Application control prevents execution of unwanted applications in the user profile and temporary folders on workstations.
Application control
Only letting approved programs run on your computers. Everything else is blocked by default.
The case for it
What you lose without application control.
If malware can't run, it can't encrypt your files, steal your passwords, or open a back door. Application control is the single most effective technical control in the Essential Eight. It is also the one most businesses skip, because the rollout takes planning. Done properly, it stops a whole class of attack before it starts.
Where you need to be
What each maturity level asks of application control.
The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.
Application control is applied to all user profile folders and to all locations on servers. Microsoft's recommended application blocklist is implemented.
Application control rulesets are validated annually or more frequently. Blocklists of drivers with known vulnerabilities are implemented.
Not sure which level you should aim for?
Three questions about your regulatory position and the data you keep will point you at the right target.
Take the maturity pickerThe rollout
Setting up application control in your environment.
You get a phased rollout through Microsoft Intune and Windows Defender Application Control. Audit mode goes first, for 7 to 14 days, so we learn what your staff actually use. Enforcement then goes out in batches, with scripts and macros last. Exceptions go through a ticket, never a local override. We review the ruleset quarterly and validate it annually as you move towards maturity level 3.
Free self-assessment
No email required.
Score yourself on all eight controls.
Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.
Take the self-assessmentAsked on client calls
Questions we get about application control.
- Won't this break our staff's workflows?
- It would if we enforced on day one. The rollout starts in audit mode, where the agent reports what is being run without blocking any of it. That is where we find the quiet legitimate software nobody thought to mention. The accountant's macro-heavy spreadsheet, the office manager's ancient utility, a developer's own tooling. Those get allowlisted first, and enforcement follows. Disruption is close to zero when the rollout is sequenced properly.
- What about shadow IT? Staff installing things themselves?
- Application control is what stops it, and that is the point. If someone installs an unapproved tool, it will not run. They call the helpdesk, and we either allowlist the tool or point them at an approved equivalent. The conversation with staff still has to happen, but the block is already in place.
- Is this the same as antivirus?
- No. Antivirus works from a blocklist, so it has to know about the bad thing first. Application control works from an allowlist, so only approved software runs. That difference matters because attackers change their malware faster than antivirus can keep up. An allowlist does not care what the new file is called. If it is not approved, it does not run.
- How long does a proper rollout take?
- Six to ten weeks for a typical 50-seat business. The first fortnight is audit mode, gathering data. Tuning the ruleset and getting exceptions signed off takes another two weeks. Enforcement then goes out department by department over the weeks that follow. Rushed rollouts are the ones that disrupt a business. Sequenced ones do not.
Where to go next
Essential Eight controls that work with application control.
Control 02
Patch applications
Keeping your software up to date so it has the latest security fixes.
Read the controlControl 04
User application hardening
Turning off features in web browsers and Office that attackers commonly abuse.
Read the controlControl 05
Restrict administrative privileges
Making sure only the people who need admin rights have them, and only when they need them.
Read the controlThe maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .
The qualifier
Let's see if we're a fit.
Seven questions, one moment of your time. We'd rather tell you now than three months in.