{"id":3310,"date":"2026-08-12T06:10:56","date_gmt":"2026-08-12T06:10:56","guid":{"rendered":"https:\/\/zecurit.com\/help\/?post_type=docs&#038;p=3310"},"modified":"2026-08-12T06:10:57","modified_gmt":"2026-08-12T06:10:57","slug":"creating-an-application-group-in-zecurit","status":"publish","type":"docs","link":"https:\/\/zecurit.com\/help\/endpoint-management\/application-control\/creating-an-application-group-in-zecurit\/","title":{"rendered":"Creating an Application Group in Zecurit"},"content":{"rendered":"\n<p>An <strong>Application Group<\/strong> is a collection of applications that you want Application Control to manage. You can create a group using the <strong>product name, vendor, executable file, file hash, or folder path<\/strong>. After creating the group, assign it to a <strong>Deployment Policy<\/strong> to allow or block the selected applications.At least one <strong>Application Group must exist before you can create a Deployment Policy.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is an Application Group?<\/h2>\n\n\n\n<p>An <strong>Application Group<\/strong> defines the applications that Application Control identifies on a device. The action taken for those applications, such as <strong>Block or Allow<\/strong>, is configured in the <strong>Deployment Policy<\/strong>. The same Application Group can be used with different policies for different devices based on the required action.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Create Application Group<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"500\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Add-Application--1024x500.png\" alt=\"\" class=\"wp-image-3352\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Add-Application--1024x500.png 1024w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Add-Application--300x147.png 300w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Add-Application--768x375.png 768w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Add-Application--1536x751.png 1536w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Add-Application--2048x1001.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log in to the <strong>Zecurit portal<\/strong>. <\/li>\n\n\n\n<li>Go to <strong>Endpoint Manager \u2192 Application Control<\/strong>. <\/li>\n\n\n\n<li>On the <strong>Application Control<\/strong> page, select the <strong>Application Group<\/strong> tab.<\/li>\n\n\n\n<li>Click <strong>Create Application Group<\/strong><\/li>\n\n\n\n<li>Select the required <strong>Platform<\/strong>, such as <strong>Windows, Linux, or macOS<\/strong>. <\/li>\n\n\n\n<li>Click <strong>+ Add Application Group<\/strong> to open the application group configuration. <\/li>\n\n\n\n<li>Enter the required group details and configure the application rules.<\/li>\n\n\n\n<li>Click <strong>Add App List<\/strong> to save the application group.<\/li>\n<\/ol>\n\n\n\n<p>Saved groups become available for selection when building a Deployment Policy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Configuring Group Details<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Field<\/strong><\/th><th><strong>Required<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Application Group Name<\/td><td>Yes<\/td><td>A descriptive, unique name (e.g., &#8220;Prohibited app &#8211; US Branch&#8221;). Use naming conventions that indicate scope or purpose, since this name appears later in policy and violation records.<\/td><\/tr><tr><td>Access Type<\/td><td>Yes<\/td><td>Determines whether listed applications are blocked or the only ones permitted.<\/td><\/tr><tr><td>Risk Level<\/td><td>No<\/td><td>Classifies the group&#8217;s severity for reporting and prioritization.<\/td><\/tr><tr><td>Associate Rule<\/td><td>Yes<\/td><td>The actual application matching rules that define group membership.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Access Type: Block List vs. Allow List<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Access Type<\/strong><\/th><th><strong>Behavior<\/strong><\/th><th><strong>Typical Use Case<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Block List<\/td><td>Applications matching the group&#8217;s rules are denied; everything else is permitted<\/td><td>Blocking known risky, unlicensed, or non-business software (e.g., torrent clients, unauthorized browsers)<\/td><\/tr><tr><td>Allow List<\/td><td>Only applications matching the group&#8217;s rules are permitted; everything else is denied<\/td><td>Locking down highly regulated or kiosk-style devices to a fixed software set<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Block List is selected by default and suits most general-purpose enforcement. Allow List is more restrictive and is typically reserved for high-security environments, since any application not explicitly listed will be prevented from running.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Risk Level<\/h2>\n\n\n\n<p>Risk Level is a classification tag (Low, Medium, High) rather than an enforcement setting. It doesn&#8217;t change how the group is enforced, but it does:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Appear in reports and dashboards to help prioritize review.<\/li>\n\n\n\n<li>Help other admins quickly gauge the sensitivity of a group without opening its rule list.<\/li>\n\n\n\n<li>Support filtering when auditing large numbers of application groups over time.