Skip to main content

How allowlisting events work

Allowlisting events are collected only when allowlisting is enabled, and the app control mode for the device is set to audit or rules.
  • Events are captured on Windows and macOS workstations when applications execute
  • Idemeum agent tracks binary executions for exe, msi, dmg, and pkg files
  • Allowlisting execution events are uploaded to idemeum cloud every 5 minutes

Allowlisting event structure

To access allowlisting events navigate to your admin portal and access ActivityEvents. You will be presented with the high level view of all events for your tenant. You can click on each event to expand the metadata for the event. You can immediately see if EPM and / or Allowlisting are enabled for your tenant. If you see Execution column populated for each event, then Allowlisting is enabled. If you see Elevation column populated for each event, then EPM is also enabled. \ Clean Shot 2026 05 25 At 12 50 16@2x