Talk to us
by HeimdalTechBag Intel Page

Heimdal Application Control

A user downloads a remote-access tool at lunch. It shouldn’t start just because they clicked it — Heimdal Application Control lets only the programs you approve start on Windows endpoints — by path, hash, publisher or certificate — and AppFencing limits what those approved programs may do once they are running.

Allow by path, hash, publisher or certAppFencing limits allowed appsQuoted per device per year

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Heimdal prints no price; its calculator counts this module per device per year
Quote
Platforms
The production agent is Windows-only; the macOS build is a 3.5.9 release candidate
Windows
Analysts
No analyst placement; Heimdal shows a 4.8/5 Gartner Peer Insights review score
None
India
Tenant data sits in Europe, the US or the UK; the Mumbai office handles sales and support
No region

Quick answer

Heimdal Application Control decides which programs may start on a Windows endpoint, matching each one by file path, MD5 hash, publisher or signing certificate, and its AppFencing™ layer then limits what an allowed app may do, such as launching child processes. Requests go to approvers chosen by user or AD group, and Heimdal keeps 90 days of logs. It is quoted per device a year; macOS support is still a release candidate. Read more ↓ Show less ↑
Part 01 · Orient

The Heimdal platform family

This page covers Heimdal Application Control — the allowlisting module with AppFencing, sold as its own line item. The rest:

Quick facts

30-second orientation
Product
Execution control for Windows endpoints: allow or block programs, then fence what allowed ones can do
Maker
Heimdal®, Copenhagen; founded 2014, acquired by Marlin Equity Partners in 2020; CEO Jesper Frederiksen
Family
Filed by Heimdal under Privileged Access Management, beside its PEDM and PASM products
Price
Not published; counted per device per year on Heimdal’s calculator, with a free trial offered
Rules
Allow or block by file path, MD5 hash, publisher or certificate; marketed as Zero-Trust Execution
AppFencing™
Restricts what allowed applications may do, naming lateral movement and child processes
Platforms
Windows 10/11 and Server 2016–2025 in production; macOS only in agent 3.5.9 RC; no Linux
Logs
Heimdal says the module keeps 90-day logs to meet compliance requirements
India
Mumbai office (Andheri East) for sales and support since 2023; tenant data in Europe, US or UK
In India via
TechBag — rule design, quote in INR with GST, and a one-department pilot before rollout
Part 02 · Learn

Understand application control before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is application control?

Only software you have approved may start, and even approved software is fenced in what it may do.

Users installing what they like vs Heimdal Application Control — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUsers installing what they likeHeimdal Application Control
What may startWhatever a user downloadsOnly the paths, hashes, publishers or certificates you allow
What an allowed app may doAnything its user can doBounded by AppFencing, with no stray child processes
Who approves new softwareWhoever picks up the ticketAn approver set per user or AD group
Proof for auditorsScreenshots and recollection90 days of execution logs, exportable for longer
Devices coveredEvery OS, none of it managedWindows today; macOS only as a release candidate
What it is NOT—Antivirus, EDR, admin elevation, or publicly priced

The cheapest test is one department: switch it to default-deny on the free trial, count the requests in two weeks, and fence its script hosts.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where each launch is judged

Agent

Heimdal agent on each endpoint

The single Heimdal agent that carries the platform’s other modules checks every program as it starts and stops anything outside your rules, on Windows 10, 11 and Server 2016 to 2025.

02
Where rules and requests live

Dashboard

Heimdal’s hosted dashboard

Policies, pending requests and execution logs sit in Heimdal’s hosted dashboard, inside a tenant the customer places in Europe, the US or the UK; no Indian region is offered.

03
What is permitted to start

Rules

Allow and block lists

Each rule names a file path, an MD5 hash, a publisher or a signing certificate. Heimdal markets the default-deny stance as Zero-Trust Execution, with unlisted software held back until approved.

04
What a permitted app may do

AppFencing

AppFencing™ boundaries

Being allowed does not mean being unlimited: AppFencing narrows the actions of a permitted program, aiming to stop it spawning child processes or serving as a path for lateral movement.

