How to catch new software installs without false alarms
Routine patches, updates, and repairs constantly create new files, folders, or registry entries that look identical to new software, triggering false positives. At the same time, unsigned installers get blocked or missed entirely, leaving administrators struggling to reliably track what is actually being installed.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1using custom EDR detection rules
- 2deploying AppLocker policies to block unmanaged executables in user directories
- 3deploying Intune detection and remediation scripts
- 4spending hours troubleshooting system blocks to figure out why nothing launches
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“The challenge is reliability: some applications are missed, while software updates, repairs, or version changes can generate false positives because they create new files, folders, or registry entries.”source ↗
“Most (or all) files are unsigned, blocked all over the place…”source ↗
“oof, unsigned installers are a special kind of headache. spent half a morning once trying to figure out why nothing would launch only to realize windows was silently blocking every dll”source ↗
Where this came up
People with this problem also raised
- 3Why does software installation fail on secure systems?
- 3Unauthorized third-party software integrations on client networks
- 4Vendor forced us from perpetual licenses to a subscription
- 14Why am I seeing ads in software I already paid for?
- 7How to revert unwanted software UI and design updates
- 3How to audit unused CRM customizations when the original builder leaves