Said It Here

How to catch new software installs without false alarms

Routine patches, updates, and repairs constantly create new files, folders, or registry entries that look identical to new software, triggering false positives. At the same time, unsigned installers get blocked or missed entirely, leaving administrators struggling to reliably track what is actually being installed.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    using custom EDR detection rules
  2. 2
    deploying AppLocker policies to block unmanaged executables in user directories
  3. 3
    deploying Intune detection and remediation scripts
  4. 4
    spending hours troubleshooting system blocks to figure out why nothing launches

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/sysadmin1 person · September 2026

“The challenge is reliability: some applications are missed, while software updates, repairs, or version changes can generate false positives because they create new files, folders, or registry entries.”source ↗

Visible-AK · r/sysadmin · 24 upvotes
r/msp2 people · October 2026

“Most (or all) files are unsigned, blocked all over the place…”source ↗

cubic_sq · r/msp · 1 upvotes

“oof, unsigned installers are a special kind of headache. spent half a morning once trying to figure out why nothing would launch only to realize windows was silently blocking every dll”source ↗

Direct_Relief3675 · r/msp · 1 upvotes

Where this came up

People with this problem also raised