We use ThreatLocker Allowlisting to control inventory and manage software. We want to make sure that we know which software is being used on our client computers and that we are only allowing approved software to run. This is in line with the principle of least privilege, which ensures that users are only allowed to do the things they need to do and not the things they don't. This is especially important for shared-use computers and different environments where users on the same computer may have different access levels.
COO at OverDrive IT
We get good visibility, as well as our helpdesk tickets, and time is reduced
Pros and Cons
- "The most valuable feature is selective elevation, which allows elevating an individual process to admin privilege without granting admin privilege to that user, which has been by far the most useful feature outside of the overall solution itself."
- "ThreatLocker Allowlisting needs to improve its user interface and overall workflow."
What is our primary use case?
How has it helped my organization?
The visibility into software approval requests of end users is easy. We not only have approval requests pushed directly into the platform, but we also have a ticket opened in our ticketing system. As the manager, I can run reports to see what requests are coming in from client organizations and how my technicians are handling them. This makes my life easier from a managerial perspective.
The combination of ThreatLocker and Ringfencing is excellent for blocking unknown threats and attacks. For example, we can ensure that all software stays within its designated sandbox. This means that I can run the PowerShell scripts from our RMM software, but nothing else can run the PowerShell scripts. With Ringfencing, we can say, "Allow this to run, but not that," or "Allow this website to be accessed to download an installer, but don't allow other websites to be accessed." Other use cases for Ringfencing include selective elevation of a process. For example, if a user needs to run QuickBooks and is elevated to an administrator to do so, then all privileged processes will also be elevated. However, with Ringfencing, we can prevent QuickBooks from opening PowerShell or anything else that it is not supposed to open. This helps to keep us safe and prevents unknown threats from exploiting compromised privileged processes.
In line with the textbook definition of a zero-trust model, every request must be approved. This can create some tension with clients, so it is important to get their buy-in on the process. With ThreatLocker's learning mode, we can make the approval process invisible to clients for the most part. We manually select which requests to approve and which to deny. By the time we set ThreatLocker to enforce everything, we have a good baseline of what is allowed and what is not. We have also communicated everything to the clients and found procedural ways to reduce friction.
ThreatLocker Allowlisting can help to reduce helpdesk tickets. On the one hand, we do receive approval requests with some regularity. However, on the other hand, overall tickets are reduced because we no longer have everyone trying to install iTunes or wondering why they're getting pop-ups in their browser because they have three different browser add-ons for coupon clippers that are laced with malware. After all, with ThreatLocker, users are not allowed to install these programs, to begin with, which reduces the tickets we would get after they've been installed because they're unpublished installations that any standard user could complete. The net result is an overall reduction in tickets, although there are some tickets required to manage the approvals.
ThreatLocker Allowlisting has saved our helpdesk around a 15 percent reduction in overall tickets. With the average handle time for a ticket being 14 minutes, if I have 100 tickets in a month, each one will take 14 minutes, for a total of 1,400 minutes per month.
What is most valuable?
The most valuable feature is selective elevation, which allows elevating an individual process to admin privilege without granting admin privilege to that user, which has been by far the most useful feature outside of the overall solution itself.
What needs improvement?
Approving or denying requests using the software can be more difficult to do correctly. Overall, it is easy to use, but it is not the easiest in the world to get right. There are some nuances and things that we need to understand.
ThreatLocker Allowlisting needs to improve its user interface and overall workflow. The UI looks very dated and is challenging to navigate, and we spent more time training technicians on how to interact with ThreatLocker than on what to do with it. The user experience needs a lot of work, but their beta portal is solving a lot of that. If I had to pick any lingering difficulty, it would be the learning curve to grasp how ThreatLocker manages what is allowed and the details around that.
Buyer's Guide
ThreatLocker Zero Trust Platform
April 2026
Learn what your peers think about ThreatLocker Zero Trust Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
892,487 professionals have used our research since 2012.
For how long have I used the solution?
I have been using ThreatLocker Allowlisting for almost two years.
What do I think about the stability of the solution?
We experienced some delays with our cloud agent. For example, when we changed a policy, it would take five minutes for the agent to receive the change. Or, we would tell the agent to enter a specific mode, and it would take five minutes for the agent to comply. This caused some delays in our ability to deliver services. However, the cloud provider has eliminated this issue. We now typically wait no more than thirty seconds for the agent to respond to our requests. This was a problem when we first started using the cloud agent, but it hasn't been a problem for about six months now.
What do I think about the scalability of the solution?
We have had no scalability issues whatsoever, even though our largest environment is only about 75 endpoints. We are not working at the same scale as much larger companies, but for our size, ThreatLocker has been perfectly scalable. Whether I am deploying to one person or ten people, the same script is pushed out by the RMM and everything loads up in ThreatLocker within a matter of minutes.
How are customer service and support?
The technical support team at ThreatLocker is incredibly experienced and knowledgeable. I especially value two things about interacting with them. I never have to wait long for a response. As chief operating officer, if a problem reaches my desk, it means that everyone below me has already tried and failed to solve it, or they simply didn't want to get ThreatLocker support involved. Since I have the most experience in-house, I'm usually the one who engages with ThreatLocker support. When I do, I never have to wait long to speak to someone who knows what they're doing. I always get escalated to the right level technician, even if I'm initially connected with more junior tech. ThreatLocker doesn't waste time walking me through scripts, procedures, and processes. Instead, they escalate my issue to the right person immediately so that they can help me solve whatever creative problem we're facing.
Which solution did I use previously and why did I switch?
We had some experience with Microsoft's AppLocker, but managing it required too much manual effort for our small team that required a dedicated full-time employee. ThreatLocker Allowlisting is much easier to manage.
How was the initial setup?
The initial deployment was straightforward. ThreatLocker provided the script to use in our RMM software. To deploy the software, we made some tweaks to accommodate our environment. We were then able to push out the agent in an entirely automated fashion. We had three people involved on our end, but it could have been done by a single person. We divided responsibilities to bring the product to market faster.
What about the implementation team?
The implementation was completed in-house with the support of the ThreatLocker team.
What was our ROI?
In addition to the overall time savings, there are also quantifiable costs associated with the number of malware attacks that have been stopped by ThreatLocker. I can think of at least four or five instances where an executable file was blocked by ThreatLocker before it could be detected by SentinelOne or any of the other security solutions on the machine. It is difficult to say definitively whether SentinelOne would have detected these files after execution, but I do know that ThreatLocker has helped to improve our productivity and our clients' productivity by preventing users from installing unauthorized software, such as iTunes on work computers or Spotify on protected machines. By limiting users to only approved software, ThreatLocker has also made our jobs easier as IT service providers, as we no longer have to spend time hunting down unauthorized software, uninstalling things, or remediating malware, bloatware, adware, etc. As a result, we are dealing with far fewer rogue browser extensions, which has led to a reduction in tickets and overall management overhead.
