Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Applications checks in Trust Profile

In this document
  • General Notes
  • Application is Installed
  • Application Version

Application checks look at the list of installed programs on a Windows computer, the same list you see in Settings > Apps > Installed apps or Control Panel > Programs and Features. Use them to require that a product is installed, or that it is at or above a minimum version.

Supported platforms: [Windows]

General Notes

  • Both 64-bit and 32-bit installations are found.

  • Only programs installed for all users (machine-wide) are visible. Programs installed only for a single user profile are not seen by these checks.

  • Publisher and Application are glob patterns and are not case sensitive. A value without * or ? must match the name exactly.

  • Leave Publisher empty to accept any publisher. Fill it in when the application name is generic enough to be shared by other products.

  • The installed programs list is refreshed at most every 15 seconds, so a program that was just installed or removed may take a moment to be seen.

  • If several installed entries match (for example a 32-bit and a 64-bit copy), one matching entry is enough for the check to pass.

trust profile application check

Application is Installed

Platforms

[Windows]

Comparison

None

Fields

Publisher (optional), Application (required)

Passes when an installed program matches the application name and, if given, the publisher.

Installers often add extra text to the name, such as the architecture or language. Use * to allow for it.

Table 1. Examples
Publisher Application

(empty)

Mozilla Firefox* (matches Mozilla Firefox (x64 en-US))

CrowdStrike, Inc.

CrowdStrike Windows Sensor

Microsoft*

Microsoft Intune Management Extension*

Application Version

Platforms

[Windows]

Comparison

equals, does not equal, is less than, is less than or equal, is greater than, is greater or equal

Fields

Publisher (optional), Application (required), Version (required)

Compares the version of an installed program with the version you enter. Versions are compared number by number, so 1.10 is higher than 1.9.

Use is greater or equal to enforce a minimum patch level. For example, Application Google Chrome*, is greater or equal, Version 128.0.6613.84.

How missing and unusual entries behave
  • If the application is not installed, the check fails for every comparison, does not equal included. If you mean not installed, or installed but older than X, build it with a group set to Match any check. Add NOT Application is Installed and Application Version is less than X. Match applies to the whole platform group, so this works best when these two are the only checks in the group.

  • An installed entry that records no version counts as older than any real version. It passes is less than and never passes is greater or equal.

Tip
To see the exact name, publisher and version Windows records, run this in PowerShell: Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*, HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, Publisher, DisplayVersion
www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013