Feature Preview - Coming Soon
Ringfencing controls what an application can do after it is allowed to run. Releasing soon, ThreatLocker is adding the ability to create Ringfencing policies separate from Application policies. Ringfencing applied to existing Application policies will continue to be honored.
This will require future agents that are currently unavailable

Open the Ringfencing page
-
Sign in to the ThreatLocker Portal.
-
Select Apps from the left navigation menu.
-
Select the Ringfencing tab.
-
Select Windows or macOS based on the endpoints you want to manage.
Page controls
| Control or column | Purpose |
|---|---|
| New Policy | Opens the two-step Create Ringfencing Policy workflow. |
| Windows / macOS | Displays policies for the selected operating system. |
| Applies To | Filters the list by the scope assigned to each policy. |
| Search | Finds a policy in the current list. |
| Inactive / Expired | Includes policies that are inactive or past their expiration date. |
| Order | Shows or changes the policy's position in the list. |
| Active | Enables or disables the policy without deleting it. |
| Policy Name | Identifies the policy. |
| Policy Level | Shows the organization, group, or other level where the policy is assigned. |
| Conditions | Summarizes the applications or application group matched by the policy. |
| Status | Shows or changes the policy's enforcement mode. |
| Created | Shows when the policy was created. |
| Delete | Permanently removes the policy. |
Before you begin: Identify the target operating system, devices, users, applications, resources to protect, and any access the application must retain. Review the monitored file and registry settings before relying on those restrictions.
Create a Ringfencing policy
Define policy details and scope
-
Select New Policy.
-
Enter a unique Policy Name.
-
Enter a Description that explains the policy's purpose, if needed.
-
Choose whether to turn off Policy Active. Turn it off to finish or review the policy before activating it.
-
Select Add Policy to Top or Add Policy to Bottom to set the policy's initial position.

Select devices and users
-
Under Device or Device Groups, keep Entire Organization or remove it and select the required devices or groups.
-
Under Users or User Groups, keep Everyone or remove it and select the required users or groups.
-
Select Next.

Scope check: Review both scope fields before continuing. The policy is evaluated only within the selected device and user scope.
Choose conditions
Conditions identify the applications to which the configured Ringfencing actions apply. You can select a broad application group or search for one or more specific applications.
| Condition | When to use it |
|---|---|
| Applications with a permit policy | Targets applications that have an Application Control permit policy. |
| Applications without a permit policy | Targets applications that do not have a matching Application Control permit policy. |
| Application | Targets a specific built-in or custom application. |
| Process Tree | Targets activity when the selected application appears anywhere in the process tree. |

Add a specific application
-
Enter the application name in Conditions.
-
Select the application to match it directly, or select Use Process Tree to match it anywhere in the process tree.
-
Repeat the search if the policy requires more than one application condition.

Process Tree: Use this option when the selected application may launch or participate in the activity through another process. Because it evaluates the entire process tree, test the policy carefully before enforcing it broadly.
Configure expiration and scheduling
Leave both settings off if the policy should remain continuously available. Enable either setting when the policy should be temporary or time-bound.
-
Enable Expire Policy and select the date and time after which the policy should no longer be active.
-
Enable Schedule Policy to define a recurring day, start time, and duration.
-
Select the plus icon to add another schedule period when required.

Timing check: A policy outside its configured schedule or past its expiration will not provide the expected active protection. Confirm the date, time, and duration before saving.
Configure Ringfencing actions
Enable only the restrictions the policy requires. Each enabled action displays additional controls for exceptions or allowed destinations.
| Action | Configuration |
|---|---|
| Interact with other applications | Restricts application-to-application interaction. Choose whether to allow everything except the listed applications or allow only the listed applications. |
| Access files | Restricts access to monitored files. Add paths that should be excluded from the restriction. |
| Change the registry | Restricts changes to monitored registry keys. Add registry paths that should be excluded. |
| Access the internet | Restricts network access. Add destinations to exclude by domain, IPv4 address, IPv6 address, or tag. |
| Access the clipboard | Displayed as Coming Soon and is not currently available for policy configuration. This will restrict clipboard access. |
Configure application interaction
-
Enable Restrict this application from interacting with other applications.
-
Select Allow All Except Below to permit application interaction except for the listed applications.
-
Select Allow Only the Below to restrict other interactions and permit only the listed applications.
-
Search for and add each required application.

Configure file and registry restrictions
-
Enable the required file or registry restriction.
-
Select the clicking here link to review or modify the monitored files, file extensions, or registry keys used by the restriction.
-
Enter each file, folder, or registry-path exception.
-
Select the plus icon to add additional exceptions.

Monitored resources: The file and registry restrictions use the configured monitored items. Verify that the paths, extensions, and registry keys you intend to protect are included in those settings.
Configure internet access
-
Enable Restrict this application from accessing the internet.
-
Select an exception type: Domain, IPv4, IPv6, or Tags.
-
Enter the exception value.
-
Select the plus icon to add the entry.
-
Repeat these steps for each required destination.

Configure notifications and enforcement
Use User Notification to determine whether users receive a message when the policy affects an action. The Portal displays Do not notify (Default) by default.
| Mode | Behavior |
|---|---|
| Inherit Status From Computer | Uses the current status of each applicable computer. |
| Secured Mode | Enforces the configured Ringfencing restrictions regardless of the computer's current maintenance mode. |
| Monitor Only Mode | Observes matched activity without blocking it and records a green deny in the Unified Audit so you can validate the policy's impact before enforcement. |
Recommended rollout: Start in Monitor Only Mode, review the resulting activity, add only the exceptions the application requires, and then change the policy to Inherit or Secured Mode.
After reviewing all conditions, actions, exceptions, timing, and enforcement settings, select Create.
Edit and manage policies
Edit an existing policy
-
From the Ringfencing policy list, select the policy you want to edit.
-
Review the read-only Policy ID.
-
Update the policy name, description, active state, order, device scope, or user scope as needed.
-
Select Next.

-
Add or remove conditions, change an application between a direct condition and a process-tree condition, update timing, or revise actions and exceptions.
-
Select Save.

Recommended rollout and maintenance
-
Begin with the smallest practical device and user groups.
-
Use a specific application condition when possible. Use broad or process-tree conditions only when the use case requires them.
-
Select Monitor Only Mode and exercise the application's normal workflows.
-
Review the resulting activity and add only the file, registry, application, or network exceptions required for normal operation.
-
Change the policy to Inherit or Secured Mode and validate it again.
-
Expand the policy scope gradually.
-
Review the policy after application updates or workflow changes.
-
Deactivate policies that you may need again. Delete a policy only when its configuration is no longer required.
Help Center