December 12, 2023
During execution of the Application Control task, Kaspersky Endpoint Security controls the launching of applications on user devices. This helps reduce the risk of device infection by restricting access to applications. Application launching is regulated by Application Control rules.
To use the component, a license that includes the corresponding function is required.
This feature is not supported in the KESL container.
Application Control can operate in two modes:
- Denylist. In this mode Kaspersky Endpoint Security allows all users to launch any applications that are not specified in the Application Control rules. This is the default operation mode of the Application Control component.
- Allowlist. In this mode Kaspersky Endpoint Security prevents all users from launching any applications that are not specified in the Application Control rules.
For each Application Control operation mode, separate rules can be created and an action can be specified: apply rules or test rules. Kaspersky Endpoint Security performs this action when it detects an attempt to start an application.
The Application Control settings are described in the following table.
Application Control settings
Enable Application Control
The check box enables the Application Control component.
This check box is cleared by default.
Action on application startup attempt
The action that Kaspersky Endpoint Security performs upon detecting an attempt to start an application that matches the configured rules:
Application Control mode
Application Control task operation mode:
Application Control rules
This group of settings contains the Configure button. Clicking this button opens the Application Control rules window.