Manage the inventory

Prev Next

Application Control sorts your inventory items based on reputation received from the configured reputation source.

To review and manage inventory items for all systems in your setup, you must be a ePO - On-prem administrator. If you are a non-global administrator, you can only review and manage inventory items for systems for which you have the required permissions. If you need permissions to manage enterprise-wide inventory items, contact the ePO - On-prem administrator.

  1. Define how to manage the inventory:

    • For all managed endpoints, navigate to Menu Application Control InventoryBy Applications.

    • For a selected endpoint, navigate to Menu Application Control InventoryBy Systems and click View for the relevant endpoint.

  2. Prevent malicious executable files or script files from running.

    1. Select the files to block.

    2. Select ActionsBan Files to open the Allow or Ban Files wizard.

    3. Specify the rule group for the rules.

      • To add the rules to an existing rule group, select Add to Existing Rule Group, select the rule group from the list, and specify the operating system.

      • To create a rule group with the rules, select Create a New Rule Group, enter the rule group name, and specify the operating system.

      Note

      You can define rules to allow or ban a file based on both SHA-1 and SHA-256 values of the file.

    4. Click Next.

    5. Review the rules, then click Save.

  3. Allow trusted executable files or script files to run.

    1. Select the files to allow.

    2. Select ActionsAllow Files to open the Allow or Ban Files wizard.

    3. Perform one of these actions.

      • To allow the file only on the selected endpoint, add the file to the allow list of the endpoint by selecting Add Files to Allow list.

      • To allow the file on multiple endpoints, and to add the rules to a rule group, Select Add to Existing Rule Group or Create a New Rule Group.

    4. Click Next.

    5. Review the rules, then click Save.

  4. Recategorize an unknown executable file or script file as a trusted file by editing the reputation by Application Control for the file.

    1. Select the files.

    2. Select Actions Set Reputation by Application Control to open Set Reputation by Application Control.

    3. Select the reputation value.

  5. Add the updated rule group to the policies applied to the endpoints.