Skip to content
arrow_back
search
E8-AC-ML2.2 bolt ASD Essential Eight

Application control excludes user profiles and temporary folders

Ensure application control is in place everywhere except user profiles and temp folders.

record_voice_over

Plain language

This control is about making sure that only approved software can run on your computers, except in some specific areas like user profiles and temporary folders. Without this control, unwanted software or viruses could sneak in and cause harm, like slowing down your systems or stealing important information.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Application control

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.
bolt ASD Essential Eight E8-AC-ML2.2
priority_high

Why it matters

If application control doesn’t cover user profiles and OS/browser/email temp folders, attackers can run malware from these paths, leading to data loss and outages.

settings

Operational notes

Regularly review allow/deny rules and logs for user profile and browser/email temp paths, and confirm common temp locations can’t be used to launch executables.

Mapping detail

Mapping

Direction

Controls