Application Control prevents any new or unknown applications from running on protected endpoints. When the self-approval feature is enabled and users try to run an unknown or new application on a protected endpoint, they are prompted to approve or deny the application execution.
When a user approves the application execution, the business need or justification, if any, provided by the user for running the application is sent to the ePO - SaaS administrator. The administrator reviews the approval request and can define rules to allow or ban the application for one or all endpoints in the enterprise.
The rules that are applied through policies have precedence over the self-approval feature. For example, if the self-approval feature is enabled and the user tries to run an application that is banned through a policy, the user isn't prompted to take action. Also, you can't self-approve and perform any actions that are prevented by Application Control memory-protection techniques.
The self-approval feature is available for binary or executable files, scripts, installers, and supported files that you run from network shares and removable devices.
Note
Although the self-approval feature is available in Limited Feature Activation mode, use this feature in Full Feature Activation mode (after restarting the endpoints). This feature requires patching of some system libraries and patching might require a restart to work effectively.