We’re trying to design a long-term app allowlisting strategy across macOS and Windows devices managed by Hexnode. A few things are confusing:
- On macOS, some Adobe Creative Cloud apps such as Premiere Pro, Photoshop, Illustrator, InDesign, Lightroom, and Media Encoder appear in the Blocklist/Allowlist picker, but they don’t consistently show up in Reports > Applications.
- The picker also shows apps or identifiers that look like they came from enrolled devices, not just apps we manually added.
- On Windows, Application Compliance shows many duplicate-looking entries for the same app, including MSI GUIDs, package names, display names, and SDK components. Managing hundreds of pages manually doesn’t seem practical.
- On macOS, a strict allowlist caused Finder and some background services to be blocked on a freshly wiped test device, even after selecting everything available.
- Since many users are local admins, broad allowlisting of
/Applications/feels like a loophole because users could place unapproved apps there.
What is the best practical approach for app allowlisting and monitoring with Hexnode on macOS and Windows, especially if we want an audit/monitor mode before enforcement?