What is Microsoft's recommended application blocklist?
It is a list Microsoft publishes of its own signed applications that attackers commonly abuse, and that most businesses have no reason to run. Blocking them closes a specific gap: application control permits trusted software, and these are trusted, so without the blocklist they sail straight through.
The technique this defends against has a name in security circles, living off the land, and the logic is simple. Rather than bringing in malware that antivirus might recognise, an attacker uses tools already present and already trusted on a Windows machine. Legitimate diagnostic utilities, scripting hosts and developer components can download files, execute code and move around a network, and they do it wearing a valid Microsoft signature. Nothing looks wrong because, from the system's point of view, nothing is wrong.
That is why the Essential Eight expects the blocklist alongside application control rather than treating control alone as sufficient. An approved-software list built by watching what your business runs will happily permit these binaries, because they are part of Windows and they are signed by Microsoft. The blocklist is the explicit instruction to make an exception to your exception: trusted generally, blocked here.
In practice this is configuration applied through your application control tooling or device management, and it is a normal part of a competent deployment rather than a separate project. Two things matter. Run it through a learning phase first, because a technical team or an odd line-of-business application may legitimately invoke one of these, and you want to find that in a pilot rather than in production. And keep it current, since Microsoft adds to the list as new abusable components are identified, and a blocklist applied once and never revisited is missing everything found since. If you are unsure whether yours is applied at all, that is worth asking your provider today: 1800 456 567.
Close the trusted-tool gap
Applying the blocklist is part of a proper application control deployment. We implement it and keep it current as Microsoft updates the list.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business