ManageEngine Application Control Plus logo

ManageEngine Application Control Plus

by ManageEngine · Since 2002
No reviews yet
ActiveAvailable globallyCloud
Quick facts
VendorManageEngine
Year launched2002
StatusActive
LocationCalifornia Pleasanton 4141 Hacienda Drive Pleasanton CA 94588 USA
Countries servedGlobal
Languages16
Integrations1+
Free tier
Free trial
Contact salesYES

About ManageEngine Application Control Plus

ManageEngine Application Control Plus is an application control software from ManageEngine that helps secure the infrastructure and prevent unauthorized application usage. It combines features like allowing and blocking applications based on organizational needs, managing application-specific privilege access, and removing unwanted admin rights so users can maintain control over application usage. This solution also provides just-in-time application access and privileges whenever necessary, and limits the child processes that an application can create to ensure compliance and security. With these capabilities, organizations can effectively manage their application environment. Key capabilities: allow/block applications manage privileges remove admin rights just-in-time access limit child processes Best for: IT administrators that need to manage application control and endpoint privileges.

ManageEngine Application Control Plus (ACP) is a highly capable cybersecurity solution tailored for organizations seeking to strengthen endpoint security through rigorous application control and privilege management. At its core, ACP delivers on two fronts: automating the categorization of applications into allowlists and blocklists, and enforcing Zero Trust principles by minimizing unnecessary user privileges. This dual functionality is crucial for modern enterprise environments, where the attack surface is constantly expanding. ACP’s application-specific privilege enforcement ensures that users operate under the principle of least privilege (PoLP), significantly reducing the likelihood of unauthorized access or privilege escalation. What makes ACP particularly effective is its automation — the software can intelligently classify and manage applications with minimal manual input, saving IT teams time and reducing human error. The user interface follows the intuitive, structured design seen in other ManageEngine products. While the console is not accessible via mobile browsers, the web interface for desktop environments is user-friendly and supports centralized policy management across Windows and Mac endpoints.

Pros & Cons

What users like
  • +Granular Application Control: Automatically allowlists or blocklists apps based on custom rules, reducing attack surface.
  • +Built-in Privilege Management: Enforces least privilege by removing unnecessary admin rights and enabling just-in-time access.
  • +Zero Trust Alignment: Supports Zero Trust architecture by tightly controlling app access and privilege elevation.
  • +Audit & Compliance Ready: Offers detailed reporting for regulatory compliance and internal audits.
  • +Flexible Deployment: Includes audit mode for non-disruptive monitoring and user access request workflows.
What users flag
  • Initial Setup Complexity: May require careful configuration to align with organizational policies and avoid over-restriction.
  • Windows-Centric: Primarily designed for Windows environments; limited support for macOS/Linux endpoints.
  • Learning Curve: Admins may need time to fully leverage advanced features like child process control and privilege elevation.

Features

Key features

Automated Application Allowlisting and Blocklisting
Automatically places applications into trusted (allowlist) or restricted (blocklist) categories based on defined rules.
Endpoint Privilege Management (EPM)
Built-in capability to manage application-specific privileges and remove unwanted local admin rights, enforcing the principle of least privilege.
Just-in-Time Application Access and Privileges
Grants temporary, time-bound access to applications and elevated privileges only when needed, automatically revoking them afterward.
Child Process Control
Limits or controls the creation of child processes by applications to prevent malicious behavior.
Audit Mode Functionality
Allows endpoints to run in audit mode to monitor application activity without enforcing restrictions, aiding policy validation.
Comprehensive Auditing and Reporting
Provides detailed reports for every app launch attempt, user activity, and compliance purposes.