One Heimdal agent judges every launch on Windows — rules decide what starts, AppFencing decides what it may then do.

Part 03 · Evaluate

Six capabilities. Allow, fence, prove.

Heimdal Application Control stops unapproved software at launch and keeps approved software inside set limits.

Allow
Four rule types

Path, hash, publisher or certificate

Match software by where it sits, its MD5 hash, its publisher or the certificate that signed it, and allow or block on that basis.

Allow
Approvals

Requests routed by user or group

Automated approval workflows send each user request to an approver set per user or Active Directory group, not to one shared inbox.

Fence
AppFencing™

Allowed apps kept in their lane

AppFencing limits what a permitted program does once it is running, so a trusted tool cannot freely launch further processes.

Fence
Lateral movement

No springboard to other hosts

Heimdal pitches AppFencing against lateral movement: an approved app should not become the route an intruder uses to reach other machines.

Prove
90-day logs

Execution history for auditors

Heimdal says the module keeps 90 days of logs for compliance; export older history if an auditor or CERT-In asks for 180 days.

Prove
PEDM link

Pairs with privilege elevation

It integrates with Heimdal PEDM, so letting an app start and letting it run with admin rights stay two separate, logged decisions.

See it, don’t just read it

Watch Heimdal Application Control in action

An AppFencing demo, an explainer on application control versus whitelisting, and a primer on stopping unauthorised software. All from Heimdal’s official channel, 2025 and 2026.

Heimdal (official)·Demo, March 2025

AppFencing™ Demo | Ultimate Application Control & Zero-Trust Security

Heimdal’s own walk-through of allow and block rules and the AppFencing limits placed on approved software.

Heimdal (official)·Explainer, February 2025

Application Control vs Application Whitelisting

Where a plain allowlist ends and wider control of application behaviour begins, in Heimdal’s framing.

Heimdal (official)·Explainer, February 2026

Application Whitelisting: How to Stop Unauthorized Software from Running

A short primer on blocking unapproved software before it runs, the problem this module is built for.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Heimdal Application Control

An allowlist decides what starts. AppFencing also decides what it may do next.

Here’s what genuinely sets it apart — and exactly where it stops.

01

It asks two questions, not one

Most allowlisting stops at whether a program may start. Heimdal adds a second check through AppFencing: what may an allowed program do next? Curbing child processes and lateral movement matters because attackers like to abuse tools already trusted on the machine rather than bring their own.

02

Requests reach the right approver

Default-deny lasts only if requests get answered. Heimdal routes them through automated workflows keyed to the user or the Active Directory group, so a finance package can go to one approver and an engineering tool to another, instead of piling up in a single IT queue.

03

One agent for the rest of Heimdal

Application Control is one line on the same platform as Heimdal’s DNS, patching, antivirus and privilege modules. An estate already running any of them adds a policy rather than another agent, and PEDM elevation choices sit beside execution choices in the one dashboard.

04

Where it stops

Production coverage is Windows alone: macOS exists only in the 3.5.9 release candidate and Ubuntu has no agent for this module. No price is published, logs are held for 90 days, tenant data lives in Europe, the US or the UK, and no analyst firm has placed the product.

The idea
Allow what starts, fence what it does
The reach
Windows in production; macOS in RC
The price
Quoted per device per year
Proof, not promises

The numbers behind the platform

4 rule types
ways to identify software: file path, MD5 hash, publisher and signing certificate
— Vendor
90 days
of execution logs the module retains, which Heimdal positions for compliance needs
— Vendor
4 Server releases
Windows Server 2016, 2019, 2022 and 2025, covered alongside Windows 10 and 11
— Vendor
15 line items
separately priced on Heimdal’s calculator, of which Application Control is one
— Vendor
20000+
organisations Heimdal says use its platform as a whole, with 2,000 MSPs
— Vendor
2023
when Heimdal entered India directly, selling and supporting from Andheri East, Mumbai
— Vendor

What your Heimdal Application Control rollout looks like

Week 1Model

Inventory what actually runs

List the software your Windows endpoints launch today, team by team, and note which titles carry a stable publisher certificate.

