All insights

What is application control, and will it stop staff working?

6 min readBy Brendon Whiting, Founder · 22 January 2026

Application control means only approved software is permitted to run on your computers; anything else is blocked by default. It is the Essential Eight's first and most effective control, and also the most disruptive if it is switched on carelessly. Deployed properly, in learning mode first with a real exceptions process, most staff never notice it exists.

The idea is worth understanding because it inverts how most people imagine security works. Traditional antivirus keeps a list of things known to be bad and tries to stop them, which means it is permanently one step behind whatever was written last week. Application control keeps a list of things known to be good and refuses everything else. The difference matters enormously against new threats: malware that has never been seen before is unrecognised, and unrecognised software does not run. That is why the Australian Signals Directorate ranks it first among the eight, and why it is also the one businesses most often skip.

They skip it because the failure stories are memorable. Flip enforcement on across a business on a Monday morning without preparation and you will block the accounting package's update, the plugin someone in reception depends on, and the little utility the workshop has used for a decade. Work stops, the phones light up, and by Wednesday somebody has switched it off, which leaves you with the cost and none of the protection. That outcome is entirely avoidable and it is a process failure rather than a technology one.

A competent deployment runs in stages. It begins in learning mode, sometimes called audit or monitor mode, where the tool watches what actually runs across your fleet without blocking anything, typically for a few weeks. That inventory is genuinely revealing in its own right: most businesses discover software they did not know they had, licences nobody is tracking, and the occasional program that has no business being on a work machine. Then you build the approved list from what the business legitimately uses, pilot enforcement on a small tolerant group, and only afterwards extend it, usually department by department rather than all at once.

The exceptions process is the part that decides whether this succeeds, and it is organisational rather than technical. Someone will need something blocked, on a deadline, and the question is how quickly they can get a decision. If the answer is minutes, application control becomes background furniture. If the answer is next Tuesday, people find workarounds, ask a colleague to email them the file, or use a personal laptop, and you have made the business less secure while paying for the opposite. Name who can approve, agree a target response time, and tell staff how to ask before enforcement starts.

For the Essential Eight, the maturity levels ask for progressively more. At Maturity Level 1 the expectation is control over what can execute in the locations users can write to, which is where most malware lands. Higher levels extend the scope and add stricter validation of what is permitted. The framework also expects Microsoft's recommended application blocklist to be applied, which closes a specific gap: legitimate Microsoft-signed tools that attackers use precisely because they are trusted. That is the kind of detail that separates a real implementation from a checkbox.

Tooling-wise, we use ThreatLocker for this in client environments, and the platform matters less than the deployment discipline. What you should look for is a genuine learning mode, a fast approval workflow, sensible handling of software updates so that every routine version change does not become a support ticket, and reporting you can hand to an assessor. That last point is worth stressing: application control generates the evidence that proves the control exists, and evidence is what an insurer or a tender panel actually asks for.

The honest caveats. It is real work to set up and it does not end, because software changes and the approved list has to keep pace, which is part of why it is bought as a managed service more often than run in-house. It will not stop everything, since attacks that abuse a legitimate approved application still run. And it needs the other controls around it, because a business with perfect application control and no multi-factor authentication has bolted the front door and left a window open.

If you want it deployed in the order that does not cause a revolt, learning mode first, pilot second, exceptions process agreed before enforcement, that is how we do it: 1800 456 567. And if you would rather start by finding out where your current setup sits against all eight controls, the Cyber Security Scorecard is free.

Deploy it without the revolt

We run application control in learning mode first, pilot it on a friendly group, and agree an exceptions process before anything is enforced.

Frequently asked questions

They request it and someone approves or declines, usually within minutes for a known application. That exceptions process is the single thing that determines whether application control succeeds, because a block with no fast route to yes teaches people to work around the system. Agree the process, and who can approve, before enforcement begins rather than after the first complaint.

No, and they work from opposite directions. Antivirus tries to recognise things that are bad, which means it is always chasing what is new. Application control permits only what you have approved, so anything unrecognised simply does not run, including malware nobody has catalogued yet. They complement each other and neither replaces the other.

The concept applies everywhere, the tooling differs. Windows has the most mature options, macOS is well covered by the major products, and mobile platforms handle it through device management policies restricting what can be installed. A mixed fleet needs a plan per platform, which is a scoping question worth asking before anyone signs anything.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.