Application blocking is deactivated by default. You must activate it manually, configure conditions to control the users eligible for application blocking, and define a custom message.
Procedure
-
Start the DEM Management Console.
-
On the User Environment tab, select Application Blocking.
-
Click Global Configuration.
-
Select Activate Application Blocking.
-
Click Add in the Conditions section to configure conditions to control which users have application blocking activated.
-
Click Add in the Message section to add a parent application that displays a custom message when it attempts to start a blocked application.
Most commonly, the parent applications used are
explorer.exe, located inC:\Windows\andcmd.exe, located inC:\Windows\System32. If one of the configured parent applications attempts to start a blocked application, the configured message is displayed instead of the default message. -
Enter a message title, message text, and the amount of time for which the message appears.
-
Click OK.
Results
With application blocking activated, only applications from the Windows folder, C:\Program Files, and C:\Program Files (x86) are allowed to run.
What to do next
To allow and block additional paths, see Allow and Block Additional Applications.
Was this page helpful?