Select tools to manage App Control for Business

App Control for Business (App Control) is one of the most effective ways to prevent unwanted code from running in your environment. App Control's technology offers strong protection against malware and unauthorized software, but managing the full lifecycle can be intimidating. While Microsoft's first-party tooling is much improved, customers often turn to partner solutions to complete the end-to-end process.

This article describes the management product offerings from Microsoft that you should consider when planning your App Control deployment. It also spotlights noteworthy non-Microsoft offerings that might help if your requirements aren't yet covered by first-party offerings.

Microsoft first-party management offerings

Microsoft doesn't yet offer a single pane of glass experience for managing App Control for Business. Customers often use multiple tools to manage the full end-to-end lifecycle of App Control for Business.

Here are some of the Microsoft products you can use for your App Control deployments:

App Control Wizard

The App Control Wizard is the official, open-source policy creation tool maintained by the App Control product team. The GUI interface can create, edit, and merge App Control policies. It uses the App Control management API and PowerShell cmdlets under the hood and is packaged and distributed as an MSIX app.

Key capabilities:

  • Create App Control policies starting from a template, configure policy options, and add custom rules for most supported rule types
  • Edit App Control policies
  • Create rules from event data using local event logs, remote logs, or exported to comma-separated files
  • Form a combined policy by merging two or more policies
  • Generate App Control policy XML and binary files

Microsoft Intune

Microsoft Intune provides limited App Control policy authoring but has robust policy deployment capabilities. Intune is commonly used by cloud-native customers and in hybrid environments. It doesn't yet include any built-in event collection or reporting for App Control scenarios.

Key capabilities:

  • Choose among eight preset base policies or import your own custom base and supplemental policies
  • Targeted self-configuration of Intune as a Managed Installer
  • Policy targeting and staged rollouts

Note

Intune's eight preset base policies don't allow direct customization. However, you can use supplemental policies for these preset base policies to add trust for other apps.

Microsoft Defender for Endpoint (MDE)

Microsoft Defender for Endpoint provides event collection and querying through advanced hunting and security dashboards.

Key capabilities:

  • Automatic collection and parsing of App Control events into reporting tables
  • Advanced hunting queries and post-compromise breach analysis
  • Device timelines showing block events
  • Correlation with broader endpoint security event data
  • Integration with automated investigation and response workflows

Microsoft Azure-based management (Azure.local, Azure Arc, server tools)

Azure portal includes several tools for managing your cloud native and hybrid server deployments.

Key capabilities:

  • Windows Admin Center provides guidance and reporting on configuration state of App Control for server workloads
  • Azure.local includes App Control policy configured by default from the baseline security configuration. Policy management is available via PowerShell cmdlets integrated in the console. Scenario-based reporting within the console is also available.
  • Azure Monitor allows centralized event ingestion and reporting.

Microsoft Configuration Manager (ConfigMgr)

ConfigMgr supports policy deployment at enterprise scale and setting ConfigMgr as a managed installer. Often used in environments with complex device management needs. Can also assist with event collection via integration with other tools.

Key capabilities:

  • Deploy a base policy that allows Windows and Windows Store-signed apps, ConfigMgr, and apps and scripts deployed by ConfigMgr or other managed installers
  • Optionally, allow app binaries identified as safe by the Intelligent Security Graph (ISG)
  • Allow any apps and scripts found in file path locations you configure through a one-time client-side scan during policy application
  • Automatic configuration of ConfigMgr as a managed installer
  • Custom policy deployment using ConfigMgr Packages and Programs or OS Deployment Task Sequences

Other Microsoft tools useful for managing App Control for Business

CITool.exe

Command-line tool provided inbox with Windows that can be used alongside PowerShell or other script engines to automate on-device policy management and active policy reporting.

PackageInspector.exe

Command-line tool provided inbox with Windows that generates catalog files for files it sees written to disk. You can sign and distribute these catalog files to authorize code you wish to allow.

PowerShell

App Control cmdlets enable policy authoring, conversion, and validation. Common in automated workflows or environments where scripting is preferred.

Windows Event Forwarding

Supports event collection by aggregating App Control logs from multiple devices.

Power BI

Can be layered on top of Log Analytics or other structured event repositories to create visual dashboards for reporting.

Group Policy

Useful for domain-joined environments. Supports policy deployment for policies created for use on Windows Server 2016, Windows Server 2019, and older versions of Windows 10.

Partner solutions that enhance App Control for Business

The following partner offerings provide management and governance capabilities that complement Microsoft's first-party tools.

Note

Microsoft doesn't provide support for third-party products. Contact the product developer for support.

AppControl Manager (Free and open source)

Developer: Violet Hansen

Availability: AppControl Manager is available from the Microsoft Store. Its source code and documentation are available on GitHub.

AppControl Manager is a Windows app for creating, editing, deploying, and monitoring App Control policies. Its graphical interface supports policy management on local and remote devices.

