Microsoft now steers customers to App Control for Business, since this legacy feature gets no new capabilities. It controls which executables, scripts, installers, DLLs and packaged apps may run through Group Policy rules.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AppLocker in context, with comparison tables and the common traps.
Terms in this definition
- App Control for Business
Previously known as Windows Defender Application Control. On Windows it blocks any driver or app that its policy does not permit, and Microsoft suggests choosing it over AppLocker.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Managed installer
Software deployed through a nominated distribution tool, Intune or Configuration Manager for instance, is trusted automatically under this App Control for Business feature, tracked via an AppLocker rule collection. Earlier installs are not tagged retrospectively.