We realized the benefits of ThreatLocker Allowlisting after six months of use. This was because we needed to become familiar with the product, build our baselines, and understand how it worked. We also needed to establish routines, build workflows, train our technicians, and educate our clients on how to interact with the software. By the six-month mark, we began to see a return on investment, and it was fully realized by the one-year mark.
What's my experience with pricing, setup cost, and licensing?
The price of ThreatLocker Allowlisting is reasonable in the market, but it is not fantastic. It is also much less expensive than some other products we use.
Which other solutions did I evaluate?
We considered Auto Elevate from Cyberfox and Microsoft's AppLocker, but managing Microsoft's AppLocker would have required too much manual effort for our small team which would require a dedicated full-time employee. ThreatLocker Allowlisting is much easier to manage. ThreatLocker Allowlisting is a more comprehensive solution, and we liked the way that ThreatLocker said they would support us better than the other companies. With the other companies, it was more of a traditional support model, but with ThreatLocker, we have an average wait time of 30 seconds on our support chat. In the year and a half, almost two years, that we've been with ThreatLocker, this has always been the case. We've never had to wait more than 30 minutes to get a live human being who is an expert on ThreatLocker. If they can't solve the problem, they'll escalate it to someone who can. Beyond that, they stand behind their product. Because it's such a complicated product, and we're a small company, this was all the difference to us. We knew that if we had problems, we would have their team to lean on for help, and they've stood behind their product.
What other advice do I have?
I would rate ThreatLocker Allowlisting nine out of ten. ThreatLocker Allowlisting is not a perfect product, but they do a fantastic job of continuing to improve it and make it more approachable.
There are management and overhead costs, as well as maintenance costs associated with changing or updating the lists. There is also some limited maintenance required as programs and hashes change. Additionally, we need to make some updates to properly maintain the lists, consolidate policies, and so on.
Try ThreatLocker risk-free and work with their team. They can make their complex product more approachable so that users can see its benefits and capabilities.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner Reseller
Project manager at a tech services company with 1-10 employees
Application control on clients' devices is much easier
Pros and Cons
- "The solution has made knowing and managing what is running on our clients' devices much easier for us. We know they cannot run what they are not supposed to run."
- "The customer service is amazing."
- "From my point of view, logging could be improved. Logging should be easier."
- "From my point of view, logging could be improved. Logging should be easier."
What is our primary use case?
We use the application for whitelisting, elevation, and ringfencing purposes.
How has it helped my organization?
The coolest part is that we do not need local admins anymore. It was a great switch to take away the local admin rights.
The benefits include a little bit more relaxation and peace of mind because we have control over what is going on.
ThreatLocker Zero Trust Endpoint Protection Platform has helped our organization save on operational costs, but I do not have the metrics.
ThreatLocker Zero Trust Endpoint Protection Platform is good at blocking access to unauthorized applications. It only allows running applications that are allowed. If there is anything new to the environment, it is not going to run.
ThreatLocker Zero Trust Endpoint Protection Platform has helped reduce help desk tickets.
ThreatLocker Zero Trust Endpoint Protection Platform has helped free up our IT team’s time for other projects or tasks.
What is most valuable?
The solution has made knowing and managing what is running on our clients' devices much easier for us. We know they cannot run what they are not supposed to run. We have peace of mind because we are aware of what is happening if anything new tries to come into the workstation.
It is pretty easy to use. The UI is pretty straightforward, especially after the upgrade. I like it more than what it was previously. There is also a phone app. When a user sends a request, we can see it on our phones. It makes our work a bit easier.
What needs improvement?
From my point of view, logging could be improved. Logging should be easier. Sometimes, we have noticed that there is too much logging that can apply to different types of software.
For how long have I used the solution?
We have been using the solution since the end of 2021.
How are customer service and support?
The customer service is amazing. I would rate it a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use a solution of this type before.
What other advice do I have?
The platform is great. I would rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
ThreatLocker Zero Trust Platform
April 2026
Learn what your peers think about ThreatLocker Zero Trust Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
892,487 professionals have used our research since 2012.
Advanced IT Specialist at Robinson tech
ThreatLocker Allowlisting
Pros and Cons
- "The biggest improvement has been knowing that something unauthorized isn't going to get installed on anyone’s machines."
- "There are some times when applications get submitted, the hashes don't really line up."
What is our primary use case?
We use it over our 31 clients, and twelve hundred devices. We use it over all of our Windows workstations and Mac workstations to prevent unauthorized installs and downloads of applications.
How has it helped my organization?
Allow Listing is great. The biggest improvement has been knowing that something unauthorized isn't going to get installed on anyone’s machines. Even if somebody did manage to get into their systems, they wouldn't be able to do anything without us knowing about it.
What is most valuable?
Definitely, the allowed listing and the Zero Trust platform are the most useful aspects of the solution.
It is very easy for an administrator to approve and deny requests. So easy in fact that I have given it to a majority of our client's main point of contact, where they are able to approve them, whether it's via their mobile cell phone or logging into the portal on their computers.
The overall visibility into software approval requests of end users is very good. We can see everything that we need to see including the application path, the user that requested it, and the computer host name. When it's approved on the workstation endpoint, it pops up with a text box saying, “Hey, this has been approved. Click here to install your application.”
We allow listing with the ring-fencing. We do implement that when needed. For example, for Word and Excel, there's no need for those to talk out to PowerShell and command prompt, so we do have those ring-fenced where they cannot speak to that.
Their combination for blocking unknown threats on attacks is good. If it's not something we've previously approved, it does get locked every time. Sometimes it even gets in the way of our day-to-day, which is good. It's what we wanted it to do. It does its job a little too well.
It is great for establishing trust for every access request no matter where it comes from. Whether the user is an admin or not, they all still have to get their software approved. Once it has been approved, it makes it easy for everyone as they're able to install it on their own without approval again.
It helped reduce our organization's help desk tickets. We haven't had nearly as many clients submitting tickets, say, for example, McAfee installing when they're trying to install Adobe. We approve Adobe and we don't install the McAfee install. That will get in the way a lot, and we have seen a major reduction in tickets such as those.
Being able to not have to worry about what everyone's installing all the time has definitely improved our ability to focus our attention on other projects.
What needs improvement?
The new portal that they just released took care of a whole lot of improvements.
There are some times when applications get submitted, and the hashes don't really line up. It would be excellent if there was a way for the hashes to point to a known application. The biggest example I have is probably web browser plug-ins. Those come up and they look very gross and don't give you very much information at all so you have to go to Google and look up what they are.
For how long have I used the solution?
I've used the solution since February of 2022. It's been about a year and eight months.
What do I think about the stability of the solution?
The stability is very good. I have not seen any outages.
What do I think about the scalability of the solution?
