Trinetri logo
Device Control

Application Control

Application Control helps organizations allow only trusted applications to run while blocking unauthorized software. Improve security, maintain compliance, and reduce cyber risks.

  • 2 min
  • July 22, 2026

What You'll Learn

  • How to create an application block policy by exact executable name
  • Deploy a block policy to specific endpoints with an Apply-type deployment
  • Grant temporary access through a fixed duration or a scheduled time window
  • Monitor deployment status and per-endpoint policy enforcement
  • Remove a block cleanly with a Remove-type deployment
  • Confirm removal and audit policy status across the fleet
CTA background

Experience Trinetri Autonomous Platform in Action.

Frequently Asked Questions

Does temporary access modify the underlying block policy? No. Temporary access sits alongside the policy as a scoped, time-bound exception for one endpoint and one executable, and the policy itself is never edited. Once the grant ends, enforcement resumes automatically with no manual step required. See [how to configure application control](/learn/application-control/how-to-configure-application-control) for the full workflow.
What's the difference between Fixed Duration and Time Window? Fixed Duration starts counting the moment the grant is created, for a set number of hours or another unit, suited to a reactive, ticket-driven request. Time Window instead uses an exact start and end timestamp, which fits a pre-planned event where the times are already known, like a maintenance slot or a vendor call.
How do I permanently unblock an application? Create a Remove-type Application Control Policy Deployment targeting the same policy and endpoints the block was originally applied to, then confirm in Policy Status that the policy now shows Inactive for that endpoint.
Is the Executable Name field case-sensitive? Yes. The field must match the real binary exactly, including case, so it's worth confirming the name on a live endpoint rather than typing it from memory or from the application's marketing name.
Can one temporary access grant cover multiple applications? No. Each temporary access entry is scoped to a single Executable Name, so a separate grant is needed for every application that requires a temporary exception.
What happens when a temporary access window ends? The underlying block policy resumes automatically, and the application becomes blocked again on that endpoint with no manual step, and the grant's Status updates to Expired.