Category filter

Configure Application Compliance for Windows devices

In organizations, security or compliance concerns may sometimes necessitate the restriction of specific applications on devices. Or perhaps, you may just want to block apps that affect the user’s productivity and overall work experience. For this, you can easily use Hexnode UEM’s Blocklist/Allowlist feature to restrict access to such apps on the devices. However, what if you merely want to detect the presence of those apps without blocking them? With the help of Hexnode UEM’s Application Compliance feature, you can do just that. It enables you to identify whether specific applications are present on Windows devices in your workplace and determine their compliance status accordingly.

Notes:

  • Application Compliance policy is supported only on Windows 10 (Pro, Enterprise, Education) and Windows 11 (Pro, Enterprise, Education) devices.
  • Hexnode Agent app version 4.8.0 or above should be installed on the device.

Setting Application Compliance

Application Compliance allows you to check the compliance of the device with respect to the apps that are installed on the device. The device is considered non-compliant if any app from the blocklist is present on the device or if there is an app installed that is not included in the allowlist. However, this policy does not restrict the use or access to these applications. It does not block them, hide their icons on the device, or prevent their installation.

Perform the following steps to configure application compliance for Windows devices,

  1. Log in to your Hexnode UEM portal.
  2. Navigate to Policies > New Policy. Click on New Policy to create a new one or select an existing one to make edits. Then, Enter the Policy Name and Description in the provided fields.
  3. Go to Windows > App Management > Application Compliance. Click on Configure.
  4. Choose the type as Blocklist or Allowlist.
  5. Click on +Add. Then, click on Add App to select apps individually from the list of apps or click on Add Group to select an app group.
  6. Select the apps from the list and click on Done.
  7. Then, click on Save.

If Blocklist is selected, the device is scanned for the presence of apps specified on the blocklist. Conversely, if Allowlist is selected, the device is scanned for any app not mentioned in the list. If either condition is met when the respective option is selected, the device is deemed non-compliant.

Under Device Summary > Compliance Info you can view the Application compliance status and the exact number of blocked apps present on the device.

Configuring Application Compliance policy on Windows devices.

Note:


The option Device is not application compliant under Admin tab > General Settings > Compliance Settings, must be enabled. The device will not be marked as non-compliant unless you’ve enabled this option.

Associate the policy with target entities

If you haven’t saved the policy,

  1. Navigate to Policy Targets.
  2. Select the required Devices, Users, Device Groups, User Groups or Domains.
  3. Click on Save.

If you have already saved the policy,

  1. Navigate to Policies > My Policies and select the required policy.
  2. Click on Manage > Associate Targets.
  3. Select the required Devices, Users, Device Groups, User Groups or Domains.
  4. Click on Associate.
  • Deploying and Managing Apps