Beginning with Windows Agent 10.8.3, Advanced Settings includes an option to enable a Second Look check. This feature helps prevent legitimate applications from being unnecessarily blocked during brief timing gaps, such as immediately after an application update or system reboot, when updated application definitions may not yet be available on the endpoint.
When enabled, instead of blocking the application outright, ThreatLocker performs a “Second Look” to quickly re-evaluate the execution and determine whether it should be allowed, reducing user disruption and eliminating the need for manual approval requests in these scenarios.
To enable this 'Second Look' feature, navigate to the 'Advanced Settings' page and, within the 'Create Settings' sidebar, select the 'Second Look' option from the 'Setting Type' dropdown.

Ensure that you select the level to which this Advanced Setting will apply, as well as the 'Order By'.
Once this has been selected, a new switch will become available in the 'Parameters' section titled 'Enable Second Look'. Ensure this switch is turned on, then select the 'Create' button to create your new Advanced Setting.

After selecting 'Create', ensure that you choose the 'Update Agents' button at the top of the page to update ThreatLocker Agents with the added information.

Help Center