide and check Violations over the next few days to see how often the tool is actually being launched, and by whom.
  4. Once confident the rule is accurate, edit the policy and switch the enforcement action to Block & Notify or Block Execution.
  5. Continue monitoring Violations to confirm enforcement is working and to catch any legitimate use cases that need an exception.

Articles

How can we help?