Scenario: Application Management
17 April 2023
ID 183681_1
You can manage applications startup on user devices. You can allow or block applications to be run on managed devices. This functionality is realized by the Application Control component. You can manage applications installed on Windows devices.
Prerequisites
- Kaspersky Security Center is deployed in your organization.
- The Kaspersky Endpoint Security for Windows policy is created and is active.
Stages
The Application Control usage scenario proceeds in stages:
- Forming and viewing the list of applications on client devices
This stage helps you find out what applications are installed on managed devices. You can view the list of applications and decide which applications you want to allow and which you want to prohibit, according to your organization's security policies. The restrictions can be related to the information security polices in your organization. You can skip this stage if you know exactly what applications are installed on managed devices.
How-to instructions:
- Administration Console: Viewing application registry
- Kaspersky Security Center 13.2 Web Console: Obtaining and viewing a list of applications installed on client devices
- Forming and viewing the list of executable files on client devices
This stage helps you find out what executable files are found on managed devices. View the list of executable files and compare it with the lists of allowed and prohibited executable files. The restrictions on executable files usage can be related to the information security polices in your organization. You can skip this stage if you know exactly what executable files are installed on managed devices.
How-to instructions:
- Administration Console: Inventory of executable files
- Kaspersky Security Center 13.2 Web Console: Obtaining and viewing a list of executable files stored on client devices
- Creating application categories for the applications used in your organization
Analyze the lists of applications and executable files stored on managed devices. Basing on the analysis, create application categories. It is recommended to create a "Work applications" category that covers the standard set of applications that are used at your organization. If different user groups use different sets of applications in their work, a separate application category can be created for each user group.
Depending the set of criteria to create an application category, you can create application categories of three types.
How-to instructions:
- Administration Console: Creating application categories for Kaspersky Endpoint Security for Windows policies, Creating an application category with content added manually, Creating an application category with content added automatically
- Kaspersky Security Center 13.2 Web Console: Creating application category with content added manually, Creating application category that includes executable files from selected devices, Creating application category that includes executable files from selected folder
- Configuring Application Control in the Kaspersky Endpoint Security for Windows policy
Configure the Application Control component in the Kaspersky Endpoint Security for Windows policy using the application categories you have created on the previous stage.
How-to instructions:
- Administration Console: Configuring application startup management on client devices
- Kaspersky Security Center 13.2 Web Console: Configuring Application Control in the Kaspersky Endpoint Security for Windows policy
- Turning on Application Control component in test mode
To ensure that Application Control rules do not block applications required for user's work, it is recommended to enable testing of Application Control rules and analyze their operation after creating new rules. When testing is enabled, Kaspersky Endpoint Security for Windows will not block applications whose startup is forbidden by Application Control rules, but will instead send notifications about their startup to the Administration Server.
When testing Application Control rules, it is recommended to perform the following actions:
- Determine the testing period. Testing period can vary from several days to two months.
- Examine the events resulting from testing the operation of Application Control.
How-to instructions for Kaspersky Security Center 13.2 Web Console: Configuring Application Control component in the Kaspersky Endpoint Security for Windows policy. Follow this instruction and enable the Test Mode option in configuration process.
- Changing the application categories settings of Application Control component
If necessary, make changes to the Application Control settings. Based on the test results, you can add executable files related to events of the Application Control component to an application category with content added manually.
How-to instructions:
- Administration Console: Adding event-related executable files to the application category
- Kaspersky Security Center 13.2 Web Console: Adding event-related executable files to the application category
- Applying the rules of Application Control in operation mode
After Application Control rules are tested and configuration of application categories is complete, you can apply the rules of Application Control in operation mode.
How-to instructions for Kaspersky Security Center 13.2 Web Console: Configuring Application Control component in the Kaspersky Endpoint Security for Windows policy. Follow this instruction and disable the Test Mode option in configuration process.
- Verifying Application Control configuration
Be sure that you have done the following:
- Created application categories.
- Configured Application Control using the application categories.
- Applied the rules of Application Control in operation mode.
Results
When the scenario is complete, applications startup on managed devices is controlled. The users can start only those applications that are allowed in your organization and cannot start applications that are prohibited in your organization.
For detailed information about Application Control, refer to Kaspersky Endpoint Security for Windows Online Help and to the Kaspersky Security for Virtualization Light Agent.