Skip to content

Application control

Only letting approved programs run on your computers. Everything else is blocked by default.

The case for it

What you lose without application control.

If malware can't run, it can't encrypt your files, steal your passwords, or open a back door. Application control is the single most effective technical control in the Essential Eight. It is also the one most businesses skip, because the rollout takes planning. Done properly, it stops a whole class of attack before it starts.

Where you need to be

What each maturity level asks of application control.

The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.

ML1 The 2026 baseline

Application control prevents execution of unwanted applications in the user profile and temporary folders on workstations.

ML2 Regulated or audited

Application control is applied to all user profile folders and to all locations on servers. Microsoft's recommended application blocklist is implemented.

ML3 Defence or sensitive

Application control rulesets are validated annually or more frequently. Blocklists of drivers with known vulnerabilities are implemented.

Not sure which level you should aim for?

Three questions about your regulatory position and the data you keep will point you at the right target.

Take the maturity picker

The rollout

Setting up application control in your environment.

You get a phased rollout through Microsoft Intune and Windows Defender Application Control. Audit mode goes first, for 7 to 14 days, so we learn what your staff actually use. Enforcement then goes out in batches, with scripts and macros last. Exceptions go through a ticket, never a local override. We review the ruleset quarterly and validate it annually as you move towards maturity level 3.

Free self-assessment

No email required.

Score yourself on all eight controls.

Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.

Take the self-assessment

Asked on client calls

Questions we get about application control.

Won't this break our staff's workflows?
What about shadow IT? Staff installing things themselves?
Is this the same as antivirus?
How long does a proper rollout take?

The maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit