All insights

What is Microsoft's recommended application blocklist?

2 min readBy Brendon Whiting, Founder · 24 February 2026

It is a list Microsoft publishes of its own signed applications that attackers commonly abuse, and that most businesses have no reason to run. Blocking them closes a specific gap: application control permits trusted software, and these are trusted, so without the blocklist they sail straight through.

The technique this defends against has a name in security circles, living off the land, and the logic is simple. Rather than bringing in malware that antivirus might recognise, an attacker uses tools already present and already trusted on a Windows machine. Legitimate diagnostic utilities, scripting hosts and developer components can download files, execute code and move around a network, and they do it wearing a valid Microsoft signature. Nothing looks wrong because, from the system's point of view, nothing is wrong.

That is why the Essential Eight expects the blocklist alongside application control rather than treating control alone as sufficient. An approved-software list built by watching what your business runs will happily permit these binaries, because they are part of Windows and they are signed by Microsoft. The blocklist is the explicit instruction to make an exception to your exception: trusted generally, blocked here.

In practice this is configuration applied through your application control tooling or device management, and it is a normal part of a competent deployment rather than a separate project. Two things matter. Run it through a learning phase first, because a technical team or an odd line-of-business application may legitimately invoke one of these, and you want to find that in a pilot rather than in production. And keep it current, since Microsoft adds to the list as new abusable components are identified, and a blocklist applied once and never revisited is missing everything found since. If you are unsure whether yours is applied at all, that is worth asking your provider today: 1800 456 567.

Close the trusted-tool gap

Applying the blocklist is part of a proper application control deployment. We implement it and keep it current as Microsoft updates the list.

Frequently asked questions

Rarely in an ordinary business, because these are developer and diagnostic tools most staff never touch. The exceptions are real though: a technical team or a line-of-business application may invoke one legitimately. That is what a learning-mode phase finds, and the answer is a documented exception for the specific case rather than skipping the list.

Yes, Microsoft updates it as new abusable binaries are identified, which means applying it once is not the same as maintaining it. Treat it like any other security configuration: applied centrally, reviewed periodically, and re-checked when Microsoft publishes changes. A blocklist from three years ago is missing whatever has been found since.

Yes, and the two address different things. Antivirus looks for malicious files; these are legitimate, signed Microsoft files behaving as designed. That is exactly why attackers reach for them, because nothing flags a trusted tool. Blocking them removes the technique rather than trying to detect its use.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.