S
Small-Business (50 or fewer emp.)
"ThreatLocker's Default-Deny App Control Delivers Powerful Zero-Trust Protection"
For an MSSP, the standard stack includes EDR, Managed SOC, AV, email protection, training, ITDR, etc. Application control is rarely seen. ThreatLocker provides that with default deny to block unapproved apps, enforcing zero-trust. From a technician's view, that's huge. Controlling app execution blocks malware, data loss, and other risks. Management can be difficult at times because learning mode allowlists everything on a computer. The best approach is to create a baseline computer with only approved software and use that for policies. Going forward, limiting learning mode is a good long-term strategy. The different modules provide enhanced protection for customers. It integrates nicely with our PSA and offers APIs for integration with other products and MCP protocols. It can be hard to manage without regular audits. Policies can grow out of control as team members change them. The cyber hero support has resources to automate some things, but I ended up writing an MCP tool to integrate with ThreatLocker that automates a lot of this using Claude or other AI agents. Application whitelisting is huge. Many organizations don't consider it and end up allowing more apps than needed. Elevation control also provides a unique solution to control admin rights while allowing users to escalate specific apps. Though I can't speak to costs, these modules save me tons of time. I don't worry about users running ransomware as admin.
"Exactly What We Needed"
Deny by default, with an easy-to-manage console. It gives us peace of mind beyond any other security tool. ThreatLocker offers better device control in ways our existing EDR doesn't catch until something happens—point at which it's already time to react. With ThreatLocker, we can allow what's needed to run while preventing it from going beyond intended business use. Integration with ServiceNow helps by automatically creating a ticket for app requests. Support is amazing: we get nearly instant access to a cyberhero for quick questions, or escalation for more complex issues. It's hard to say what I don't like, because it's more about not knowing everything about the product. I can use it for my needs, but a deeper understanding isn't possible since it's not the only system I use. It blocks unwanted actions that could lead to compromise. It also helps close the gaps between EDR, anti-ransomware, and NDR, making coverage more connected.
"ThreatLocker: Intuitive, High-Performance Protection with Solid Onboarding"
ThreatLocker has a clean, easy-to-navigate interface that simplifies managing complex security policies. It integrates well with Windows environments and other security tools, with strong performance and minimal endpoint impact. Although pricing may be higher than traditional AV, its proactive approach to preventing ransomware and unauthorized software can offer excellent ROI by reducing incidents and admin overhead. Onboarding is well-supported with responsive customer service and helpful deployment guidance. Its intelligent policy automation and learning mode streamline implementation, making Zero Trust practical for all organization sizes. A major drawback is the need for careful planning and ongoing policy management. The default-deny approach has a learning curve for admins, and overly restrictive policies can block legitimate apps until exceptions are set. While the interface is intuitive, managing complex environments with many custom apps can be time-consuming. Integrations with specialized or legacy software may need extra testing and tuning. Pricing can be higher than other endpoint security products, making it a bigger investment for small businesses. Even with responsive support, implementation requires time and resources, and AI-assisted learning aids policy creation but doesn't replace admin oversight. ThreatLocker has addressed key challenges by reducing ransomware, malware, and unauthorized software execution via default-deny. It has improved endpoint security by ensuring only approved apps run, while Ringfencing and Elevation Control enforce least privilege and limit impact of compromised apps.
"Zero Trust Security with Complete Control and Ease of Use"
ThreatLocker is very user-friendly, especially the unified audit for checking transactions like executions on devices. The easy-to-view window showing what's been blocked and denied helps us understand our environment at a granular level. It also gives us immediate control in emergencies, making us feel safe. Maybe custom reporting could have more options. We haven't fully explored additional features. Patch management seems useful, but I'm not sure if ThreatLocker is the best tool for that. I use it for full control over applications on managed endpoints to prevent unauthorized executables. It ensures specific policy management and quick action during emergencies while offering an easy audit for monitoring transactions.
M
Mid-Market (51-1000 emp.)
"ThreatLocker Offers a Solid and Secure 'Allow-Only' Security Layer"
ThreatLocker provides a robust security layer that's crucial in our stack. The concept of blocking everything and then permitting only what users truly need makes IT infrastructure much safer than trying to detect and block every malicious action. Sometimes with application updates, ThreatLocker blocks the update files. Due to how many apps update, this can require complex policies to allow updates while still blocking malicious actions. It has given us better control over built-in Windows tools and other pre-installed apps that are often underused. For example, we can restrict PowerShell to specific user groups, or use Ringfencing to allow it but block internet or network access. This enables centrally controlled tool sets that are often exploited by attackers, while allowing legitimate secure use.
