A user downloads a remote-access tool at lunch. It shouldn’t start just because they clicked it — Heimdal Application Control lets only the programs you approve start on Windows endpoints — by path, hash, publisher or certificate — and AppFencing limits what those approved programs may do once they are running.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Heimdal Application Control — the allowlisting module with AppFencing, sold as its own line item. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Only software you have approved may start, and even approved software is fenced in what it may do.
What consolidation actually replaces, dimension by dimension.
| Dimension | Users installing what they like | Heimdal Application Control |
|---|---|---|
| What may start | Whatever a user downloads | Only the paths, hashes, publishers or certificates you allow |
| What an allowed app may do | Anything its user can do | Bounded by AppFencing, with no stray child processes |
| Who approves new software | Whoever picks up the ticket | An approver set per user or AD group |
| Proof for auditors | Screenshots and recollection | 90 days of execution logs, exportable for longer |
| Devices covered | Every OS, none of it managed | Windows today; macOS only as a release candidate |
| What it is NOT | — | Antivirus, EDR, admin elevation, or publicly priced |
The cheapest test is one department: switch it to default-deny on the free trial, count the requests in two weeks, and fence its script hosts.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The single Heimdal agent that carries the platform’s other modules checks every program as it starts and stops anything outside your rules, on Windows 10, 11 and Server 2016 to 2025.
Policies, pending requests and execution logs sit in Heimdal’s hosted dashboard, inside a tenant the customer places in Europe, the US or the UK; no Indian region is offered.
Each rule names a file path, an MD5 hash, a publisher or a signing certificate. Heimdal markets the default-deny stance as Zero-Trust Execution, with unlisted software held back until approved.
Being allowed does not mean being unlimited: AppFencing narrows the actions of a permitted program, aiming to stop it spawning child processes or serving as a path for lateral movement.
One Heimdal agent judges every launch on Windows — rules decide what starts, AppFencing decides what it may then do.
Heimdal Application Control stops unapproved software at launch and keeps approved software inside set limits.
Match software by where it sits, its MD5 hash, its publisher or the certificate that signed it, and allow or block on that basis.
Automated approval workflows send each user request to an approver set per user or Active Directory group, not to one shared inbox.
AppFencing limits what a permitted program does once it is running, so a trusted tool cannot freely launch further processes.
Heimdal pitches AppFencing against lateral movement: an approved app should not become the route an intruder uses to reach other machines.
Heimdal says the module keeps 90 days of logs for compliance; export older history if an auditor or CERT-In asks for 180 days.
It integrates with Heimdal PEDM, so letting an app start and letting it run with admin rights stay two separate, logged decisions.
An AppFencing demo, an explainer on application control versus whitelisting, and a primer on stopping unauthorised software. All from Heimdal’s official channel, 2025 and 2026.
Heimdal’s own walk-through of allow and block rules and the AppFencing limits placed on approved software.
Where a plain allowlist ends and wider control of application behaviour begins, in Heimdal’s framing.
A short primer on blocking unapproved software before it runs, the problem this module is built for.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most allowlisting stops at whether a program may start. Heimdal adds a second check through AppFencing: what may an allowed program do next? Curbing child processes and lateral movement matters because attackers like to abuse tools already trusted on the machine rather than bring their own.
Default-deny lasts only if requests get answered. Heimdal routes them through automated workflows keyed to the user or the Active Directory group, so a finance package can go to one approver and an engineering tool to another, instead of piling up in a single IT queue.
Application Control is one line on the same platform as Heimdal’s DNS, patching, antivirus and privilege modules. An estate already running any of them adds a policy rather than another agent, and PEDM elevation choices sit beside execution choices in the one dashboard.
Production coverage is Windows alone: macOS exists only in the 3.5.9 release candidate and Ubuntu has no agent for this module. No price is published, logs are held for 90 days, tenant data lives in Europe, the US or the UK, and no analyst firm has placed the product.
List the software your Windows endpoints launch today, team by team, and note which titles carry a stable publisher certificate.
Allow by publisher or certificate wherever possible, falling back to MD5 hash or path only for unsigned in-house tools.
Switch one team to default-deny, map approval workflows to its AD group, and track every request it raises for a fortnight.
Apply AppFencing to script hosts and office apps first, checking that blocked child processes do not break macros or plug-ins.
Extend the policy to the rest of the Windows estate and schedule a log export, since the dashboard holds only 90 days.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A user tried to start an unsigned remote-access tool from Downloads. The path rule stopped it and the request went to our approver.”
“Publisher rules saved us. Approving the vendor certificate once covered every monthly update of our accounting software.”
“AppFencing stopped our document editor from launching a script host, which is exactly what our red team had abused.”