It is deployed to every single endpoint that we currently manage Windows-wise and then a majority that we manage Mac-wise. We currently have 712 computers being monitored.
They continue to grow. They produce Mac releases, Windows updates, and patches.
How are customer service and support?
Technical support is great, they get to the requests before we can go through them.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
The initial setup was pretty straightforward to the point where the documentation was good enough that I could have a level one brand new green tech to handle it and be confident.
Deploying it through DATTO RMM is probably the biggest way we deploy and then we might have a manual agent deployment if necessary.
We utilized two people for the deployment.
It does require maintenance. We'll do monthly check-ins with Threat Locker and an account manager to go over just to see what we can improve.
What about the implementation team?
The deployment was handled in-house.
What was our ROI?
We have seen an ROI via the amount of hours we save not having to worry about looking at different applications getting installed. We also don't have to worry about clients getting ransomware attacks and things like that, so that has helped us a lot.
What's my experience with pricing, setup cost, and licensing?
Pricing is a little high, however, you get what you pay for.
Which other solutions did I evaluate?
We did look at other solutions before choosing this solution.
What other advice do I have?
We have noted time to value. It's easier than ever to approve very quickly rather than having to talk with clients to see what they are trying to install. The virtual deployment allows you to see what's going on super quick. The onboarding was pretty extensive. It took us a solid six to eight months before seeing time to value.
I'd rate the solution eight out of ten.
I'd advise others that if they use the product they have lots of peace of mind and sleep better knowing your clients are better protected.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Managing Partner at ICS cyber management
Easy to use with great features and helpful support
Pros and Cons
- "Every single feature has been invaluable."
- "The reporting could be improved."
What is our primary use case?
We use the solution as a zero-trust application. We put it on all of our customer machines. We're a security operations company that performs, security, and compliance services for different companies. For all of the companies that we support, we put Threat Locker on. As a zero-trust application, we know the only applications that we've approved are going to be able to function in those customer environments and be that much more secure.
How has it helped my organization?
The solution has improved the organization by making sure every customer is more secure. It doesn't allow anything we don't know or haven't approved to run on any machine.
What is most valuable?
Every single feature has been invaluable.
It's very easy for administrators to approve or deny requests using the cloud listing.
You get good visibility with this product - more than anything else on the market. Threat Locker is amazing for providing that visibility. I know every single thing about a request due to the way they process it and the data they show us. We have the ability to see everything that an application is actually going to do.
We do use ring-fencing for every customer. It's great at blocking known and unknown threats. It's the only thing that I know, without a doubt, will do the job. I know that if I haven't made a policy for something, it still will not let it run.
It's the best, period, for allowing us to assess allowed listings and establishing trust for every request.
Overall, the solution has helped us consolidate applications and tools. It's definitely helped reduce unnecessary software.
We've been able to reduce operating costs based on tool consolidation. However, it would be a difficult number to calculate.
What needs improvement?
The reporting could be improved. They're already working on some things with that. That said, as far as its functionality, its stability, and my trust level in it, I honestly don't know how it could get better.
For how long have I used the solution?
We've been using the solution for two years.
What do I think about the stability of the solution?
We have never had a problem with stability.
What do I think about the scalability of the solution?
We have 2500 machines. There are different customers using it. Some are government entities and some are public. Organizations range from very small to extremely large.
The solution is 100% scalable.
How are customer service and support?
Technical support is the best in the business.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
While we have used different solutions, nothing compared to what this solution provides.
How was the initial setup?
We have different deployment models for each customer. It's an application that I install on every machine in my customer's environment.
The deployment is very straightforward. In a couple of clicks, you are finished.
The implementation depends on the customer. For some customers, we install to the machine. Others, we push it out. Some also have scripting so that if you have an RMM tool, It's an easy little script that you push out via the RMM tool or even as a PowerShell script. Their deployment is something else that sets them apart since it's so easy to get it on either one machine or a mass deployment of machines.
You only need one person for deployment.
The product doesn't require maintenance. Everything is handled on the back end.
What about the implementation team?
We used a third party to deploy the solution. We don't support the machine it's installed on. We only do security. We use multiple third parties.
What was our ROI?
We have 100% witnessed an ROI. It sells my service.
What's my experience with pricing, setup cost, and licensing?
The pricing is correct.
Which other solutions did I evaluate?
We did evaluate other options. We've tested everything from top to bottom. For example, we looked at Fortigate and Palo Alto as well as some options from Cisco and Microsoft. None offered the same level of detail.
What other advice do I have?
We're a partner.
We have witnessed an immediate time to value using this solution.
I'd rate the solution ten out of ten. I'd advise others to pull the trigger and get it. They'll love it. The solution provides a level of security that is unmatched.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer:
CEO at Atlantic Data Team
Automatically whitelists everything that runs during Learning Mode, making go-live much easier
Pros and Cons
- "The great thing is that if you get a malicious email and you try to run something, ThreatLocker is not going to let it do anything. It is not going to let anything infect your network."
- "Something we have come up against a couple of times is that we have two clients that are software developers. They create software that doesn't have digital signatures and that's not easy to categorize or whitelist with ThreatLocker. We have to go in and make custom rules to allow them to do their work and to be protected from malicious threats."
What is our primary use case?
Every single endpoint and everything that we manage has ThreatLocker on it. We saw how valuable it was, and we went to every one of our customers and told them either we install this on your PCs or we have to just part ways as friends.
We use the basic ThreatLocker product for Zero Trust and we have one client where we're using Elevation Control.
How has it helped my organization?
The big benefit is that I can sleep better.
What is most valuable?
The fact that it stops anything that we don't want from running is the biggest thing. It's also very easy for administrators to physically approve or deny requests. The difficulty is in determining whether they should approve or deny.
We use ThreatLocker Allowlisting with Ringfencing and I would give ThreatLocker a 10 out of 10 on pretty much everything. The establishing of trust for every access request, no matter where it comes from, is the way of the future.
What needs improvement?
Something we have come up against a couple of times is that we have two clients that are software developers. They create software that doesn't have digital signatures and that's not easy to categorize or whitelist with ThreatLocker. We have to go in and make custom rules to allow them to do their work and be protected from malicious threats. We've gotten really good at it.
ThreatLocker's support has been absolutely wonderful, you get somebody there very quickly. The danger is when one of my techs calls in with a question about some rules, and he reaches somebody on the other end that has about the same level of technical ability—and I know it says "cyber hero in training"—my concern would be that if the people on both ends of a call are inexperienced, they could inadvertently create a rule that opens up too much. So if I have a concern about that, I usually just get on the call myself.
There is one other big thing. If I want to install a piece of software, and I want everybody in the organization to be able to install that software subsequently, when I put a computer in Learning Mode that disables ThreatLocker. I then install the software and Learning Mode tells ThreatLocker everything that the software just did.