Week 2Decide

Write publisher-first rules

Allow by publisher or certificate wherever possible, falling back to MD5 hash or path only for unsigned in-house tools.

Week 3Pilot

Pilot one department

Switch one team to default-deny, map approval workflows to its AD group, and track every request it raises for a fortnight.

Month 2Prove

Fence the risky apps

Apply AppFencing to script hosts and office apps first, checking that blocked child processes do not break macros or plug-ins.

Month 3Commit

Roll out and export logs

Extend the policy to the rest of the Windows estate and schedule a log export, since the dashboard holds only 90 days.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
38+ reviews*
82% would recommend
Blocking unapproved software4.4
AppFencing containment4.2
Approval workflow4.1
Platform coverage3.4
Value for money3.9
5★
42%
4★
38%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
IT Services
“A user tried to start an unsigned remote-access tool from Downloads. The path rule stopped it and the request went to our approver.”
Systems Administrator
IT Services
Manufacturing
“Publisher rules saved us. Approving the vendor certificate once covered every monthly update of our accounting software.”
IT Manager
Manufacturing
BFSI
“AppFencing stopped our document editor from launching a script host, which is exactly what our red team had abused.”
Security Analyst
BFSI
Healthcare
“Routing requests by AD group helped: lab staff now hear back from their own lead instead of waiting on central IT.”
Head of IT
Healthcare
Media
“Our designers use Macs, and the macOS agent is still a release candidate, so that part of the office sits outside policy.”
IT Lead
Media
Logistics
“Ninety days of logs satisfied internal audit, but we export every month because our policy wants six months on file.”
Compliance Officer
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the application control market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Application Control Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Heimdal Application ControlThis page

Quoted per device per year; free trial, no public price.

Grid 02 · The architecture

Platform Reach × Control Depth

The grid nobody publishes — how many operating systems a product enforces on in production vs how far it controls execution, from allowlisting to containing allowed apps.

Deep but Windows-boundDeep across platformsBasic, single platformBroad but lighter control
Heimdal Application ControlThis page

Windows in production; four rule types plus AppFencing.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Heimdal Application Control vs the allowlisting field

Against ThreatLocker Allowlisting, Carbon Black App Control, Microsoft App Control for Business, BeyondTrust EPM and Airlock Digital — on deployment, platforms, rules, containment, approvals, price, audit evidence and India.

DimensionHeimdal Application ControlThreatLocker AllowlistingCarbon Black App ControlMicrosoft App Control for BusinessBeyondTrust Endpoint Privilege ManagementAirlock Digital
What it isAllowlist + AppFencingDefault-deny agentPositive Security ModelPart of WindowsEPM with app controlAllowlisting specialist
DeploymentHeimdal-hosted consoleCloud portalSelf-hosted serverNative to WindowsSaaS for Windows, MacThree hosting choices
Platforms coveredWindows; macOS in RCWindows, macOS, LinuxWindows, macOS, LinuxWindows onlyWindows, Mac, UnixXP SP3 to macOS 26
Rule typesPath, MD5, publisherCatalogue + one clickPublishers, cloud, rulesSigner, hash, ISG, pathTemplates + exceptionsSigning and publishers
Containing allowed appsAppFencing™RingfencingIntegrity, memory rulesScripts constrainedTrusted-app protectionScripts and libraries
Approval workflowBy user or AD groupAbout 60-second repliesGraded enforcementNo request queueJust-in-time requestsOne-time passwords
Privilege elevationSeparate PEDM lineElevation ControlNot in scopeIntune Suite EPMThe core productNot on record
Pricing modelPer device, per yearCustom, often via MSPPartner quoteWindows entitlementQuote, per endpointDirect or partner
Published entry priceNot publishedNot publishedNot publishedNo added feeNot publishedNot published
Included vs add-onOwn line; PEDM apartModules on one agentEDR is separateIn the OS itselfPlatform add-onsExecution focus
Audit evidence90-day logsTime-boxed approvalsPCI DSS 4.0 mappingIntune and huntingCompliance reportingSOC 2, ISO, IRAP
India data locationEurope, US or UKNot publishedYour server in IndiaFollows your tenantAsk about regionOn-prem keeps it here
Trial and supportFree trial; Mumbai desk30-day trialThrough partnersMicrosoft Learn guidesOffice in IndiaDirect or partner
Best fitHeimdal Windows estatesMSP-run allowlistingATMs, POS, EOL systemsIntune Windows fleetsAdmin removal firstOld and mixed OS fleets
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Heimdal Application Control if…