I
Information Technology Field Engineer / Compliance Analyst
"Comprehensive Zero Trust Protection with Robust Application Control"
What I appreciate most is the control and visibility it offers. Application Allowlisting blocks unauthorized or unknown software, and Ringfencing limits what approved apps can access or communicate with. It moves us beyond traditional antivirus by enforcing a true least-privilege, Zero Trust approach without causing unnecessary user disruption. The main downside is the administrative overhead, especially during initial learning and policy tuning. Legitimate apps, updates, scripts, and installers can be blocked until reviewed and approved, adding extra work for a small IT team. The platform is powerful, but the interface and policy structure can be complex, and troubleshooting block reasons isn't always straightforward. Once properly tuned, it works well, but it needs ongoing attention to avoid user disruption. ThreatLocker helps prevent unauthorized software, malicious executables, scripts, and PUAs from running. It also restricts approved app access via Ringfencing and helps manage temporary admin privileges. The biggest benefit is reducing our attack surface and stopping threats that traditional AV misses, while giving IT better visibility and control.
"Effortless Zero-Trust Security Minimizes Risk and Keeps Systems Operational"
Reducing security risk. Software vulnerabilities are lessened with no admins, and supply chain issues are mostly mitigated on the application/software side. User systems just work now, and the old habit of reloading Windows rarely happens. Plus, elevating programs for certain apps gives users the ability to perform tasks. We see improved system performance and happy clients. Deploying ThreatLocker is quite simple, and it integrates well. The platform is intuitive and easy to use; unified audit aids not just ThreatLocker but also general system and logging needs. Pricing is competitive and lower than other platforms, making it an easy sell. Cyber Heros responds quickly and often helps or handles the rule. I always say it's a love-hate relationship. The only downside is how Zero Trust works. When applications change and lack built-in rules or alter their interaction with the computer, you have to do some work or relearn the app. It's manageable. Explaining to users and clients why usually helps. Cyber hero auto approval can help if you have a small team or struggle with the platform. Not having an incident. Clients/users trust IT to keep them safe. We haven't had any ransomware or similar events; they've all been stopped. Users have clicked on files and links that tried to execute commands, but ThreatLocker blocked it every time. The ability to elevate apps like UPS to run with more permissions so users can update rates and programs without having permissions is valuable.
D
Director of Business Operations | Controller
"Effective Security Tool That Requires Proactive Management"
The strongest feature is application allowlisting. When properly set up, it effectively stops unauthorized programs from running. I also value the endpoint visibility it offers. However, reaching that point requires considerable effort, and some aspects—like learning mode—didn't perform as anticipated. It's a robust solution but demands a significant time investment for effective management. The main challenge is the time needed to manage the platform. Learning mode underperformed, so creating and maintaining policies required much more manual work than expected. False positives and application approvals can add to the administrative burden, especially in frequently changing environments. ThreatLocker is a powerful security tool, but organizations should be ready to spend time on policy tuning and ongoing management to fully benefit. It helps reduce ransomware, unauthorized software, and malicious activity by blocking non-approved applications. This gives us far greater control over our endpoints than traditional antivirus. For us and our clients, that means better security, clearer insight into what's running, and confidence that unexpected software won't execute without our knowledge. Although ongoing policy management is needed, the added protection has been a valuable part of our security strategy.
"Intuitive Interface, Speedy Portal, and Outstanding Support"
The platform's UI is intuitive and straightforward to navigate. It's always clear which module I'm in, how to access support, and how to roll out new policies. It integrates seamlessly with our RMM and ticketing system, making it easy to approve requests and manage software updates. The portal is responsive and fast. The support is top-notch, and the CyberHeros consistently provide answers to my queries. ThreatLocker does seem to cause some slowdown on older hardware, especially machines with limited resources. It's expected, but we have to monitor that for clients using older equipment. ThreatLocker helps us maintain control over the applications installed on client computers. We can block malicious or unwanted software before installation, saving us time on cleanup and investigation later. This is a significant value-add and helps justify the cost of ThreatLocker.
"Streamlined and Intuitive with Exceptional Support from Cyber Heroes"
Overall, this is an excellent tool for what it's designed to do. Once you grasp its purpose, it becomes straightforward to use, and the assistance from the Cyber Heroes truly makes a difference. The software operates efficiently, and we haven't observed any performance or agent issues on our PCs. The primary hurdle we've faced is grasping the policy setup and how the components interact. That seems more like a learning curve due to the platform's extensive capabilities rather than a flaw in the product. As you start to comprehend the underlying logic, the structure becomes clearer; it's mainly about getting accustomed to it and understanding its intent. Occasionally, we encounter complex configurations where a specific policy feature would make things easier, but typically we consult the cyber heroes and manage to work it out. As an MSP, we deal with clients who struggle to manage employee work habits, especially in PHI and HIPAA environments. ThreatLocker plays a crucial role in our solution. Managing storage policies and applications through ThreatLocker is highly beneficial and simpler than modifying registry entries or using other blockers. This is particularly useful when we need to allow something temporarily—it's just a few clicks in the portal, without having to bypass GPOs, wait for updates, and then revert security groups.