Every now and then, ThreatLocker will block something, like a web browser update or a web browser plug-in update, and some of that is just not important so I don't worry about whitelisting it. It keeps trying to run, and ThreatLocker keeps causing it to not run, which is okay.
But when I turn on ThreatLocker Learning Mode to install some other piece of software, if there is something that has been trying to install for weeks and hasn't been able, and then attempts to install while ThreatLocker is in Learning Mode, it will allow it to happen.
To summarize, when you put ThreatLocker in Learning Mode, if there's something else that is trying to run at the same time as whatever it is that you're trying to install, it will be allowed to run.
For how long have I used the solution?
I've been using ThreatLocker Allowlisting for two or three years.
What do I think about the stability of the solution?
It's completely stable, other than every now and then an agent will stop phoning home and somebody will have to intervene, but that's very rare.
What do I think about the scalability of the solution?
Scaling is super easy. The great thing is that you can deploy policies to other computers. That means I can make a policy in the parent company, which is mine, and I can then deploy it to all computers.
We have 380 users of ThreatLocker from our company, but I just merged my company with another company so the total across all of our endpoints is about 1,300.
How are customer service and support?
Their tech support is the best I have ever come across.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We never used a Zero Trust solution before ThreatLocker. We use a next-gen antivirus product called SentinelOne. We had deployed that on all PCs and servers. When ThreatLocker came up, it was so valuable and thorough, that we replaced SentinelOne with ThreatLocker across the board.
How was the initial setup?
In the initial deployment, which I did completely, it was a little difficult to understand how the policies and the rules interact together, at first. But it's a complicated subject, so it took a while for us to grasp all of it. And it took even longer to grasp the finer points of it. But they have very good training and their support is absolutely unparalleled, just great. I've never waited longer than a minute for somebody to get online.
ThreatLocker is a cloud solution. We install it on the local machines but it reports back to the portal, which is in the cloud. As a deployment model, that's perfectly fine. It's very easy to roll out. We use a little piece of software called PDQ Deploy and we can push it out to all machines at once. We can also use our RMM solution, which is ConnectWise, to push it out. It's very easy.
Once I understood it a little, I brought on two techs and they sat with me while we did deployments. Periodically, if I have figured out a different way to do rules, we do in-house training where I show my guys what I'm doing and why I'm doing it, and we document it and write down the steps. Now, those guys know how to install ThreatLocker and deploy it.
It doesn't really require any maintenance. Every now and then we have an agent that's not phoning home, but not often.
What about the implementation team?
I did it myself but had help from Colin Ellis who works for ThreatLocker. He helped us take everything out of Learning Mode and make sure that there was nothing malicious that we were missing that might be allowed to run. He is one of the smartest guys I have ever met.
What was our ROI?
We have very much seen a return on our investment. We have been around as a company for a long time, for fourteen years. And it was really only recently that we figured out what we were worth and what we should be charging. But it's very hard to go back to a customer that you've had for many years and say, "Hey, you've been paying $45 a month for a long time and we're now charging $120 a month.
However, if we can come in and say, "Look, this is the best tool on the market for keeping you safe, and we feel so strongly about it that we insist that you install it or we just can't work with you anymore." We were able to charge another $25 to $30 a month for that product. We had to explain exactly what it did and how it worked, but we were able to significantly increase our recurring revenue by adding that product because the pricing is reasonable and, when you present it correctly to the customer, it is so valuable that you can charge another $25 to $30 a month, per machine.
I saw the value in it before we deployed it, from the very first presentation I saw about it. I was intrigued enough that I went to the booth, once we were on break at the trade show, and started talking to people there. It was just obvious what its value was going to be. It really does allow me to sleep, in every sense of the word.
It felt as if we were in a losing battle, and then ThreatLocker came along and it
felt like we had a chance. As an industry, we're up against nation-states. All of us as little MSPs are up against people who have endless resources and money and who are either sponsored by their governments or organized crime.
What's my experience with pricing, setup cost, and licensing?
The pricing works fine for me. It's very reasonably priced.
Which other solutions did I evaluate?
We do have other antivirus products running at the same time. We have Webroot and, in some cases, we have Windows Defender running at the same time. But ThreatLocker just catches everything so we don't have to worry about antivirus signatures being up to date.
We also evaluate other products all the time. Komodo was one as well as something from Trend Micro.
It was obvious, right from the get-go, that ThreatLocker was the most efficient and effective way to stop malware from running. The thing that makes ThreatLocker different and better than all other Zero Trust solutions that I've ever heard of—and I've never tried another one, but I've heard the horror stories —happens in the beginning by turning on Learning Mode and letting that run for three to four weeks. That means that when you turn ThreatLocker on by taking it out of Learning Mode, all of the things that have been running during that time are whitelisted and they're allowed to run.
In the olden days, when you turned on Zero Trust, it blocked everything. And then we had what we used to call the "scream test." We would wait for people to start screaming and then go wherever the screaming was, figure out what was being blocked, and unblock it. But that was horrible because even if you unblocked one file, that one file might be trying to call two or three other files to run and make that software work. And if you don't whitelist those too, you still get problems. So that's the upside of Learning Mode. ThreatLocker takes that initial pain completely out of the equation.
What other advice do I have?
In terms of reducing help desk tickets, at first, it's something of a wash. When you first install ThreatLocker and make it active after a certain time in Learning Mode, the tickets are going to go up because people are going to have software, over the next 60 days or so, that they can't run because it didn't happen to run during the Learning Mode period. So for the first 45 to 60 days, we probably had a small increase in tickets because we had to whitelist things. But since then, it has been significantly better. Once we got all the rules sorted out so that people could do whatever work they need to do, and we still keep them protected, we had very little background noise. There is a ticket increase at first, which is normal and expected. There's no way that you're going to turn this on and have everything be perfect every time. But after that, the tickets go down significantly.
Every now and then, we'll get a call from someone who has gotten a phishing email, and they're suspicious of it. They'll call us and ask us to look at it. But the great thing is that if you get a malicious email and you try to run something, ThreatLocker is not going to let it do anything. It is not going to let anything infect your network.
If somebody takes a look at ThreatLocker and doesn't understand what it can do for them, I don't know if that person should be in the IT business. It sounds like I'm sitting here worshiping at the altar of ThreatLocker, but that's not entirely true. There might be other solutions out there that are similar. I know that there are other Zero Trust solutions, but there's no compelling reason for me to move anywhere else.
They just do a great job across the board. When I merged my company with another company, that company had been playing around with ThreatLocker but had never turned it on. They didn't understand how it worked. They tried turning it on internally and it blew up a bunch of stuff but that was because they didn't follow the instructions.