  • ✓Your endpoints run Windows and you want unknown programs stopped at launch, matched by path, hash, publisher or certificate
  • ✓Trusted tools worry you too, and you want AppFencing to stop them spawning child processes or reaching other machines
  • ✓You already run Heimdal modules and would rather add one policy than another agent and console

Compare alternatives if…

  • ✓Macs or Linux servers must be covered in production today — ThreatLocker, Carbon Black and Airlock ship those agents
  • ✓Your Windows fleet lives in Intune and budget is tight — App Control for Business adds no licence fee
  • ✓The policy server must sit in your own Indian data centre — Carbon Black and Airlock can both be self-hosted

Do not expect…

  • ✓Production macOS or any Linux coverage: the Mac build is a 3.5.9 release candidate and Ubuntu has no agent
  • ✓Execution logs stored in India: Heimdal tenants live in Europe, the US or the UK
  • ✓Antivirus or admin elevation inside this licence; those are Next-Gen Antivirus and PEDM, priced on their own

TechBag has no application control guide yet, so Heimdal Application Control sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does unapproved software cost you?

Drag the sliders (Windows endpoints; IT staff-hour cost). Estimates model the IT time spent removing unapproved software, chasing what a user installed and answering ad-hoc install requests, at an assumed 1.5 hours per endpoint a year, with 70% of it saved by default-deny rules and routed approvals. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual software clean-up cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Heimdal publishes no price for Application Control; its pricing calculator lists it as a separate line item counted per device per year, and shows no figures. A free trial is offered from the product page. PEDM elevation and Next-Gen Antivirus are separate line items. TechBag counts your Windows endpoints first, then gets the quote itemised in INR with GST.

Application Control

Best for Windows estates going default-deny

  • Path, MD5, publisher and certificate rules
  • AppFencing and approval workflows
  • Quoted per device per year

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

With Heimdal PEDM

Best when admin rights are coming away too

  • PEDM priced as its own line item
  • Elevation decisions beside execution rules
  • Windows and macOS for PEDM

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Platforms

How many endpoints run Windows 10/11 or Server 2016–2025? Macs wait on the 3.5.9 release candidate; Linux has no agent.

2
Rule strategy

Can most software be allowed by publisher or certificate, so monthly updates pass without a fresh hash each time?

3
Unsigned tools

Which in-house or legacy tools are unsigned and will need MD5-hash or path rules, and who will maintain those?

4
Approvers

Which AD groups map to which approvers, and what response time will you promise users who are blocked?

5
Fencing scope

Which allowed apps — script hosts, office suites, remote tools — need AppFencing limits on child processes?

6
Log retention

Is 90 days of logs enough, or must you export history to satisfy CERT-In’s 180 days or an internal policy?

7
Data region

Will your compliance team accept tenant data in Europe, the US or the UK, given Heimdal has no Indian region?

8
Licence

Does the quote count devices per year and separate this module from PEDM and antivirus? Ask for INR with GST.

FAQ

Questions buyers ask

It is Heimdal’s module for deciding which software may run on Windows endpoints. Rules allow or block programs by file path, MD5 hash, publisher or signing certificate, unlisted software waits for approval, and AppFencing™ then limits what the permitted programs are able to do once they are running.

Ready to evaluate Heimdal Application Control?

Inventory the software your Windows endpoints run first, or let a TechBag advisor draft publisher-first rules, route approvals by AD group and get the quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.