Additional features

Application Allowlisting
Automatically creates and manages lists of allowed applications based on specified rules.
Application Blocklisting
Prevents specified applications and malicious executables from running.
Endpoint Privilege Management (EPM)
Assigns need-based, application-specific privileged access to prevent privilege elevation attacks.
Remove Unwanted Admin Rights
Discovers and centrally removes excessively distributed local administrator rights.
Just-in-Time Access
Enables temporary application access and elevated privileges that are automatically revoked after a set period.
Child Process Control
Creates global policies to control the execution of child processes generated by applications.
User Access Request
Allows users to request access to essential applications that are currently restricted.
Granular Control over Application Access
Provides fine-tuned control over which applications are allowed or blocked.
Minimize Unauthorized Access
Reduces the risk of unauthorized access by managing and removing unnecessary admin rights.
Adherence to Policies
Helps ensure compliance with organizational policies and regulations through privilege management.
Comprehensive Auditing
Offers detailed reports for auditing and compliance purposes, logging every app launch attempt.
Boost Efficiency
Provides users with necessary tools and access to perform jobs effectively, reducing delays.
Reduce Downtime
Ensures necessary applications and privileges are available on demand, minimizing interruptions.
Increased Flexibility
Offers just-in-time access and audit mode for adaptable policy enforcement.
Audit Mode Functionality
Monitors application activity without enforcing restrictions immediately, for policy validation.
Zero Trust Enforcement
Supports the establishment of a Zero Trust security model.
Principle of Least Privilege (PoLP) Enforcement
Ensures users only have the minimum necessary access to perform their tasks.
Automated Application Placement
Automates allowlisting and blocklisting based on specified control rules.
Customizable Control Rules
Allows specifying prerequisites for application control rules.
Application Grouping
Enables grouping applications by type or business function for consistent policy application.
Executable-Level Control
Operates at the executable level to control scripts, DLLs, installers, and other associated files.
Trusted Vendor Validation
Validates digital signatures and automatically permits applications from trusted software publishers.
Complete Audit Trails and Forensics
Logs who executed an application, when, and from where, supporting incident response and threat hunting.
Flexibility Regulator
Allows administrators to tailor the application control process around specific enterprise requirements, with modes like Strict and Audit.
WAN Architecture Support
Supports managing computers in distributed setups like branch or remote offices and for mobile users, using low bandwidth.
Centralized Web Console
Controls applications for users in local offices, remote offices, and on-the-go from a single console.
Active Directory Authentication
Integrates with Active Directory for user authentication.
Two-Factor Authentication (2FA)
Provides an additional layer of security for access.
Download/Schedule Reports
Allows users to download or schedule comprehensive reports.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

Global
Countries served
16
Interface languages
10
Billing currencies

Interface languages

EnglishSpanishPortugueseFrenchGermanItalianDutchRussianChinese (Simplified)JapaneseKoreanArabicTurkishPolishCzechSlovak.

Billing currencies

🇺🇸USD🇪🇺EUR🇬🇧GBP🇦🇺AUD🇨🇦CAD🇯🇵JPY🇨🇭CHF🇨🇳CNY🇮🇳INR🇷🇺RUB

No reviews yet

Be the first to drop a review

Alternatives to ManageEngine Application Control Plus

CrowdStrike Falcon logo

CrowdStrike Falcon

CrowdStrike Falcon is a cybersecurity platform from CrowdStrike that provides advanced protection for endpoints, cloud…

CrococryptLib logo

CrococryptLib

CrococryptLib is a Windows file and folder encryption software from HissenIT that supports data protection…

Deep Instinct logo

Deep Instinct

Deep Instinct is a cloud data security platform from Deep Instinct that prevents and explains…

DriveLock logo

DriveLock

DriveLock is a cloud-based endpoint security software from DriveLock that protects systems, data, and devices…

Magnet OUTRIDER logo

Magnet OUTRIDER

Magnet OUTRIDER is a forensic software platform from Magnet Forensics designed for rapid triage of…

R

REVE Endpoint Security

REVE Endpoint Security is a security software from REVE Antivirus that protects endpoints from various…

Often compared with ManageEngine Application Control Plus

Compare any two tools →
CrowdStrike Falcon logo
CrowdStrike Falcon
Endpoint Protection
0.0
CrococryptLib logo
CrococryptLib
Endpoint Protection
0.0
Deep Instinct logo
Deep Instinct
Endpoint Protection
0.0
DriveLock logo
DriveLock
Endpoint Protection
0.0