Trinetri logo
Device Control

Prohibited Software

Prevents the use of unapproved or high-risk software by detecting prohibited applications and automatically uninstalling them from managed endpoints.

  • 1 min
  • September 3, 2026

What You'll Learn

  • How to create a Prohibited Software rule by selecting a detected application and version
  • How to choose between the pre-filled default uninstall command and a custom uninstall command
  • How to enable the Auto-Uninstall Policy and configure a notification shown to users before uninstall
  • Where to review Auto-Uninstall Status per endpoint, including success/failure and uninstall time
  • How to exclude specific endpoints from prohibited software enforcement using Global Exclusion
CTA background

Experience Trinetri Autonomous Platform in Action.

Frequently Asked Questions

What does a Prohibited Software rule track? A rule pairs a name you choose with a specific software entry and version selected from the detected software inventory, so enforcement targets the exact application version present in your environment rather than just an executable name.
What's the difference between Pre-fill and Custom uninstall commands? Pre-fill uses the software's default uninstall command, auto-populated for you (for example, calling the vendor's uninstall executable with a silent switch). Custom lets you supply your own uninstall command instead.
What does the Auto-Uninstall Policy control? It's a global toggle that turns on automatic uninstallation of prohibited software across endpoints. Once enabled, you can also turn on Notify Before Uninstall and customize the message users see before the uninstall runs.
Can I exclude specific endpoints from enforcement? Yes. Turning on Global Exclusion in Settings reveals an Excluded Assets field where you can select one or more specific endpoints that prohibited software rules won't be enforced against.
Where do I check whether an uninstall succeeded or failed? Auto-Uninstall Status lists each endpoint alongside the software name, version, uninstall status (Success or Failed), and the uninstall time.