What is self-approval?

Prev Next

Application Control prevents any new or unknown applications from running on protected endpoints. When the self-approval feature is enabled and users try to run an unknown or new application on a protected endpoint, they are prompted to approve or deny the application execution.

Important

Self-approval is available only in a ePO - On-prem managed environment.

When a user approves the application execution, the business need or justification, if any, provided by the user for running the application is sent to the ePO - On-prem administrator. The administrator reviews the approval request and can define rules to allow or ban the application for one or all endpoints in the enterprise.

The rules that are applied through policies have precedence over the self-approval feature. For example, if the self-approval feature is enabled and the user tries to run an application that is banned through a policy, the user isn't prompted to take action. Also, you can't self-approve and perform any actions that are prevented by Application Control memory-protection techniques.

The self-approval feature is available for binary or executable files, scripts, installers, ActiveX controls, and supported files that you run from network shares and removable devices. This feature is available on all supported Windows platforms except Windows NT, Windows 2000, and Windows 2003 (IA-64 platform).

Note

Although the self-approval feature is available in Limited Feature Activation mode, use this feature in Full Feature Activation mode (after restarting the endpoints). This feature requires patching of some system libraries and patching might require a restart to work effectively.