<\/li>\n<\/ul>\n\n\n\n<p>As a general guideline:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Risk Level<\/strong><\/th><th><strong>Example Scenarios<\/strong><\/th><\/tr><\/thead><tbody><tr><td>High<\/td><td>Malware-adjacent tools, unauthorized remote access software, unlicensed P2P\/torrent clients<\/td><\/tr><tr><td>Medium<\/td><td>Consumer cloud storage apps, unsanctioned browsers, unmanaged VPN clients<\/td><\/tr><tr><td>Low<\/td><td>Legacy internal tools being phased out, low-impact utilities under review<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Associating Rules<\/h2>\n\n\n\n<p>Rules define exactly which applications belong to the group. You can build rules three ways:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>+ Add New<\/strong>: manually create a rule using one of the match types below.<\/li>\n\n\n\n<li><strong>Select from existing<\/strong>: reuse a rule already defined elsewhere in your organization, keeping definitions consistent across groups.<\/li>\n\n\n\n<li><strong>Import CSV<\/strong>: bulk upload a list of applications, useful when migrating an existing block\/allow list from another tool or spreadsheet.<\/li>\n<\/ul>\n\n\n\n<p>If no rules have been added yet, the group will show &#8220;No rules added yet&#8221; until at least one is created. A group with no rules has nothing to enforce.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Match Types Explained<\/h2>\n\n\n\n<p>Rules can identify applications using any of five match types, available as tabs when adding a rule:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Match Type<\/strong><\/th><th><strong>Matches On<\/strong><\/th><th><strong>When to Use<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Product\/Software<\/td><td>The application or product name<\/td><td>Broadest match; blocks\/allows an app regardless of publisher-signed executable name or install location<\/td><\/tr><tr><td>Vendors<\/td><td>The software publisher<\/td><td>Useful for blocking or allowing everything from a specific vendor at once<\/td><\/tr><tr><td>Executable<\/td><td>The executable file name (e.g., chrome.exe)<\/td><td>More precise than product name; useful when the product name is inconsistent across versions<\/td><\/tr><tr><td>File Hash<\/td><td>A specific file&#8217;s cryptographic hash<\/td><td>Most precise; targets an exact file\/version, ignoring renamed copies with different hashes<\/td><\/tr><tr><td>Folder Path<\/td><td>The install or execution directory<\/td><td>Useful for blocking anything launched from a specific location, such as a USB drive or temp folder<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Tip:<\/strong> Combine match types within a single group when needed. For example, match by Vendor to catch most releases, plus File Hash entries for specific flagged builds.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Example Application Groups<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Group Name<\/strong><\/th><th><strong>Access Type<\/strong><\/th><th><strong>Risk Level<\/strong><\/th><th><strong>Match Type Used<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Prohibited app &#8211; US Branch<\/td><td>Block List<\/td><td>High<\/td><td>Product\/Software<\/td><\/tr><tr><td>Approved Browsers &#8211; Kiosk Devices<\/td><td>Allow List<\/td><td>Low<\/td><td>Executable<\/td><\/tr><tr><td>Unauthorized Remote Access Tools<\/td><td>Block List<\/td><td>High<\/td><td>Vendors<\/td><\/tr><tr><td>Flagged Build &#8211; CVE Review<\/td><td>Block List<\/td><td>Medium<\/td><td>File Hash<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Best Practices<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Keep group names specific and self-explanatory, since they surface later in the Violations log.<\/li>\n\n\n\n<li>Start new block rules with Notify Only enforcement (configured at the policy level) before switching to Block Execution, to avoid disrupting legitimate workflows.<\/li>\n\n\n\n<li>Use File Hash matching for time-sensitive security responses (e.g., a newly identified malicious binary) rather than waiting to identify a stable product name.<\/li>\n\n\n\n<li>Periodically review Risk Level tags to ensure they still reflect current threat priorities.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting Tips<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Issue<\/strong><\/th><th><strong>Resolution<\/strong><\/th><\/tr><\/thead><tbody><tr><td>&#8220;No rules added yet&#8221; won&#8217;t clear<\/td><td>Add at least one rule via + Add New, Select from existing, or Import CSV before saving<\/td><\/tr><tr><td>CSV import fails<\/td><td>Confirm the file matches the expected column format; check for missing required fields or malformed entries<\/td><\/tr><tr><td>Group not appearing in Deployment Policy selector<\/td><td>Confirm the group was saved successfully with Add App List, not left in an unsaved draft state<\/td><\/tr><tr><td>Wrong applications being matched<\/td><td>Review the match type used; Product\/Software matches are broader than Executable or File Hash<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><\/h2>\n\n\n\n<p><\/p>\n","protected":false},"featured_media":0,"parent":3309,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_is_vendor_doc":"0","footnotes":""},"doc_tag":[],"class_list":["post-3310","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/comments?post=3310"}],"version-history":[{"count":6,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3310\/revisions"}],"predecessor-version":[{"id":3353,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3310\/revisions\/3353"}],"up":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3309"}],"next":[{"title":"Creating a Deployment Policy in Application Control","link":"https:\/\/zecurit.com\/help\/endpoint-management\/application-control\/deploying-the-policy\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3319"}],"wp:attachment":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/media?parent=3310"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/doc_tag?post=3310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}