Skip to content
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows

Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows

Written By Anoop C Nair
Last Updated December 3, 2024
Posted In Windows
SHARE

Let’s discuss Application Control for Business, the Ultimate Solution to Block Unwanted Apps and Malware on Windows devices. Application Control for Business is a robust security solution designed to help organizations block unwanted applications and protect against malware on Windows devices.

It ensures that only trusted and safe applications are allowed to run by using a combination of IT policy rules and advanced AI-based app reputation technology from Microsoft. IT administrators can easily configure and deploy these policies based on signed templates to create a secure environment.

This proactive approach helps prevent unauthorized software installations, reduces the risk of security breaches, and ensures that only compliant applications are used in the organization.

In this post, you will find everything you need about Application Control for Business, the ultimate solution to block unwanted apps and malware on Windows. This solution helps protect the organization from potential security threats and ensures a safer computing environment for everyone.

Patch My PC

Application Control for Business

The IT admin uses a trusted, signed, reputable template to set up Application Control for Business policies. After selecting the template, they can make a few changes to customize it for their needs. The admin chooses the “Policy Creation” settings option in the App Control Policy wizard.

This step allows them to create a new base or supplemental policy, depending on the need. The wizard guides them through the process, making it easy to set up the policy rules and get everything ready for deployment.

Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows - Fig.1 - Creds to MS
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Fig.1 – Creds to MS

Select a Policy Type

In the screenshot below, select the policy type as “Multiple Policy Format” and “Base Policy.” The “Multiple Policy Format” option allows you to create a base or supplemental policy, depending on your needs.

The “Base Policy” option helps you create a new code integrity policy for the system, ensuring that only trusted and secure applications can run. This setup makes managing and enforcing security policies across your organization’s devices easier.

Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows - Fig.2 - Creds to MS
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Fig.2 – Creds to MS

Signed and Reputable Mode

Here, you should enable the “Signed and Reputed Mode.” Once this mode is enabled, you can see the policy name and the location of the policy file. This ensures that the policy is based on trusted and signed templates.

After confirming these details, click “Next” to proceed with the setup and continue creating and deploying the policy.

Signed and Reputable Mode authorizes
Windows OS components
Microsoft Store applications
Office 365, OneDrive, Teams
WHQL-signed kernel drivers
All Microsoft-signed applications
Files with good reputation using ISG
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Table 1
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows - Fig.3 - Creds to MS
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Fig.3 – Creds to MS

Configure Policy Template

In the “Configure Policy Template” section, you should enable the “Managed Installer” and disable the “Audit Mode.” Audit Mode is helpful for testing but won’t enforce the policy.

Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows - Fig.4 - Creds to MS
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Fig.4 – Creds to MS

Custom Rule Conditions

You can easily add custom rule conditions by clicking the “Add Custom” button. A pop-up window will appear where you can select the rule type as “Path.” Then, choose “Reference File” as “Folder” and click “Browse” to locate the folder you want to include in the rule.

Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows - Fig.5 - Creds to MS
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Fig.5 – Creds to MS

This allows you to customize the policy further by specifying particular folders or paths to control which apps can run. The screenshot below shows more details.

Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows - Fig.6 - Creds to MS
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Fig.6 – Creds to MS

Finished Creating the App Control for Business Policy

The App Control for Business policy has been successfully created. The output files are saved in the following locations:

  • C:\Users\WDACUser\Documents\SignedReputable2024-11-14.xml
  • C:\Users\WDACUser\Documents{698CCD7B-9340-4AB2-A00E-8BC61DA52D95}.cip
  • You can open these files to review the policy settings and prepare for deployment. The first file is the policy in XML format, and the second is a deployment-ready file.
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows - Fig.7 - Creds to MS
Application Control for Business the Ultimate Solution to Block Unwanted Apps and Malware in Windows – Fig.7 – Creds to MS

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Resources

Secure and resilient Windows strategy from Client to Cloud

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update

Key Takeaways BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update! After deploying the June 2026 Windows update (KB5094126), some HP EliteDesk 800 G6 devices began prompting for the BitLocker recovery key after every reboot. Based on our investigation, the Secure Boot UEFI 2023 certificate update does not appear to be […]

AC Anoop C Nair 5 min read
Microsoft Defender for Endpoint

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Key Takeaways In this post, we are discussing how Microsoft Defender for Endpoint EDR Updates Will Be Delivered Through Microsoft Update. Microsoft has introduced a new update model for Microsoft Defender for Endpoint Detection and Response (EDR) security updates. Previously, these updates were included with the monthly Windows security updates. This change enables Microsoft to […]

AC Anoop C Nair 5 min read