Advanced Setting - Temporary Approval Settings

5 min. readlast update: 09.04.2026

ThreatLocker has provided an Advanced Setting used to facilitate and configure the Temporary Approval Settings within an organization's environment.  

Temporary Approvals allow the organization to safely delegate authority of approvals while maintaining long-term control and consistency security within the organization. For more information on Temporary Approvals, please see the associated article: Temporary Approvals | ThreatLocker Help Center

Using this Advanced Setting, administrators can configure the default settings and options that users with the Temporary Approval permission can use when actioning Approval Requests, including:

  • Temporary policy duration
  • Approval scope, including whether a Temporary Approval can be applied to:
    • A computer
    • A group
    • The entire organization
  • Allowed approval methods
    • Prioritizing ThreatLocker Built-In Applications
    • Custom Application (File hash and custom rules)
    • Installation Mode
    • Learning Mode
  • Elevation settings

To start, navigate to the Advanced Settings page.

Select '+ New Setting' button to open the Create Settings sidebar.

  1. Under Setting Type, select Temporary Approval Settings.
  2. At this time, only Entire Organization can be selected in the Applies To dropdown. Administrators can select Applies To parameters when configuring Temporary Approval Settings under the Allowed Applies to Options section. 
  3.  Select to place this setting at the top or bottom of the Advanced Settings list. 

1. Temporary Policy Duration: This setting determines how long policies created through Temporary Approvals remain active before expiring. Administrators can set the duration from 1 hour to 30 days. Alternatively, administrators can select Do Not Expire to configure newly created Temporary Approval policies so they remain active indefinitely.

Note: Do Not Expire only applies to policies created after the setting is enabled. Already existing policies are not affected.

Allowed Applies To Options determines which scope options administrators can use when creating policies through Temporary Approvals. Enabling all three options, for example, allows the option for temporary policies to be applied at the Computer, Group, or Organization level.

  1.  Requesting Computer: Enable this setting to allow temporary policies to be Applied To a requesting computer. 
  2. Requesting Group: Enable this setting to allow temporary policies to be Applied to a specified requested group.
  3. Entire Organization: Enable this setting to allow temporary policies to be Applied To the Entire Organization.

Application Match Handling will allow the use of built-ins when creating new temporary approval policies.

  1. Allow Using Built-Ins: Enable this to allow temporary policies to use built-in application definitions.
  2. Require Built-In Application Match When Available: When enabled, this will require the use of a built-in application if it is available. This setting will supercede any options in the next section Allowed Temporary Approval Methods. 

Allowed Temporary Approval Methods will determine which methods of permission will be enabled to be applied to temporary approval policies.

  1. File Hash and Custom Rules: Enabling this setting will allow the option of approval through creating a new Custom Application using the file hash and custom rule criteria for the requested file.
  2. Installation Mode: Enabling this setting will allow the option of approval through a temporary Installation Mode.
    • When enabled, this will allow the use of Enable Triggered Installation Mode, which when enabled, will keep the machine in a secure state until the user attempts to run the approved file again on the system. This ensures the system is secure until the intended user is present and ready to install the required software.
      • Maximum Time to Hold Triggered Installation Mode Before the Request Expires will dictate how long the approved installation mode will last before the request expires, with times configurable anywhere from 1 hour - 7 days.
  3. Learning Mode: Enabling this setting will allow the option of approval through a temporary Learning Mode.

Under Allowed Temporary Approval Methods, only enabled settings are available to use as temporary approval policy creation methods. Note: When 'Require Built-In Application Match When Available' is enabled, these settings will be overridden in the case of a matching built-in application.

Elevation Settings will allow administrators to enable elevation with requests, allowing the addition of temporary elevation to policies made for temporary approvals.

  1. Allow Elevation for Known Applications: Enabling this setting will allow administrators to create temporary elevation for files that are recognized in known built-in and custom applications. 
  2. Allow Elevation for Unknown Applications: Enabling this setting will allow administrators to create temporary elevation for files that are not recognized as matching in known built-in and custom applications.

After enabling elevation, administrators can configure the duration of the elevation policy, anywhere from 1 hour - 30 days. The elevation policy will end when the temporary approval policy ends, even if the elevation policy duration exceeds that of the approval policy.

 

Once all settings are configured, click the blue 'Create' button in the bottom left corner of the sidebar to save all settings.

Press the Update Agents button to deploy all newly added settings.

Was this article helpful?