Key features

Prev Next

Application Control protects your organization against malware attacks before they occur by proactively controlling the applications that run on your devices. Change Control blocks change activities in server environments to prevent security breaches and data loss, and lowers the impact of outages.

Dynamic allow listing

You can manage your allow list in a secure and dynamic way. IT administrators don't need to manually maintain lists of approved applications. Application Control groups executables (binaries, libraries, and drivers) across your company.

Protection against threats

Application Control extends coverage to executable files, libraries, drivers, Java applications, and scripts for greater control over application components. It enforces control on connected or disconnected servers, virtual machines, endpoints, and fixed devices, such as kiosks and point-of-sale (POS) terminals. It also locks down protected endpoints against threats and unwanted changes, with no file system scanning or other periodic activity that might impact system performance.

Knowledge acquisition

You can switch to Observe mode to discover policies for dynamic desktop environments without enforcing a allow list lockdown. This mode helps you deploy the software in pre-production environments without affecting the operation of existing applications.

Note

This feature is available only in a ePO - On-prem managed environment.

Reputation-based execution

Application Control integrates with a reputation source to receive reputation information for files. Based on the reputation received, Application Control allows or bans the execution and software installation.

Centralized management

Application Control integrates with ePO - On-prem software for consolidated and centralized management, and a global view of enterprise security from a single console.

Note

This feature is available only in a ePO - On-prem managed environment.

Write protection

Use write protection rules to prevent users from creating and changing files and directories. Write-protecting a file makes it read-only.

Read protection

Read protection rules prevent users from reading the content of specified files, directories, and volumes. If a directory or volume is read-protected, all files in that directory or volume are also read-protected. Subdirectories inherit read protection rules.

Real-time monitoring

Change Control monitors file changes in real time, eliminating need for multiple scans on endpoints to identify change violations.

Content change tracking

Change Control tracks content and attribute changes for files and includes special alerting mechanisms to instantly notify you of critical changes.