“Routing requests by AD group helped: lab staff now hear back from their own lead instead of waiting on central IT.”
“Our designers use Macs, and the macOS agent is still a release candidate, so that part of the office sits outside policy.”
“Ninety days of logs satisfied internal audit, but we export every month because our policy wants six months on file.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the application control market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per device per year; free trial, no public price.
The grid nobody publishes — how many operating systems a product enforces on in production vs how far it controls execution, from allowlisting to containing allowed apps.
Windows in production; four rule types plus AppFencing.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against ThreatLocker Allowlisting, Carbon Black App Control, Microsoft App Control for Business, BeyondTrust EPM and Airlock Digital — on deployment, platforms, rules, containment, approvals, price, audit evidence and India.
| Dimension | Heimdal Application Control | ThreatLocker Allowlisting | Carbon Black App Control | Microsoft App Control for Business | BeyondTrust Endpoint Privilege Management | Airlock Digital |
|---|---|---|---|---|---|---|
| What it is | Allowlist + AppFencing | Default-deny agent | Positive Security Model | Part of Windows | EPM with app control | Allowlisting specialist |
| Deployment | Heimdal-hosted console | Cloud portal | Self-hosted server | Native to Windows | SaaS for Windows, Mac | Three hosting choices |
| Platforms covered | Windows; macOS in RC | Windows, macOS, Linux | Windows, macOS, Linux | Windows only | Windows, Mac, Unix | XP SP3 to macOS 26 |
| Rule types | Path, MD5, publisher | Catalogue + one click | Publishers, cloud, rules | Signer, hash, ISG, path | Templates + exceptions | Signing and publishers |
| Containing allowed apps | AppFencing™ | Ringfencing | Integrity, memory rules | Scripts constrained | Trusted-app protection | Scripts and libraries |
| Approval workflow | By user or AD group | About 60-second replies | Graded enforcement | No request queue | Just-in-time requests | One-time passwords |
| Privilege elevation | Separate PEDM line | Elevation Control | Not in scope | Intune Suite EPM | The core product | Not on record |
| Pricing model | Per device, per year | Custom, often via MSP | Partner quote | Windows entitlement | Quote, per endpoint | Direct or partner |
| Published entry price | Not published | Not published | Not published | No added fee | Not published | Not published |
| Included vs add-on | Own line; PEDM apart | Modules on one agent | EDR is separate | In the OS itself | Platform add-ons | Execution focus |
| Audit evidence | 90-day logs | Time-boxed approvals | PCI DSS 4.0 mapping | Intune and hunting | Compliance reporting | SOC 2, ISO, IRAP |
| India data location | Europe, US or UK | Not published | Your server in India | Follows your tenant | Ask about region | On-prem keeps it here |
| Trial and support | Free trial; Mumbai desk | 30-day trial | Through partners | Microsoft Learn guides | Office in India | Direct or partner |
| Best fit | Heimdal Windows estates | MSP-run allowlisting | ATMs, POS, EOL systems | Intune Windows fleets | Admin removal first | Old and mixed OS fleets |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no application control guide yet, so Heimdal Application Control sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (Windows endpoints; IT staff-hour cost). Estimates model the IT time spent removing unapproved software, chasing what a user installed and answering ad-hoc install requests, at an assumed 1.5 hours per endpoint a year, with 70% of it saved by default-deny rules and routed approvals. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Heimdal publishes no price for Application Control; its pricing calculator lists it as a separate line item counted per device per year, and shows no figures. A free trial is offered from the product page. PEDM elevation and Next-Gen Antivirus are separate line items. TechBag counts your Windows endpoints first, then gets the quote itemised in INR with GST.
Best for Windows estates going default-deny
Best for a broader rollout
Best when admin rights are coming away too
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many endpoints run Windows 10/11 or Server 2016–2025? Macs wait on the 3.5.9 release candidate; Linux has no agent.
Can most software be allowed by publisher or certificate, so monthly updates pass without a fresh hash each time?
Which in-house or legacy tools are unsigned and will need MD5-hash or path rules, and who will maintain those?
Which AD groups map to which approvers, and what response time will you promise users who are blocked?
Which allowed apps — script hosts, office suites, remote tools — need AppFencing limits on child processes?
Is 90 days of logs enough, or must you export history to satisfy CERT-In’s 180 days or an internal policy?
Will your compliance team accept tenant data in Europe, the US or the UK, given Heimdal has no Indian region?
Does the quote count devices per year and separate this module from PEDM and antivirus? Ask for INR with GST.
Inventory the software your Windows endpoints run first, or let a TechBag advisor draft publisher-first rules, route approvals by AD group and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.