Application Control

Application Control manages the startup of applications on users' computers. This allows you to implement a corporate security policy when using applications. Application Control also reduces the risk of computer infection by restricting access to applications.

Configuring Application Control consists of the following steps:

  1. Creating application categories.

    The administrator creates categories of applications that the administrator wants to manage. Categories of applications are intended for all computers in the corporate network, regardless of administration groups. To create a category, you can use the following criteria: KL category (for example, Browsers), file hash, application vendor, and other criteria.

  2. Creating Application Control rules.

    The administrator creates Application Control rules in the policy for the administration group. The rule includes the categories of applications and the startup status of applications from these categories: blocked or allowed.

  3. Selecting the Application Control mode.

    The administrator chooses the mode for working with applications that are not included in any of the rules (application denylist and allowlist).

When a user attempts to start a prohibited application, Kaspersky Endpoint Security will block the application from starting and will display a notification (see the figure below).

A test mode is provided to check the configuration of Application Control. In this mode, Kaspersky Endpoint Security does the following:

Application Control operating modes

The Application Control component operates in two modes:

Application Control can be configured to operate in these modes both by using the Kaspersky Endpoint Security local interface and by using Kaspersky Security Center.

However, Kaspersky Security Center offers tools that are not available in the Kaspersky Endpoint Security local interface, such as the tools that are needed for the following tasks:

This is why it is recommended to use Kaspersky Security Center to configure the operation of the Application Control component.

Application Control operating algorithm

Kaspersky Endpoint Security uses an algorithm to make a decision about starting an application (see the figure below).

Application Control operating algorithm

In this section

Application Control functionality limitations

Receiving information about the applications that are installed on users' computers

Enabling and disabling Application Control

Selecting the Application Control mode

Managing Application Control rules

Testing Application Control rules

Application activity monitor

Rules for creating name masks for files or folders

Editing Application Control message templates

Best practices for implementing a list of allowed applications

Page top