When we merged the companies, I was very adamant about this: "Guys, you need to put this piece of software on every PC that you manage—every single one. I simply explained to the one guy who was complaining about it, because he was the one who had turned it on before he had figured out how to whitelist things first, that there was a way to get around the issue that you have. And once you get past that issue, it's really great.
One last point: There is a feature, Elevation Control, that we're only using for one of our clients, but it works so well. It's fabulous, just wonderful.
I have an advantage over many other people and that is that I live 20 minutes away from ThreatLocker's corporate office. I'm fortunate enough to know Danny Jenkins (CEO), his brother, and several other people who are high up in the company. I visited them at their old office, and I went over on opening day and visited their new office.
I can walk in there and see how the people are working and I can also see the morale of the people who are working there. To everybody who walks in there, it looks like a fun environment to work in. It's a scary business to be in and yet I see people walking around smiling and saying to me, "Hey. How are you?" You don't see any evidence of people stressed out and working in a job that they didn't like. Probably the best thing that I can say about the leadership at ThreatLocker is that they put their people first.
Their training is very good. They treat their people very well and that makes those people want to help customers and MSPs. It's a very well-run business.
I would rate ThreatLocker at 11 out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
CEO at TechFox, LLC
Has allowed us to provide our clients with genuine security and gives us peace of mind
Pros and Cons
- "ThreatLocker Allowlisting has all of these features integrated into one console, making it effective."
- "We identified several areas that we would like to see improved."
What is our primary use case?
We use ThreatLocker Allowlisting for application whitelisting, and zero trust. We utilize the elevation portion to allow access without us having to grant it on an individual basis. We also utilize the Ringfencing portion of the solution to block and protect things that normally we don't want to occur, or could occur on a normal basis.
We didn't have a solution for this specific security feature or package. So we added ThreatLocker Allowlisting 3 yrs ago when we realized that we need to step up our game with cybersecurity nowadays.
ThreatLocker does something different than our other tools, so we kept our antivirus and other protection. We changed tools over time, but not because of ThreatLocker; it sits on top of all of that and provides the security we're looking for.
How has it helped my organization?
With ThreatLocker Allowlisting, training is key. If we properly train our staff and go through product training, knowledge bases, and learning processes, it is relatively easy to approve or deny requests. Without this training, we would be lost, as the product is too powerful to guess at. I have a standing appointment with Cyber Heroes every Tuesday at ten am for an hour, where we go through any issues I see, seek help or advice, and approve or deny requests. This also allows us to take a look at our environment as a whole, and make any necessary fixes, modifications, or improvements for our clients. By doing this, we can get to know the product and ensure we use it properly, leading to successful results.
The visibility into software approval requests is straightforward due to the presence of an approval center. We can view all the necessary approvals for our clients in one place. Additionally, we receive an email that creates a ticket in our ticketing system, allowing us to track and follow up on it. This provides us with two locations to manage the process, making it easy to keep track of.
By default, Allowlisting is built-in with Ringfencing, so we would need to take action to turn it off. Ringfencing is enabled for all the major items we would want it for. We can make systems more secure by taking additional steps if desired. Out of the box, Ringfencing is enabled for all the potentially dangerous items that could cause problems if not monitored.
The combination of Allowlisting and Ringfencing helps us block unknown threats and attacks. For example, we allow this application to run, which is fine, but it may try to do something we don't want it to do. By Ringfencing it, we can stop the application from doing anything other than what we intend. We can also prevent other applications from being spawned by previously approved applications. By doing this, we create a container and compartmentalize the application to prevent it from doing anything outside of our intentions.
I believe that ThreatLocker Allowlisting has distinguished us from other MSPs and has allowed us to provide our clients with genuine security in a time when there is no reliable solution for security due to the constant presence of zero-day threats. This is the way we can anticipate a zero-day attack and have the means to prevent it if it does occur, which is what gives me peace of mind.
We have recently (Q 2 & 3 of 2024) are implementing across all of our environments Network Access Control (NAC). NAC has dramatically improved our endpoint firewall control. This reduced the access to endpoint to a Zero-trust level.
We still have some work to do, as we need to approve everything. Once things calm down, Allowlisting will help reduce our organization's help desk tickets. We don't want small changes to be made that we don't plan for. Allowlisting is the best way to set our clients up. Allowlisting requires some effort upfront to get it working the way we want it, but once it's set, Allowlisting will do the work for us.
Allowlisting, once is settled does not add any additional labor or time on our help desk staff.
Since ThreatLocker combined four solutions into one, we saved a significant amount on implementation costs.
What is most valuable?
When all of these features are combined, we have a strong product. If any of these features were to be used as a standalone product, it would be largely ineffective. However, ThreatLocker Allowlisting has all of these features integrated into one console, making it effective. Without this combination, I would need to use four different products to achieve the same result. The combination of integrated features is the reason why ThreatLocker AllowListing is so powerful.
We are an MSP. One of the benefits of this product is that we can monitor our clients' activities beyond just removing the software. Even if they don't have military privileges, we can still keep track of what is happening in their environment, such as file access, application installation, or network access. We can see what they are doing, and we can allow the activities that they are supposed to be doing and prevent them from doing activities that could be harmful to them or us. This enables us to have a lower cost of management for our clients, which would otherwise require more effort.
What needs improvement?
We identified several areas that we would like to see improved. We submitted these as feature requests and ThreatLocker has acknowledged them. They are in the process of being implemented and many of them have been completed in the past year and a half, which we are delighted about. For example, I had been asking for the ability to copy a policy for a few months, and then it suddenly became available. This saves us a lot of time because if we set something up for one client, we don't have to do all the work again for another client; we can just copy it.
For how long have I used the solution?
I have been using the solution for 3 yrs
What do I think about the stability of the solution?
ThreatLocker pushes the boundaries of technology while also integrating well with the core of the operating system. So far, we have not had any problems, so I would say it is quite stable.
What do I think about the scalability of the solution?
ThreatLocker Allowlisting is highly scalable. We currently have thousands of endpoints on it and could easily have ten times more. There is no limit to ThreatLocker Allowlisting scalability.
How are customer service and support?
The technical support is excellent. I appreciate when a solution has great tech support because I don't have time to spend trying to figure out an issue that needs to be fixed quickly. I don't want to have to talk to someone who doesn't know what they're doing when I reach out to them; they usually resolve the issue within minutes. We can contact them by phone, email, or text and submit a ticket, and they will provide an answer promptly. The technical support is truly remarkable.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. I was fully involved in the initial setup for my company and in getting ThreatLocker running. We then passed it on to our certified and knowledgeable techs, who can now do it. When we initially rolled out and deployed, we wanted to make sure we were monitoring ThreatLocker closely.
ThreatLocker has lots of documentation and explanations on how to deploy it. I strongly recommend using their free concierge service with Cyber Hero to guide you step by step. This eliminates the need for you to figure it out on your own. Their professionals will help you deploy properly and successfully. This is one of the great benefits of this company and product, as they want us to be successful with their product.
