App Filter
App Filter Endpoint Control
The App Filter endpoint control feature empowers administrators to block specific applications from running on end-user devices. This is crucial for enforcing security and compliance by preventing the usage of unauthorized or high-risk applications.
This control is supported on devices running: - Windows - Linux - Darwin (macOS)
Admins can choose to enforce the App Filter: - When the user connects to the ZTNA agent (VPN mode), or - Immediately upon device boot (always-on control)
Steps to Configure App Filter Endpoint Control
-
Go to Configuration → Data Management.
-
Click “Add New Dataset”.
-
Set the Dataset Variable Type to “Application”.
-
Enter the Dataset Name and Description, then click “Create Dataset”.
-
Open the newly created dataset.
-
Toggle to Edit Mode.
-
Navigate to the Records tab.
-
Click the “+ Add Record” button.
-
Enter the Application Name for each app you want to block. You can add multiple records to block several applications.
Create an App Filter Policy
-
Navigate to Access Policy → Endpoint Policy.
-
Click “Add New Policy”.
-
Enter the Policy Name and Description.
-
Select “App Filter Control” and associate it with the previously created Application dataset.
-
Choose the dataset created for the App filter created now and choose applicable Operating Systems.
-
Select the target Users or User Groups to whom the policy should apply.
-
Define when the control should be active:
-
When VPN is connected, or
-
At device boot
-
-
Click “Submit” to apply the policy.
How It Works
- Launch the ZTNA UI Client
- Enter the InstaSafe Workspace URL
- Authenticate via the redirected InstaSafe login page
- When prompted, click "Open InstaSafe ZTNA Agent."
- The ZTNA Agent will launch — click Connect
- Upon connection, the App filter policy is automatically applied(if selected VPN is connected), restricting applications within the controlled session.