# Configure Application Compliance for Windows devices

In organizations, security or compliance concerns may sometimes necessitate the restriction of specific applications on devices. Or perhaps, you may just want to block apps that affect the user’s productivity and overall work experience. For this, you can easily use Hexnode UEM’s **[Blocklist/Allowlist](https://www.hexnode.com/mobile-device-management/help/how-to-blacklist-whitelist-apps-on-windows-devices-using-hexnode-mdm/)** feature to restrict access to such apps on the devices. However, what if you merely want to detect the presence of those apps without blocking them? With the help of Hexnode UEM’s **Application Compliance** feature, you can do just that. It enables you to identify whether specific applications are present on Windows devices in your workplace and determine their compliance status accordingly.

 Notes:- Application Compliance policy is supported only on **Windows 10 (Pro, Enterprise, Education)** and **Windows 11 (Pro, Enterprise, Education)** devices.
- Hexnode Agent app version 4.8.0 or above should be installed on the device.

 

Setting Application Compliance
------------------------------

**Application Compliance** allows you to check the compliance of the device with respect to the apps that are installed on the device. The device is considered non-compliant if any app from the blocklist is present on the device or if there is an app installed that is not included in the allowlist. However, this policy does not restrict the use or access to these applications. It does not block them, hide their icons on the device, or prevent their installation.

Perform the following steps to configure application compliance for Windows devices,

1. Log in to your **Hexnode UEM** portal.
2. Navigate to **Policies > New Policy**. Click on **New Policy** to create a new one or select an existing one to make edits. Then, Enter the *Policy Name* and *Description* in the provided fields.
3. Go to **Windows > App Management > Application Compliance**. Click on **Configure**.
4. Choose the type as **Blocklist** or **Allowlist**.
5. Click on **+Add**. Then, click on **Add App** to select apps individually from the list of apps or click on **Add Group** to select an app group.
6. Select the apps from the list and click on **Done**.
7. Then, click on **Save**.

If **Blocklist** is selected, the device is scanned for the presence of apps specified on the blocklist. Conversely, if **Allowlist** is selected, the device is scanned for any app not mentioned in the list. If either condition is met when the respective option is selected, the device is deemed non-compliant.

Under **Device Summary > Compliance Info** you can view the ***Application compliance*** status and the exact number of blocked apps present on the device.

[![Configuring Application Compliance policy on Windows devices.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/01/App-Compliance-in-Windows-devices.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/01/App-Compliance-in-Windows-devices.png)

 Note: 
The option **Device is not application compliant** under **Admin tab > General Settings > Compliance Settings**, must be enabled. The device will not be marked as ***non-compliant*** unless you’ve enabled this option.

 

Associate the policy with target entities
-----------------------------------------

If you haven’t saved the policy,

1. Navigate to **Policy Targets**.
2. Select the required **Devices, Users, Device Groups, User Groups** or **Domains**.
3. Click on **Save**.

If you have already saved the policy,

1. Navigate to **Policies > My Policies** and select the required policy.
2. Click on **Manage > Associate Targets**.
3. Select the required **Devices, Users, Device Groups, User Groups** or **Domains**.
4. Click on **Associate**.