Application allowlisting is a security control that allows only approved software, such as specific programs, scripts and libraries, to run on a computer or server, and blocks everything else by default. It reverses the default of detection-based protection: instead of evaluating unknown software and allowing it unless it is detected as malicious, it defines what is approved and denies the rest. Many security frameworks recommend it, and it is especially effective against ransomware and other malware that a signature-based tool hasn’t seen before.
At a glance
- Allowlisting is a default-deny approach: approved software runs, and unapproved software is blocked.
- Rules typically identify software by publisher signature, file hash or file location, or a combination.
- It is commonly built into operating systems and many endpoint security products, or sold as a dedicated tool.
- The main cost is upkeep: new software and updates need approval, so rollout and change processes matter.
- It works best alongside other endpoint security, not as a replacement for it.
What problem it solves
Antivirus and other endpoint protection decide whether unknown software is malicious, using signatures, heuristics, reputation and behavior. That works well, but a brand-new or customized piece of malware can still slip through if nothing about it looks malicious enough to detect. Attackers also rely on users being able to run whatever they download or receive. Meanwhile, IT teams struggle with shadow IT: software installed without approval, unpatched and unlicensed.
Allowlisting addresses all three by reducing what can run in the first place. If a ransomware executable isn’t approved, it is blocked from running, whether or not anyone has seen it before. Unapproved tools can’t run, as long as the rules are well maintained, and the organization gains a clearer picture of its software. Blocking installation, quarantining files or removing software already on a machine are separate capabilities that depend on the product. It also supports the principle of least privilege, applied to software rather than user accounts. For fixed-purpose systems such as servers, kiosks, point-of-sale terminals and industrial workstations, which should only ever run a known set of programs, it is a particularly good fit.
How it works
Discovery. The tool first inventories software already running on devices, often in an audit or learning mode that logs activity without blocking anything.
Rules. Administrators create rules for what is allowed. Common rule types are publisher rules, which trust software signed by a specific vendor; hash rules, which trust one exact file; and path rules, which trust files in protected folders. Publisher rules reduce upkeep because updates from the same vendor stay allowed; hash rules are precise but break with each update.
Enforcement. On each device, an agent or operating system feature checks every program, and often scripts and installers, before it runs. Anything not covered by a rule is blocked and logged. Some products can also restrict what approved programs are allowed to do, such as launching other programs or reaching the network.
Change management. Users or IT request approval for new software through a defined process. Many products offer trusted updaters or IT-managed deployment tools whose installs are automatically allowed.
Monitoring. Block events feed into reporting, the endpoint console or a SIEM, where repeated blocks can point to an attack or a missing rule.
When it matters for buyers
- When ransomware is the top worry. Allowlisting is one of the stronger controls against unknown executables.
- When protecting servers and fixed-purpose devices. Stable software sets make rules easier to maintain.
- When a framework or insurer asks. Application control appears in many security frameworks, including the CIS Critical Security Controls, and in some insurance questionnaires.
- When users have admin rights. If people can install anything, allowlisting adds a control point while you reduce privileges.
- When reviewing endpoint security. Many endpoint protection platforms (EPP) include application control features, so check before buying a separate tool. See our endpoint protection platforms overview.
Questions to ask vendors
- Which rule types do you support: publisher, hash, path, or others?
- Do you control scripts, installers and libraries as well as executables?
- Is there an audit mode, and how do you help us build the initial rule set?
- How are software updates handled so they don’t break the rules?
- What is the process for users to request new software, and how fast can approvals happen?
- Which operating systems and server platforms are supported?
- Is this a separate product, or part of an endpoint platform we may already own?
How it differs from endpoint protection platforms
An endpoint protection platform (EPP) is a broader category of software that protects devices, typically with antivirus and anti-malware detection, firewall and device controls, and often application control as one feature. Detection-based protection evaluates software and lets it run unless it is detected as malicious. Allowlisting denies software from running unless it is approved. Many EPPs include both approaches, so allowlisting may be a setting you turn on rather than a new product. Endpoint detection and response (EDR) is different again: it records and investigates behavior on the device, which helps catch attacks that misuse approved programs.
