Transcript
My name is Marijke van Duffen. I'm part of the Solutions Marketing team here at Ivanti. And with me today, we have Lara Hellman. Hi, Lara. Hi, Marijke. I am the product manager. So, yeah. So, Application Control at Ivanti has a very long history. We've had a product that came via AppSense for, well, it's 25 years young, in fact. It's an incredibly mature solution. But Ivanti Neurons for App Control uses the technology there, but brings it to a modern market and makes it a much easier configuration experience. At the heart of App Control, though, is the same desire it has always been, which is to, first of all, control access to applications and, secondly, to manage privileges of users. So when we talk about application control, we're talking about white listing or allow listing versus black listing or block listing. We're also talking about doing that within the context of particular circumstances, whether that's whether you are on the network or off the network, whether it's because you are a particular user in a particular group or what have you. So there's lots of flexibility there in the white listing or black listing as well. And then on privilege management side, we'd be talking about elevation on demand. So being able to remove local admin privileges from most of your users and instead allowing them to have elevated rights for particular tasks. So whether that's resetting their system clock or whether it's launching SAP, which requires administrator rights in order to save files, what have you. But it means that they only have admin rights in the context of the things that they have to have admin rights for in order to be productive. Now, Neurons for App Control takes those two concepts, which are often sold separately. And we have lots of competitors who have point products in either of those spaces. We offer both of those things under the Neurons for App Control banner. And we do something very special that is almost completely unique to us. We have a concept called trusted ownership and trusted ownership effectively reduces the admin overhead of those allow and deny lists. So rather than having to list out everything that you want to allow or worse, trying to list out everything that you want to block, you instead have a concept where you say if the file is owned by an administrator of the system or one of these other trusted owners, which includes like the Windows installer, then we can assume it's probably safe to run because anything malicious or anything that has been installed in the context of the user that may be malicious probably shouldn't be allowed. An effective IT department should be pushing out all of the allowed software, right? So therefore, it should be installed by a trusted owner. So effectively, application control takes away from you that admin overhead of trying to define your allow list and instead says, if it's got a trusted owner, then we'll always allow it. You can, of course, create exceptions to that. So you can say if it's a shared device, for example, that has particularly sensitive software on it, you can say it's only allowed to be executed by these people, even though it's a trusted owner. But if somebody nefarious comes onto the machine or somebody logs in who's not supposed to use it, then they cannot access that software still. So you still have that flexibility. And on top of that, of course, you can also specify allow lists that say ignore trusted ownership for this thing, for whatever reason, it's been installed by the wrong user, but we know it's safe. It can still be executed. And you can actually do that at a very granular level as well. So you can say we'll only allow you to execute if it's version 14 or above, for example. So it's that kind of flexibility. In addition to that, we've made the configuration very simple and very easy to help our customers get successful with. So we have something called an audit mode, which means that when they first start using app control, they can deploy an empty configuration, which will obviously have trusted ownership turned on, but nothing else. You deploy that to some machines and then that brings back some event data, some audit data to tell you what's on that machine, what you might want to consider creating rules for. So this application is being executed, but it's currently untrusted. Do you want to create a rule to allow it to be trusted or do you need to go back to your software deployment team and say, right, you need to deploy this properly? It also will tell you about applications that require elevated privileges in order to run so that you can choose to create elevation rules for that kind of thing. We also, like I say, have Elevate on demand and we have the ability for people to actually say, I need elevated privileges for this. So it gives you that ability to be very reactive to productivity requirements as well. We also offer some pre-canned rules. We call them app templates. So for popular solutions that for whatever reason would fail trusted ownership or for whatever other reason need specific AC rules for them, then we offer those already. So it's very easy for customers just to incorporate that into their configurations. And then finally, we use all of that data we collect from the machines, all of the information about what is happening on the devices. We present that in Neuron's app control. So it's very easy for the administrators to look at the data and work out what they need to do in order to ensure that their users continue to be productive. Moving on now to the new exciting things that are coming with the July release. So back over to you, Lara. One of the most popular features from the on-premises solution is something called policy change request. Now, I mentioned earlier that we can create rules based on what we know customers are using, and we can also block solutions that are on the endpoint, even if they would pass trusted ownership. But we can say for these users, don't give it to them. Policy change request lets that user say, actually, I need access to this particular solution for a particular task. So it might be something like Microsoft Visio that's on the machine, but most of the time it's blocked. But the user can click on Visio and say, actually, I need access to this. Now, the way we've integrated this is actually with ServiceNow. So at the point at which that end user says, I need access to this, it will create a request in ServiceNow in the context of that user. So it uses the user's name and the device name and the machine, and the user can actually enter a reason as well. And then in ServiceNow, you can create a process that automatically approves it or sends it off an email to the particular service owner to ask them to approve it, or whatever it is that is the appropriate thing in that customer's environment to get this approval. And once the approval is granted, the application control agent on that machine will automatically update the policy so the user has access to that piece of software. Even better, the approver can choose how long that access is given for. So you can actually set it to an hour, seven days, a month, whatever is appropriate length of time to have that access. And when that time has elapsed, the access is removed and the user would have to request it again. So that is policy change request integrated with ServiceNow. There is obviously more coming and I'll get to that in a moment. But the next piece that is coming in July is the ability to allow elevated applications. So I've talked a little bit already about how some applications, so you can create rules to allow apps, even if they fail trusted ownership, and you can create rules to elevate apps so that users get the elevated privileges they need to be productive. When you create one of those elevated rules, you can tick a box now on that rule to say automatically allow it for this user. So if they pass the elevation rules, so if they are allowed to have the application elevated, then they are also allowed to use the application. It just makes it a little bit simpler from an administrative perspective. You don't have to have two separate rules. The other thing coming in July release then is another on-premise feature that we wanted to add to neurons, which is the ability to choose where the events get stored on the endpoint. So at the moment, you can choose to have them go into the Windows application event block, which is usually fine for most people. But some customers like to be able to put it into a separate event log. Sometimes that's useful from a CM integration perspective, being able to just say, right, everything in here is application control. So go take that and store it elsewhere or analyze it however you want to. So it's just another option there. Now, we've got some features that haven't made it in for the July release, but will be coming in October. So the ability to import the on-premises configurations. So this is really important for our existing AC customers, the ability to rather than start from scratch in Neurons AC, what they will be able to do is take a copy of their existing on-premises configuration, upload it to Neurons, and it will get converted into a Neurons AC configuration. So they'll start with what they already had. So that is, like I say, coming in the future. Another great feature coming for the future will be support for EntroID users and devices. This is our highest voted enhancement request already. So we understand it is very important and it will be coming in the October release. There has been lots of work happening in this quarter to make it available for next quarter. So that will give you the ability to create rules based on an EntroID or group rather than just the AD user or group. And then finally, the other piece coming for October definitely will be that policy change request piece that I talked about, integrating with ServiceNow will also integrate with bots. So you're using bots as the process engine to determine how and whether the approval should come through for that request. So obviously, with bots, you can integrate with all sorts of other things. You can certainly initiate Teams conversations, send emails. You can go through incredibly complex logic groups if you need to, where you can say, if your name starts with a D, then approve it or whatever. You can have a very complicated approval process if you need to, using the bots in order to make sure that the policy changes get updated and approved as and when they should. But that's a highlight of some of the features coming in certainly July and looking ahead to October as well.