Environment
- App Control: All Supported Versions
Objective
Is it possible to track allowed executions when an endpoint is in enforcement?
Resolution
- In the console, under Reports > Events, use Subtype == Execution prompt allowed (unapproved file) to filter for instances where an unapproved executable was allowed to run in medium enforcement.
- To track specific executions when approved an Execution Allow Rule - Report can be used to track executions
Related Content