Essential Eight · Application Control
Application Control
Your results, and how to close the gap.
This is a format preview, not a finished report. The technical steps are grounded in public ACSC, Microsoft and Apple documentation but are not yet verified, and a few facts are deliberately left marked as open so you can see how the report flags what it cannot yet source.
Report summary
Application control stops work computers running programs you have not approved. It is one of the strongest protections you can switch on, and the one most likely to be quietly rolled back, because that risk is mostly people and process, not the technology. So this plan leads with both.
Where you stand
Already strong
- Windows PCs run Microsoft Defender and Macs run Gatekeeper, so a basic layer is already on both.
- Staff already ask before installing software, so what runs is somewhat limited.
The gap: those layers warn and scan, but nothing yet firmly blocks an unapproved program from running, which is what this plan adds.
Strengths and gap are illustrative here; the real report draws them from your answers.
What it takes
The plan
Who owns it, the budget, and the exception rule.
For ownerHow to explain the change, and handle the blocks.
For ownerThe hands-on steps for your IT, per platform.
For ITThe three parts weave together into one path, from decision to done, spelled out later in the report:
- Decide
- Prepare
- Pilot
- Announce
- Enforce
- Support & verify
Your rollout plan
Three parts, in order. The decisions and your team come first, then the technical setup, done per platform.
Decisions to make
The decisions only you can make. Nothing below starts without them.
- Assign an owner. One person accountable for the rollout, you or your IT provider.
- Approve the approach and budget. Mostly free with built-in Windows tooling; budget is optional (outside IT help to set it up). cost not sourced
- Set the exception stance. Decide in advance who can approve letting a blocked-but-legitimate program run, and how fast. This one decision is what prevents a panicked rollback.
- Add one policy line. A sentence in your IT policy: only approved software runs on work computers.
- Define done. Every work computer enforcing, an exception path in place, and a rollback you have tested.
Bringing your team along
Explain the change and why it matters, handle the blocked-program questions, and support people through it, so it sticks instead of getting switched back off.
- Tell staff why, before you enforce. "To keep us safe from malware, work computers will only run approved programs. Some things may be blocked at first, here is who to contact." A quick team chat covers a handful of people; a short written notice once you are bigger.
- Publish the exception path. "If a program you need for work is blocked, contact X."
- Pilot before you commit. Turn it on in audit mode and watch what would be blocked before enforcing anywhere, one computer for a small team, a small pilot group once you are bigger.
- Brief whoever handles support on the exception process and how to approve a legitimate program, that is you or your IT provider for a small business, or an agreed exception turnaround for a bigger one.
- Have a rollback ready. Know how to quickly loosen enforcement if something critical is caught.
- Expect a first-week bump in "X is blocked" questions right after enforcement, and plan for it.
The technical setup
The hands-on steps for whoever sets it up. Windows and Mac are done differently, so each has its own track below. Every step carries its source, and open items are flagged, not guessed.
-
Application control on every Windows workstation. AppLocker path-based rules, or WDAC (App Control for
Business), applied via Group Policy. Deploy in audit mode first, then enforcement.
ACSC, Implementing application control · Microsoft, App Control for Business deployment guide
-
Block execution from user-profile and temp folders. AppLocker deny rules on user-writable paths across
the executable, script, installer and DLL collections. exact path list + file-type coverage: open
Microsoft, Working with AppLocker rules
-
Block executable content arriving by email. Enable the Defender ASR rule "Block executable content from
email client and webmail".
Microsoft, Attack surface reduction rules reference
-
Verify safely. Confirm via audit-mode block events and the ACSC assessment method, no download-and-run
test.
Microsoft, deployment guide · ACSC, Essential Eight Assessment Process Guide
ACSC's application-control guidance is written for Windows. On Mac, Gatekeeper plus MDM is the equivalent, applied as a compensating control, whether it meets a strict Level 1 assessment should be confirmed.
-
Keep Gatekeeper on, and lock it with MDM. Gatekeeper already lets a Mac open only apps from an
identified developer that Apple has notarised and that haven't been altered. A user can normally override it;
your MDM takes that override away so it can't be switched off.
Apple, Gatekeeper and runtime protection in macOS
-
Allow trusted sources only. Set the Macs to accept the App Store and identified, notarised developers,
and to refuse unsigned or un-notarised apps. exact MDM payload: open
Apple, Protecting against malware in macOS
- Apply and hold it centrally. Push the policy from your MDM (Jamf, Kandji, Mosyle or Intune) so every Mac is the same, new and remote ones included, and staff can't loosen it. product-specific steps: open
-
Verify safely. Confirm through your MDM's compliance view or device logs, not by downloading and running
a test app.
Apple, Mac app security enhancements
From decision to done
The three parts above are not done in silos or one after another. This is the single order they weave into, the decisions and your team leading, the technical work threaded through.
-
1
Decide
DecisionsOwner, approach, exception stance, policy line.
-
2
Prepare
TeamDraft the staff message and the "blocked? contact X" path; brief IT.
-
3
Pilot
Setup + teamAudit mode on a few machines, each platform separately; review what would be blocked; refine the rules and the exception list.
-
4
Announce
TeamMessage staff just before enforcing.
-
5
Enforce
SetupSwitch to enforcement on each platform, rolling out in waves.
-
6
Support & verify
Team + setupHandle the first-week questions; confirm via block events; keep the rollback ready.
Sources
- ACSC Implementing application control
- ACSC Essential Eight Assessment Process Guide
- Microsoft Working with AppLocker rules
- Microsoft App Control for Business deployment guide
- Microsoft Attack surface reduction rules reference
- Apple Gatekeeper and runtime protection in macOS
- Apple Protecting against malware in macOS
- Apple Mac app security enhancements
How this was made. The Windows steps are citation-grounded against ACSC and Microsoft; the Mac steps against Apple's Gatekeeper and deployment guidance, and the Mac track is flagged because ACSC's application-control guidance is written for Windows. The business and change-management steps are principle-based advice: ACSC's guidance backs the audit-mode pilot, exception handling and staff communication; the rest is established rollout practice, given as advice, not cited fact. Items marked open (cost, exact folder paths and MDM payloads, file-type coverage, the AppLocker Windows edition) are resolved from the source publications before a real report ships, never invented.