Frequently Asked Questions (FAQ)

About Application Groups

What is application allowlisting?
What is application blocklisting?
What are application groups?
What are the best practices to follow during application control?
When should I choose rules based on vendors for building my allowlist/blocklist?
When should I choose rules based on product names for building my allowlist/blocklist?
When should I choose rules based on executables for building my allowlist/blocklist?
When should I choose rules based on file hash for building my allowlist/blocklist?
When should I choose to manually add files to build my allowlist/blocklist?
How does Application Control Plus differ from the Block Executable feature in the Inventory module of Endpoint Central?
How to check if the Vendor/Product/EXE is verified or not?
What will happen if we add a Vendor to a blocklist and one of their Products to a allowlist?
Is it sufficient to add an application to a allowlist/blocklist by selecting one rule or must all related rules be selected? For eg, to allowlist Chrome is it sufficient to just add Chrome from the Product rule or should chrome.exe also be added?
Is adding only a Vendor rule (For eg. Google) to an application group enough to allowlist/blocklist all installed Products published by them?
When should I opt for the Folder Path rule while building my allowlist/blocklist?

Policy Deployment

What are custom groups?
What is the significance of the flexibility modes available in Application Control?
If the application is present in both a allowlist and a blocklist, will it be allowed or blocked?
I created a allowlist with only 3 applications and deployed it in the strict mode to a target group. Despite this, users of the target group are still able to access other local Windows apps such as Photos, Paint, Windows Store etc. Why does it happen? How can I block these apps?

Unmanaged Applications

What is an unmanaged application?
A few applications that are installed in the endpoint are not shown in the list of Unmanaged Application(s), despite being excluded from all deployed allowlists and blocklists. Why is this?
How can the users access the unmanaged applications when running in strict mode?

Endpoint Privilege Management

What is Endpoint Privilege Management?
When should I enable application level privileged access to users?
What is the significance of the 'Run as ManageEngine' option that is displayed in the File menu of a few applications?
I added an application to the Privileged Application List in the Privilege Management module, however it is not being elevated when run. Why is it so?
How does the elevation of applications using the Endpoint Privilege Management feature work?
Will an application added to the Privileged Application List and associated to a Custom Group during policy deployment execute in the target machines, if they arent allowlisted to them?
What are local admin accounts?
What are built-in administrator accounts?