In the ThreatLocker Portal, Installation Mode is available in two areas. Installation Legacy is the classic Installation Mode, which catalogs all new files installed during the maintenance period for use by that computer or other computers with a Policy for that software. Installation Legacy is located in the 'Maintenance' tab of the 'Computer Details' sidebar. The Installation Mode found from the Approval Center's 'Permit Application' sidebar behaves differently due to the nature of the Approval Center, and can be used to enhance the flow of permitting applications in your organization. For further information on 'Installation Legacy', please refer to the following article:
Maintenance Modes | ThreatLocker Help Center

In the ‘Permit Application’ sidebar, a small section labeled ‘How do you want to allow this software?’ will populate when a user selects to either apply the requested software to a ‘New Install’ or update an existing application within the organization. One of these options is labeled ‘Temporarily Disable Protection for one hour and learn installed files with Installation Mode’. While this is still a version of Installation Mode, it behaves differently from ‘Legacy Installation’.

After selecting the 'Temporarily Disable Protection for one hour and learn installed files with Installation Mode' option, more options will populate below. A switch titled 'Start Installation Mode Upon File Execution' will populate. By default, this switch is on, and the 'Maximum Time to Hold Installation Mode' slider bar is set to 7 Days.
The 'Start Installation Mode Upon File Execution' switch means that Installation Mode will not be activated until the user executes the requested application. The 'Maximum Time to Hold Installation Mode' slider bar specifies the maximum time a user can delay executing the requested application before Installation Mode no longer applies. If a user tries to execute the application after this maximum time expires, the machine will not be placed in Installation Mode. If a user tries to execute the application within the time frame, Installation Mode will begin and be active for an hour after execution. If you opt to turn off the 'Start Installation Mode Upon File Execution' switch, Installation Mode will automatically be applied to the user's machine for one hour after the request is approved.
As of ThreatLocker Windows Agent 10.0, Installation Mode will no longer permit or learn executions from processes commonly exploited to launch malware, such as Windows Explorer, Command Line Tools, and Internet Browser processes. This was implemented to enhance the security of Installation Mode. Additionally, when users are in Installation Mode, attempting to install a second program's installer should block it and prevent it from being catalogued for future use within your organization.
Help Center