The deployment was done primarily myself with a script and we deployed two thousand endpoints over a three to six-month period.
Our deployment covers approximately fifty companies in multiple countries, with multiple sites across those companies. Some of the companies have more than two hundred endpoints.
What about the implementation team?
The implementation was completed in-house.
What was our ROI?
There is certainly a return on investment due to the increased control we have over our clients' environments and the peace of mind it provides us and them. ThreatLocker is an additional layer of protection that surpasses our standard security measures.
What's my experience with pricing, setup cost, and licensing?
The price is very reasonable, and we have been able to integrate ThreatLocker with all of our clients. We do not offer it as an option for only some of our clients; it is a standard feature for all of our clients. One of the reasons for this is that the pricing is quite reasonable considering all that ThreatLocker offers.
Which other solutions did I evaluate?
I attended several conferences and viewed numerous demonstrations, and I found ThreatLocker to be particularly impressive. I was very impressed with the features and product design, which showed that a great deal of thought had gone into it. I believe ThreatLocker is quite advanced in comparison to some of the other products on the market, which are more established but have yet to achieve what ThreatLocker can already do.
What other advice do I have?
I give the solution a ten out of ten.
With any product of this type, we should always maintain ThreatLocker Allowlisting. The more we maintain it, the more successful it will be and the more secure our environment will be. Maintenance should become part of our normal routine to manage our environments.
Potential users should take the time to work with Cyber Heroes in deploying ThreatLocker AllowListing, learning how to use it, and managing it. They will be very pleased with the results. They should not attempt to do this alone; it is not something they should have to do on their own, given the services ThreatLocker provides.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
Cybersecurity Administrator at a tech services company with 1-10 employees
Helps verify specific access requests, and provides us with peace of mind, but the learning curve is wide
Pros and Cons
- "The sandbox functionality is fantastic."
- "Adding applications to the allowlist can sometimes feel overwhelming."
What is our primary use case?
Users submit applications for installation, and I typically review them, granting or denying access as needed. While the volume isn't high, ThreatLocker Protect provides significant peace of mind knowing users aren't installing unauthorized or malicious software. Our biggest challenge has been user errors causing support requests. To address this, I've implemented rules for applications frequently used in daily operations. It's had a learning curve, but the effectiveness has been noticeable.
How has it helped my organization?
Making approval or denial decisions on requests is pretty straightforward for me. I haven't encountered any problems. However, I can see how it might be a bit confusing for less technical users. Things like allowing hashes and understanding all the terminology could be stumbling blocks. Still, I believe anyone with a few months to a year of IT experience would find it manageable. And of course, I was able to grasp it myself.
While allowlisting can help verify specific access requests, it doesn't guarantee overall trust as requests can still originate from compromised sources. In my experience, the zero trust model has proven the most effective approach. Its principle of "never trust, always verify" minimizes risk by scrutinizing every access, regardless of origin. We haven't encountered any security breaches with clients who implemented it, suggesting its efficacy. While antivirus remains a valuable layer of defense, I believe the zero trust framework, particularly in conjunction with ThreatLocker, offers the most robust security posture we've encountered. Thankfully, we haven't experienced any issues with this combination so far.
ThreatLocker Protect provides us with peace of mind. It's a game-changer. With it in place, we can be confident that employees are only using authorized applications, minimizing surprises and freeing up our time for other aspects of our work. We used to spend significant time dealing with malware, but that burden has been greatly reduced. Peace of mind is truly the main benefit.
Allowlisting has significantly reduced the number of tickets we receive from compromised accounts. It's eliminated them. However, we still get tickets from users who are confused about the new process, need things approved, or are feeling impatient. While the volume has decreased, these legitimate tickets related to access limitations are still present. Ultimately, we believe this trade-off is worth it for the sake of enhanced security. This is what we communicated to the team.
Implementing an allowlist has not only freed up our help desk staff for other projects but also aligns with my preference for approved application lists on both mobile devices and computers. This approach ensures smooth operation with minimal complications, and a positive outcome overall.
We utilize allowlisting alongside other security measures, with ThreatLocker as an additional layer. This choice stems from the absence of other comprehensive endpoint protection solutions, ensuring ThreatLocker doesn't overlap with existing safeguards. Therefore, it complements our antivirus for all users.
It initially took a couple of months for us to fully appreciate the benefits of ThreatLocker. While we put our people in learning mode for approximately a week to understand normal system processes, it wasn't until the lack of suspicious activity became evident that we truly recognized the impact. This doesn't diminish the importance of our existing security measures, including sound user guidance, phishing training, and other protocols that discourage risky behavior and minimize software installation needs. In essence, it took some time for the benefits of ThreatLocker to become fully apparent due to the effectiveness of our pre-existing security practices.
What is most valuable?
When new files arrive and people mention they've been tested twice in the virtual environment, I like to double-check for potential malware by scanning them on VirusTotal and other antivirus platforms. This adds an extra layer of security, which is especially helpful when I'm unsure about approving a file and research doesn't provide clear answers. The sandbox functionality is fantastic. It bolsters my confidence considerably, as it can reveal suspicious behavior like registry modifications even if initial scans are inconclusive. Overall, these features have been game-changers for me.
What needs improvement?
The current process for viewing software approval requests from end users has room for improvement. While it's generally functional, some users find it confusing. This can be due to either unfamiliarity with the process, unexpected appearance of the request window, or lack of clear instructions. Additionally, the notification box might not be sufficiently noticeable, as some users have reported missing it entirely.
Adding applications to the allowlist can sometimes feel overwhelming. The numerous fields, coupled with navigating the unfamiliar portal, can be daunting, especially on our first attempt. Even with explanations, recalling the necessary information and understanding the required actions for file inclusion can be tricky. I believe the initial learning curve for allowlisting is relatively steep. However, once mastered, it proves to be a valuable tool. My main concern lies with the initial learning hurdle.
For how long have I used the solution?
I have been using ThreatLocker Protect for around four months.
What do I think about the stability of the solution?
ThreatLocker Protect has been mostly stable over the past six months. We did experience a single outage that lasted a day, which was disruptive due to pending approvals. However, this has been the only major incident in that timeframe, suggesting overall good stability.
What do I think about the scalability of the solution?
ThreatLocker scales well and has been successfully deployed on all our required devices. We offer it as part of a premium package, but due to its higher cost, adoption among our clients is currently limited. Nevertheless, it meets our scalability needs effectively.
How was the initial setup?
The implementation was relatively straightforward. We developed components or scripts for deployment to devices, avoiding major complications. Furthermore, we have a remote management tool in place for efficient installation.
