What Is Application Allowlisting?

Also called: Application whitelisting

Related problems: Ransomware and unknown malware getting past antivirus; Users running unapproved software on company computers; Insurer or framework asking whether we control which programs can run; Fixed-purpose machines such as kiosks or point-of-sale systems that should only run a few programs

Application allowlisting is a security control that allows only approved software, such as specific programs, scripts and libraries, to run on a computer or server, and blocks everything else by default. It reverses the default of detection-based protection: instead of evaluating unknown software and allowing it unless it is detected as malicious, it defines what is approved and denies the rest. Many security frameworks recommend it, and it is especially effective against ransomware and other malware that a signature-based tool hasn’t seen before.

At a glance

  • Allowlisting is a default-deny approach: approved software runs, and unapproved software is blocked.
  • Rules typically identify software by publisher signature, file hash or file location, or a combination.
  • It is commonly built into operating systems and many endpoint security products, or sold as a dedicated tool.
  • The main cost is upkeep: new software and updates need approval, so rollout and change processes matter.
  • It works best alongside other endpoint security, not as a replacement for it.

What problem it solves

Antivirus and other endpoint protection decide whether unknown software is malicious, using signatures, heuristics, reputation and behavior. That works well, but a brand-new or customized piece of malware can still slip through if nothing about it looks malicious enough to detect. Attackers also rely on users being able to run whatever they download or receive. Meanwhile, IT teams struggle with shadow IT: software installed without approval, unpatched and unlicensed.

Allowlisting addresses all three by reducing what can run in the first place. If a ransomware executable isn’t approved, it is blocked from running, whether or not anyone has seen it before. Unapproved tools can’t run, as long as the rules are well maintained, and the organization gains a clearer picture of its software. Blocking installation, quarantining files or removing software already on a machine are separate capabilities that depend on the product. It also supports the principle of least privilege, applied to software rather than user accounts. For fixed-purpose systems such as servers, kiosks, point-of-sale terminals and industrial workstations, which should only ever run a known set of programs, it is a particularly good fit.

How it works

Discovery. The tool first inventories software already running on devices, often in an audit or learning mode that logs activity without blocking anything.

Rules. Administrators create rules for what is allowed. Common rule types are publisher rules, which trust software signed by a specific vendor; hash rules, which trust one exact file; and path rules, which trust files in protected folders. Publisher rules reduce upkeep because updates from the same vendor stay allowed; hash rules are precise but break with each update.

Enforcement. On each device, an agent or operating system feature checks every program, and often scripts and installers, before it runs. Anything not covered by a rule is blocked and logged. Some products can also restrict what approved programs are allowed to do, such as launching other programs or reaching the network.

Change management. Users or IT request approval for new software through a defined process. Many products offer trusted updaters or IT-managed deployment tools whose installs are automatically allowed.

Monitoring. Block events feed into reporting, the endpoint console or a SIEM, where repeated blocks can point to an attack or a missing rule.

When it matters for buyers

  • When ransomware is the top worry. Allowlisting is one of the stronger controls against unknown executables.
  • When protecting servers and fixed-purpose devices. Stable software sets make rules easier to maintain.
  • When a framework or insurer asks. Application control appears in many security frameworks, including the CIS Critical Security Controls, and in some insurance questionnaires.
  • When users have admin rights. If people can install anything, allowlisting adds a control point while you reduce privileges.
  • When reviewing endpoint security. Many endpoint protection platforms (EPP) include application control features, so check before buying a separate tool. See our endpoint protection platforms overview.

Questions to ask vendors

  • Which rule types do you support: publisher, hash, path, or others?
  • Do you control scripts, installers and libraries as well as executables?
  • Is there an audit mode, and how do you help us build the initial rule set?
  • How are software updates handled so they don’t break the rules?
  • What is the process for users to request new software, and how fast can approvals happen?
  • Which operating systems and server platforms are supported?
  • Is this a separate product, or part of an endpoint platform we may already own?

How it differs from endpoint protection platforms

An endpoint protection platform (EPP) is a broader category of software that protects devices, typically with antivirus and anti-malware detection, firewall and device controls, and often application control as one feature. Detection-based protection evaluates software and lets it run unless it is detected as malicious. Allowlisting denies software from running unless it is approved. Many EPPs include both approaches, so allowlisting may be a setting you turn on rather than a new product. Endpoint detection and response (EDR) is different again: it records and investigates behavior on the device, which helps catch attacks that misuse approved programs.

Frequently Asked Questions

What is the difference between allowlisting and blocklisting?
A blocklist names software that is not allowed to run and lets everything else through. Modern antivirus and endpoint protection go further than a simple blocklist, using signatures, heuristics, reputation and behavior analysis, but unknown software is still evaluated and allowed unless it is detected as malicious. An allowlist reverses that default: software that isn't approved is denied, whether or not it looks malicious. Allowlisting can stop malware nobody has seen before, but it needs more upkeep because every legitimate program must be approved.
Is application allowlisting the same as application whitelisting?
Yes. Allowlisting is the newer name for the same control, and many vendors and guidance documents have moved to it. Some older products and documents still say whitelisting.
Will allowlisting break our users' work?
It can if rolled out too fast. Most organizations start in an audit mode that logs what would have been blocked, build rules from that, and then enforce in stages, starting with servers or fixed-purpose machines. A clear, quick process for approving new software matters as much as the rules.
Do we still need EDR if we use allowlisting?
Usually yes. Allowlisting limits what can run, but attackers can still misuse approved tools such as scripting engines or remote admin software, or exploit approved applications. Endpoint detection and response watches behavior and helps catch that.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.