Configure Sophos Endpoint Application Control
Application Control is intended to stop unwanted or risky software without prematurely treating every unknown application as malware. Sophos assigns known programs to application categories. The policy then decides which ones are allowed or blocked.
The safe starting point is therefore not “block everything unnecessary”, but detect, assess, pilot and only then block. This makes remote-management, administration and collaboration tools that are genuinely used visible before a production block interrupts business processes.
Application Control is not malware protection
Threat Protection detects malicious files and behaviour. Application Control enforces an operational decision for otherwise known applications. A remote-administration tool may be legitimate for support and undesirable on a normal workstation. No blanket default switch can replace this assessment.
Allowing an application in Application Control also does not stop Sophos checking it for malware, exploits, ransomware or malicious behaviour. Conversely, a genuine false positive should not be concealed by a broad Application Control exception.
Detect first
Open the Application Control policy under My Products > Endpoint > Policies. Keep the policy in detection mode for the first phase. Scheduled or local scans can also be used so that installed applications that are not currently running appear in the inventory.
After several representative working days, assess the results under Reports > Events. The application name is not the only important value: device, user, time and business purpose also matter. An application that is legitimate on an IT administration device may be unwanted on every other endpoint.
Categories and individual applications
Sophos organises controllable programs into categories. Blocking an entire category is convenient but has a wider impact. Where products in the same category require different treatment, open the category and refine the decision at application level.
A maintainable model typically consists of a few decisions:
| Decision | Suitable for |
|---|---|
| allow category | established software class with clear approval |
| block category | software class generally prohibited in the organisation |
| block individual application | exception within an otherwise allowed category |
| allow individual application | approved product within an otherwise blocked category |
Do not fill the policy with many precautionary individual exceptions. Every deviation needs an owner and a traceable reason.
Do not treat Protected Browser and Island Browser separately
Sophos Protected Browser and Island Enterprise Browser currently share core binaries, so Sophos Endpoint can detect both with the same signature. An Application Control decision for Island Browser may therefore also affect Sophos Protected Browser; reliable separate approval is not guaranteed. The overlap also affects DLP browser detection. When using Workspace Protection, test Application Control together with Endpoint DLP and document the product boundary.
Block a pilot group
Assign the first blocking policy to a small computer group. It must include typical users, important business applications and at least one IT workstation. After assignment, check Policies on the device to confirm that this Application Control policy is actually effective.
During the pilot, verify:
- the expected application is blocked and generates an Event
- allowed applications continue to start
- Windows users receive the configured desktop message
- the helpdesk knows the application, rule and approval process
- bypass attempts using portable or renamed programs are detected
Desktop messages are a Windows feature. On other platforms, the operating process must not depend on users seeing the same dialogue.
Block script hosts only after inventory
Under Programming / Scripting tool, Application Control can control applications such as Microsoft WSH WScript. This adds a barrier against malicious JavaScript files but can also block legitimate sign-in, administration, or business-application scripts. Inventory a script host in detection mode first and block it only for appropriate device groups. This does not replace AMSI or Threat Protection and is not blanket malware remediation.
Handle new applications automatically
Sophos can automatically include new applications in an already controlled category. This keeps policies current but expands their automatic impact. In a blocked category, a newly classified but operationally required product may therefore be blocked without separate approval.
Sophos marks New applications added to this category by Sophos as optional and warns against enabling it without careful consideration. Use it only when new catalogue entries in the category should deliberately be controlled automatically. The convenience of a current list does not replace change control; for blocked categories, periodic review followed by a pilot is usually easier to govern.
New GenAI category
Sophos now lists applications that use generative AI in the GenAI category. Depending on the platform, this includes desktop clients, local models, coding assistants and content tools. Existing programs such as Cursor, Microsoft Copilot, Ollama, Perplexity and Windsurf have been moved there from previous categories.
According to Sophos, reclassification does not change an application’s existing Allow or Block status. It does, however, change where the application is found in reports and policy maintenance. Re-inventory the GenAI category after a catalogue update. A blanket block is not a substitute for rules covering browser services, data classification and approved business AI applications.
If an application is missing
Not every product is immediately available in the Sophos catalogue. Sophos provides a process for requesting that an application be added. Until classification is available, do not try to force the same result with an unspecific malware exclusion. Application Control and Threat Protection exclusions solve different tasks.
Sophos states that reviewing a new application typically takes about 6 to 10 weeks and can take longer depending on risk, complexity, and release cycle. This request is therefore not a short-term change process.
If a specific file must be prevented in the meantime, its SHA-256 can temporarily be added to the global Blocked list. This blocks only that file tenant-wide. It provides neither category detection nor a group- or policy-based Application Control decision and must be reviewed after catalogue inclusion.
⚠️ An unspecific Threat Protection exclusion is not a replacement for a missing Application Control entry. Application Control and malware exclusions solve different tasks.
Troubleshooting
If an expected application is not blocked, first check the effective policy, target group and policy order. Then check the application version, actual process and time of the last agent update. A catalogue entry does not mean that every variant or launcher is detected identically.
If a required application is blocked, correct the policy at application level and save it again. There is no need to disable Application Control globally. Then check on the affected device that the updated policy has arrived.
Related articles
Build Sophos Central Endpoint policies correctly explains policy order and effective assignment. Introduce Sophos Endpoint Control policies in practice covers the overall rollout of control features.