Installing on everyone's machines is a fairly quick process, typically taking an hour with online devices. While it doesn't require much time, we recently spent two hours on calls with someone to guide us through it. This was because our previous setup, done by someone else in the company, had some errors. We've rectified them now, but it meant changing a few things. Overall, deployment should be smooth and swift, requiring two people and around an hour if all the devices are online.
What about the implementation team?
The implementation was completed internally by our team. Given our extensive experience deploying vulnerability scanners for assessments, this process was relatively straightforward.
What other advice do I have?
I would rate ThreatLocker Protect a seven out of ten. The learning curve is quite steep, especially for those without extensive IT experience. I found it challenging to master and had to rely on my team for guidance on several occasions. Even my manager isn't completely comfortable with it yet. However, once we overcome the initial hurdle, it truly shines.
ThreatLocker requires minimal maintenance, except for one recent instance where we reviewed its configuration. While it's designed to automatically update on user machines, I noticed some devices hadn't yet received the latest version. I manually initiated the update for these devices. The cause of the delay is unclear, though the devices are online, so it might be a network issue.
Ensure all future ThreatLocker users are thoroughly briefed on its functionality. We've encountered surprises among some users regarding the approval requirement for new activities. To avoid such issues, we recommend comprehensive pre-deployment communication, outlining ThreatLocker's purpose, features, and approval process.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: MSP Reseller
Help Desk Coordinator at a aerospace/defense firm with 201-500 employees
Well-priced, phenomenal support, and operates in the learning mode in the beginning
Pros and Cons
- "Feature-wise, the learning mode and the fact that it's blocking everything are the most valuable. I don't see why more companies don't use the type of product."
- "If you have a thousand computers with ThreatLocker agents on them, when you approve or create a new policy saying that Adobe Reader that matches this hashtag and meets certain criteria is allowed to be installed, it applies at the top level or the organization level. It applies to every computer in the company. When you make that new policy and push it out and it goes out and updates all of the clients. Unfortunately, at this time, it does not look like they stagger the push-out."
What is our primary use case?
It's a solution for software whitelisting. It blocks applications from running. If there is any DLL or something else running on your computer, the admin or admins of the service get an alert. If an end-user is trying to install something that has been blocked by the organization, the admins get alerted.
How has it helped my organization?
We can sleep easier knowing viruses aren't installing things, employees aren't installing things, and nothing is running without someone getting an alert and having eyes on it and approving it.
Ringfencing is a great feature. There is grainy clarity. You can get down into the Ringfencing where you can either completely ring-fence something or you can manually choose what you want it to reach out to. The combination of Allowlisting with Ringfencing for blocking unknown threats and attacks is a great combination because you want to allow the software, but then you, as an admin, are not aware of what every piece of software does. So, you wanna start off being strict and just allow the application, but you would want to ring-fence it in case it beacons out to the internet or goes over ports that you don't think it should be traversing across. That's ringfencing, and it blocks that, but then when the end-user reaches back and says that a part of this software isn't working as it should be, then you can get into that granularity where you can look at the ringfencing policy. You can adjust the ringfencing policy from the strictest to allowing certain parts.
Establishing trust for every access request, no matter where it comes from, is a wonderful thing, and it's needed, but it can hinder and slow down. It adds steps for the end-users because they can't just go wild and install whatever they want, but ultimately, that's one of the main reasons why we invested in ThreatLocker and why we love it because it actually works as they say it should.
In terms of Allowlisting helping us reduce our organization’s help desk tickets, it's twofold because if we didn't have this, we would be getting tons of help desk tickets about bad things happening in the company because people are allowed to install whatever they want. They could be watching Twitch, YouTube, etc. They could be installing video games, which in itself would then create tons of help desk tickets for us. On the other hand, anytime someone wants to install something, we would get a help desk ticket for it. So, either way, we'd be getting help desk tickets, but at least the help desk tickets that we're getting for ThreatLocker are the type we want because now we know we're safe and secure and we're ahead of the curve for safety. Instead of being a reactive help desk ticket where you install something, and your computer is broken, now it's more proactive where you raise a ticket to install something, and your computer is not infected. We don't have to spend hours reimaging, tracking things down, being a victim of ransomware, etc.
Allowlisting has helped to free up help desk staff for other projects because now, we can allow elevation, and we can allow the approvals from an admin through it. We don't have to send people physically to go to a person's desk to do installations or set up online meetings with them to share out where we can assist with the installs. It has freed up time for the help desk staff.
Allowlisting has helped to consolidate applications and tools. We now get to see what everyone is trying to install, and we can find out why people are installing a particular application when another one has already been approved to do the same type of thing. Previously, we didn't know about that. One of the big ones would be SolidWorks. A lot of people have looked at three applications for drawing, and when we see that coming through for a request, we can suggest and ask them what about SolidWorks, and then they use that.
What is most valuable?
Feature-wise, the learning mode and the fact that it's blocking everything are the most valuable. I don't see why more companies don't use the type of product.
I like how it blocks everything. The learning mode is another feature that I like. It operates in the learning mode in the beginning. When you first get it set up in your environment, you don't want every computer to not be able to work and not be able to run the normal fresh install of Windows or other operating systems, so when we first got it set up, we were able to put it into learning mode, which was wonderful. The learning mode is a great feature they have where the computer allows everything and just learns about your typical environment and then makes a good baseline from there.
The idea that it can block everything is wonderful because, in our company, we have to follow the cybersecurity requirements of the Department of Defense. They have very strict guidelines. This software helps us meet and cross off the many cybersecurity checklists for the environment, especially for software installs and what's allowed to run in our environment. That's one of the greatest features.
Its graphical user interface is very intuitive. It's very well laid out and detailed, and it's very easy to find things. I don't have anything to suggest to them in that regard. I've made other suggestions to their company for some features, but for the way its interface is or for proving things or how to use it, I've had no suggestions.
A great thing is that you have to be their customer, but with no extra add-on, you can have access to their ThreatLocker university, where you can learn and watch videos on how to do everything.
Another great thing is that they have online cyber heroes, and I have never created a ticket and waited more than five minutes until a live person was on my check. They're immediately able to get into my tenant. They can set up a Zoom call and share their screen and show me exactly what I'm missing or where to go.
What needs improvement?
You need to have ThreatLocker agent software on every client or every computer that you want to be protected by the ThreatLocker Allowlisting application. If you have a thousand computers with ThreatLocker agents on them, when you approve or create a new policy saying that Adobe Reader that matches this hashtag and meets certain criteria is allowed to be installed, it applies at the top level or the organization level. It applies to every computer in the company. When you make that new policy and push it out and it goes out and updates all of the clients. Unfortunately, at this time, it does not look like they stagger the push-out. If your company only has a 100-megabytes internet line and you send out that update of 1 megabyte to a thousand computers, because it's sending that out to a thousand at the same time, you're using up a thousand megabytes right there. So, you could saturate your network. We have suggested they stagger it. If the system sees that there are a thousand computers, it should just try to send out to a hundred, and after that's completed, send out to the next hundred. That way, it's not saturating your network.
