Application Control is NetLock RMM's proprietary allowlisting engine for Windows โ built in-house, no third-party module. Define rulesets that describe exactly which executables may launch โ everything you did not explicitly allow is blocked.
Try DemoApplication Control is fully developed by the NetLock RMM team โ not licensed, not white-labeled, not glued together from third-party SDKs.
Embedded directly into the NetLock RMM agent โ no extra service, no extra process, no orphaned helper running on your endpoints.
No vendor lock-in, no licensing cascade, no opaque engine. Every line of the detection logic is ours and is shipped under our roadmap.
Designed from day one for multi-tenant fleets โ push rulesets to thousands of endpoints, manage exemptions per tenant, audit verdicts centrally.
Application Control turns a default-deny posture into a few clear configuration steps.
Create a ruleset and add rules describing the executables you trust โ by path, hash, or signing certificate.
Attach the ruleset under Policy Settings, so every device the policy targets enforces the same allowlist.
Any executable not matched by a rule is blocked from running and the attempt is logged for review.
Rules match on file, version, and certificate attributes โ and conditions are combined so a rule is as tight as you need it.
Match on the executable's path and its version-info strings such as file company, product, copyright, and version.
Match the exact binary by cryptographic hash โ the strongest, most tamper-resistant form of rule.
Allow software from a trusted publisher by matching the signing certificate's owner and issuer.
Constrain a rule to certificates valid within a specific date range.
Match the certificate's public key, serial number, and SHA1 thumbprint for signer-level precision.
Stack multiple attributes on one rule โ every condition must match before an executable is allowed.
Every blocked launch lands on the Blocked Applications tab, ready to be reviewed and approved.
Blocked launch attempts are captured with the executable details so nothing slips by unnoticed.
Approve a blocked entry and the server promotes it to an allow rule โ deduplicated by SHA512 hash.
Each blocked entry carries a status so your team always knows what still needs a decision.
Application Control rulesets enforce nothing until attached under Policy Settings โ Windows โ Application Control. Authoring and enforcement stay cleanly separated, so you can build and test a ruleset before any device feels it.
Default-deny application control, without the management overhead.
View Pricing