Enforced by Windows. Governed through PoliEze.

The enterprise control plane for trusted software execution

PoliEze provides end to end management of Windows App Control policies, giving security and IT the governance, visibility and evidence to control what runs across the Windows estate.

Built by the engineers who implemented and operated Application Control technologies across nearly 500,000 endpoints supporting more than one million users.

App Control enforcement zones, user mode and kernel mode Two concentric zones. The outer zone is user mode, where executables, libraries, installers, scripts and packaged apps are checked, but only when the UMCI rule option is enabled in the policy. The inner sphere is kernel mode, where drivers are checked. Kernel mode is always enforced by an App Control policy. Approved code passes through to execution and unapproved code is refused before the process starts. WINDOWS KERNEL MODEDriversalways enforcedUSER MODE.exe .dll.msi .ps1scriptsappx.sys drivers
  • Kernel mode, always enforced
  • User mode, when UMCI is enabled

The problem

Zero Trust execution is powerful. Enterprise management is hard.

  1. Policy management relies on scarce expertise

    Designing rule levels, structuring base and supplemental policies, and interpreting events require specialist knowledge. Progress slows when that expertise is concentrated in one or two people.

  2. Visibility across the Windows estate is fragmented

    Teams struggle to build a complete view of the applications, scripts, installers and unsigned binaries running across the fleet.

  3. Trust decisions lack consistent governance

    Every allowed application needs a clear owner, business justification and approval record. Without a governed process, decisions become difficult to track and defend.

  4. Constant change creates policy risk

    Software updates, new versions and local changes can introduce unexpected blocks, policy gaps and ongoing maintenance overhead.

  5. Moving to enforcement requires confidence

    Teams need to understand the likely impact of a policy before progressing from audit mode to enforcement.

  6. Evidence is difficult to sustain

    Security leaders and auditors need a reliable record of what is allowed, what changed, why it changed and who approved it.

The PoliEze platform

Control what runs. Govern how it changes.

  • See what matters

    Get a central view of what is running, what requires review and where risk remains.

  • Govern trust decisions

    Record the owner, business justification and approval history for every software trust decision.

  • Manage exceptions

    Approve, reject, review and automatically expire exceptions through one consistent workflow.

  • Track enforcement readiness

    See which business units, device groups and deployment rings are ready to move from audit to enforcement.

  • Prove the control works

    Produce clear evidence for executives, auditors and cyber governance without assembling it manually.

01 DISCOVER

Your environment

  • Everything your deployment tool installs
  • Signer and publisher inventory across the fleet
  • Per user and self installed applications
  • Legacy and unsigned line of business tools

02 CONTROL PLANE

PoliEze

  • Application Intelligence
  • Enforcement Intelligence
  • Application Lifecycle Intelligence
  • Continuous Reconciliation

03 ENFORCE

Windows endpoints

Delivered by Intune or Configuration Manager

  • Allowed

    runs normally

  • Audited

    logged, not blocked

  • Blocked

    event 3077 raised

App Control and Flow

Get to enforcement. Stay enforced.

Software changes continuously. PoliEze gives security and IT one governed model for deciding what can run, moving policies into enforcement, and holding that control as approved applications change.

Why now

AI agents changed who can start code on your endpoints

Give an agent a tool and you give it everything that tool can do. On Windows that includes launching processes, loading modules and running scripts, so the set of things that can start code is no longer just your users.

Identity controls answer who an agent is acting for. They do not answer what it is allowed to run. An allowlist answers that the same way, regardless of who asked.

Zero trust for code execution

Where it runs

A live rollout in a high change environment

Skyline International College is deploying App Control for Business with PoliEze across 200 student and staff endpoints. The environment combines two very different operating needs. Students require flexibility, while staff systems demand tighter control. PoliEze helps manage both within one governed rollout.

Skyline International College

Student lab devices

Coursework has to run. Nothing else should.

Devices are reimaged between intakes and students install things no policy author anticipated. Allow list decisions have to be quick or the class stops.

Staff devices

The same policy estate, a different profile.

Staff endpoints hold student records and sit under the same base policy as the labs, with a supplemental of their own. The multi profile problem, at a size you can see end to end.

Why it is a hard case

A teaching lab is harder than an office.

Corporate fleets change slowly. A lab is reimaged between intakes, its software turns over with the syllabus, and its users are actively encouraged to try things.

Rollout in progress200 student and staff endpointsOne base policy with a supplemental per device profileTarget: Enforcement inside eight weeksTarget: Ten minutes to get a blocked user working againTarget: Thirty minutes to deploy the permanent policy change

Questions

What teams ask first

Not the question you had?

The guides go deeper: event IDs and what they mean, why an Intune deployed app gets blocked, and what audit mode does not tell you.

Read the guides
Is App Control for Business the same thing as WDAC?
Yes. Microsoft renamed Windows Defender Application Control to App Control for Business with the Windows 11 24H2 release. The feature and its policy format are the same, only the branding changed. Before that it was called Device Guard.
Does PoliEze replace Intune or Configuration Manager?
No. PoliEze authors, versions and approves the policies, then hands them to Intune or Configuration Manager to deliver. It works alongside the deployment tooling you already run rather than replacing it.
Do we have to enforce policies straight away?
No, and you should not. Application control is normally run in audit mode first so that block events are logged without anything being stopped. PoliEze is built around that staged approach, moving a policy to enforcement one deployment ring at a time.
What happens to our work if the Essential Eight is retired?
Application control is a control, not a framework. The Australian Signals Directorate announced in June 2026 that the Essential Eight will be replaced by the Essentials series over roughly 24 months, but restricting which executables can run remains a core expectation. Work done on application control now carries across.
What does PoliEze need access to?
It needs to read your existing application inventory and code integrity events, and to publish policies to your deployment tool. Exactly what that looks like depends on whether you run Intune, Configuration Manager, or both, and we walk through it during a demo.

See what your fleet would actually block

Walk through a real policy against a real environment with us. We will show you what audit mode surfaces, what would break on day one, and how long a staged rollout takes.