Other than that, feature-wise, it's a great solid product. I have not come up with anything that they should do. Even when I thought I had an issue, they showed me that I have to look here to adjust that setting. For example, when you first join a computer, it automatically puts that computer in learning mode. You can set the time for how long it automatically stays in the mode. I believe the default setting was a month or something like that, and we thought that was too long. Their cyber heroes helped me find the area to adjust that. They already had the solution for that. I just wasn't aware of it.
For how long have I used the solution?
We have been using it since September 2021.
What do I think about the stability of the solution?
The part that can cause bandwidth issues is one of the only things where I see companies not going with them, but they probably wouldn't know that until they finally get to use the product. That would be the only downfall to it.
What do I think about the scalability of the solution?
It grows with your company, and it learns with your company. It's very good with scalability. They're always pushing updates. It's learning all the newest software that comes out. It's picking up. I'd rate it a 10 out of 10 in terms of scalability.
It's required on every computer and every server in our company nationwide. We're pretty small. Our computer count is 225. We have 120 users, but we have servers. Some people have multiple computers. We have lab computers. We have computers that are just stationary set up to 3D printers. Every computer has to have it. That's why we have more computers than employees.
How are customer service and support?
Their support is phenomenal. I rarely say that about customer support. We all have had our nightmares with certain customer support scenarios, but I've not run into any issues with ThreatLocker. They are one of the best. I've been in this industry for over eighteen years. Not just in this industry, but also as a person, you deal with customer service everywhere you go, such as McDonald's, Target, Comcast, Verizon, etc. ThreatLocker support is one of the best I've ever experienced. I'd rate them a 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't use a similar solution before. The closest solution we ever used was to whitelist the internet. So, you cannot go out to any website unless you've requested it, and it has been approved. Once we approve it, anyone can go to that website. We used a proxy for our internet traffic.
How was the initial setup?
I personally don't physically deploy it. It gets pushed out by our software center. Any new computer gets the client installed, and then that client with API package and everything else reaches back to and joins our tenant, and then we see it in the dashboard. My role is to make sure that every new machine has it. I am the admin for our company for ThreatLocker. I do audits on what the system sees as how many computers we have connected to ThreatLocker, and make sure that I'm deleting any computer that was removed from our domain. If any new computer joins, I have to make sure that it does register in ThreatLocker because sometimes, because of an internal networking error or something else, computers get the client, but it doesn't beacon out and get associated with our tenant. So, I have to do that.
Its implementation was very quick. Once we got it, it took maybe a week to work with the team to get everything staged. When it was first introduced, we left our computers in learning mode for several months, which is highly recommended. That's how we worked with ThreatLocker support and how they helped us get it all set up. After six months of learning our environment in terms of what's normal, what's allowed, and what they shouldn't block, the keys were handed over. We were told that this is our baseline and to go from there.
Its maintenance includes receiving updates on a new package. I also audit it because even though employees see a request pop up, not every employee would click on it because they won't know. So, I still need to audit. For example, a bad virus wants to run on Bill's computer. Bill will see a ThreatLocker popup saying this thing is trying to run. A lot of times, end-users think that they didn't run anything, so they just hit cancel, and I won't get alerted for that. So, I do have to physically go into the audit. Often, I look and just pull up an audit since the last time to see everything that got blocked. I go through it, and I still look for anything that was malicious because we still have to be aware of that so that we can take action.
The other part that I have to do maintenance on is just making sure that the license count is correct, and that the number of computers that the user interface says are registered is similar to what we have. I go in there and make sure that there are truly that many.
What was our ROI?
We have seen an ROI. Knowing that ransomware or viruses have been stopped and can't process, the savings pay for it.
Its time to value was within one week. In the first week, we got to see what was getting blocked. It was very eye-opening to see what was happening on all the computers with the processes that we were trying to run or install. It was definitely within the first week.
What's my experience with pricing, setup cost, and licensing?
Considering what this product does, ThreatLocker is very well-priced, if not too nicely priced for the customer.
Which other solutions did I evaluate?
I know my manager did evaluate other options. I don't recall which products were looked at, but their features were very similar. Their price was extremely high, especially compared to ThreatLocker.
What other advice do I have?
Before you buy, you need to educate your employees and let them know this is adding a safety step to the process of installing software. You also need to be prepared because if the admin isn't around, then you're going to slow down. The person is not going to be able to install the software. That is something you do need to be aware of.
It's extremely easy for an admin to approve or deny requests using Allowlisting. The only caveat to that is that because of the way that ThreatLocker is set up and how minutely you can dive down into a software install, there could be issues with some pieces of software. For example, I approve of you installing Adobe Reader. If you run that install from your desktop, and I approve it, there's a certain way to say I want it to approve this exact installation. What that means is that I approve it for that one person. If someone else tries to run that exact same install package, but it, for example, is not from the desktop and is from a shared drive or from a USB, because of that one tiny change, it will technically get blocked. To some people, it's a little confusing. If you understand how the system works, it's easy. You can use a wildcard to say this install package can be installed from any location. So, when you learn those little tips and tricks, it gets a whole lot easier, but in the very beginning, if you're fresh getting into this, or it was thrown in your lap and you were told that you're the administrator for ThreatLocker, it can be a little confusing. The great thing is that ThreatLocker has something called the install mode. Basically, you're putting a computer in a mode for a temporary amount of time, which the admin can control. When a computer is put into the install mode, ThreatLocker won't block anything. You can go ahead and run any executable. It'll allow the installation, and it'll apply it to that application or policy name that you wanna apply it to. If you're doing it for Adobe, you could add it to the Adobe Reader policy. So, it's very easy. Even if you had any issues, their support is phenomenal.
Overall, I'd rate ThreatLocker Allowlisting a 9 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free ThreatLocker Zero Trust Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
Endpoint Protection Platform (EPP) Network Access Control (NAC) Advanced Threat Protection (ATP) Application Control ZTNA as a Service ZTNA Ransomware ProtectionPopular Comparisons
Fortinet FortiGate
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cortex XDR by Palo Alto Networks
SentinelOne Singularity Endpoint
Cloudflare One
Microsoft Defender for Office 365
Varonis Platform
Zscaler Zero Trust Exchange Platform
Cisco Identity Services Engine (ISE)
Trellix Endpoint Security Platform
WatchGuard Firebox
Cato SASE Cloud Platform
Fortinet FortiClient
Buyer's Guide
Download our free ThreatLocker Zero Trust Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Which ransomware is the biggest threat in 2020?
- Are you aware of SIEM platforms that integrate both Active Directory auditing and security monitoring tools?
- What is the best solution for ransomware attack?



