AppControl Manager key capabilities

  • Creates, edits, merges, and deploys App Control policies.
  • Parses App Control events and generates reports.
  • Creates policy rules from event data.
  • Integrates with Microsoft Intune and Microsoft Defender for Endpoint.
  • Supports local and remote device management.
  • Uses MSIX packaging and doesn't send device data to a service.

AppControl Manager development approach

Hansen initially developed AppControl Manager for personal use and later released it as an open-source community project. The project focuses on providing App Control management capabilities without requiring a commercial service.

AppControl.ai (Paid offering)

Developer: AppControl.ai

Availability: AppControl.ai is a commercial SaaS platform with consulting, training, and support services. Product and contact information is available on the AppControl.ai website.

AppControl.ai collects App Control events and managed application information from an organization's endpoints. It groups file-level events into application-level context to support policy decisions and deployment planning.

AppControl.ai key capabilities

  • Provides organization-specific software reputation information.
  • Aggregates events in centralized dashboards.
  • Deduplicates events to reduce reporting volume.
  • Supports trust approval workflows.
  • Analyzes policy effects before enforcement.
  • Integrates with Microsoft Intune and Microsoft Defender for Endpoint.
  • Provides consulting, training, and customer support services.

AppControl.ai development approach

AppControl.ai was designed to manage trust decisions at the application level instead of requiring administrators to review individual file events. The service combines endpoint data, application information, and workflow automation to support application allowlisting at enterprise scale.

MagicSword (Free and enterprise offerings)

Developer: MagicSword

Availability: MagicSword is a managed SaaS platform with signed-agent and agentless deployment options. A free tier supports up to 100 endpoints, and the paid enterprise tier has a 14-day trial.

MagicSword uses threat intelligence to create App Control block policies for drivers, scripts, and binaries associated with attacker techniques. It also supports allowlist policies and application control capabilities for macOS and Linux.

MagicSword key capabilities

  • Provides a policy wizard and granular policy editor.
  • Incorporates threat intelligence from the LOLDrivers and LOLRMM projects.
  • Monitors endpoints, generates threat alerts, and tracks readiness from audit to enforcement.
  • Supports AMSI-based script detection and browser extension management.
  • Provides spawn-control rules for macOS and Linux.
  • Integrates with Microsoft Intune, Configuration Manager, Group Policy, SIEM products, and alerting services.
  • Provides enterprise reporting, threat hunting, onboarding, and support options.

MagicSword development approach

MagicSword draws on work from the LOLDrivers and LOLRMM threat research projects. The service focuses on translating current threat intelligence into policy rules that organizations can review and deploy.

PoliEze (Paid offering)

Developer: Gritellect Pty Ltd

Availability: PoliEze is a commercial offering available through Microsoft Marketplace. Product, implementation, and support information is available on the Gritellect website.

PoliEze provides management and governance capabilities for the App Control policy lifecycle. It supports policy changes, exceptions, approvals, staged rollouts, evidence capture, and ongoing assurance.

PoliEze key capabilities

  • Provides App Control policy lifecycle governance.
  • Supports the Managed Installer lifecycle.
  • Manages temporary exception requests and approvals.
  • Tracks policy changes and captures operational evidence.
  • Supports staged rollouts and enforcement readiness.
  • Uses event data to inform policy refinement.
  • Reports on application control operations and assurance.
  • Integrates with Microsoft Intune and ServiceNow.

PoliEze development approach

Gritellect based PoliEze on its experience implementing App Control in large enterprise environments. The service focuses on helping security and platform teams operate App Control as an ongoing control rather than as a one-time policy deployment.

Choosing the right management approach

Here are some factors to consider when choosing which tools to use with App Control for Business. But remember that these solutions aren't mutually exclusive. The right answer for your organization might require multiple tools to deliver the full functionality you need.

Factor Considerations
Cost Is similar functionality already included with Windows licensing? Is there a free or low-cost tier?
Policy authoring Does the solution offer a rich user experience for your admins? Can the capabilities exposed in the UI be automated using enterprise automation and systems management tooling, such as Microsoft Intune?
Event analysis Does the solution provide built-in reporting that lets you perform advanced analytics and deduplication? Can you easily generate new policy rules from data reported from client endpoints?
Software trust intelligence Is the source of rule creation primarily static or does the system incorporate new signals and intelligence into the rules it guides you to create? What signals and sources of data does the solution rely upon when making decisions about policy?
Support model Does the solution provide the support you'll need to run your business and keep your end users productive? Do you require formal Commercial support contracts or can you rely on community-driven support primarily?
Architecture Has the solution been built in a way that is optimized for your organization? How does it scale? Can it be used in all of the network and software environments that you need it to for your business? Does it cover the environment that you operate under, whether you're a Cloud‑first org, hybrid, or primarily an on-premise operation?

Up next

Continue on and explore your policy design options: